DEV Community

Cover image for Encrypted Phone: Securing Strategic Communications in Europe
Manuel Spataro
Manuel Spataro

Posted on

Encrypted Phone: Securing Strategic Communications in Europe

Four recent cases from Italy, Portugal, Spain and Germany show how data exposure, endpoint risk and communication failures can combine into a wider security problem. How prepared is Europe to protect sensitive communications and strategic information?

1. The attack surface starts before the message is sent

A smartphone sits at the intersection of identity, communications and personal information. A phone number alone does not prove espionage or device compromise. It can, however, become the first link in an information chain connecting a person to their role, organisation, contacts and, in some circumstances, their communications.
Recent European cases illustrate different parts of this problem. In Italy, Portugal and Spain, phone numbers and other personal data linked to institutional figures were exposed. In Germany, a confidential communication involving senior Bundeswehr officers was directly intercepted.
The four incidents do not necessarily share the same technique, nor do they automatically show that the smartphones involved were compromised. Taken together, they do show how exposed data, identification of individuals and interception of communications can become parts of a broader information-gathering chain.
The security question therefore goes beyond whether a particular phone is secure. It is whether the entire system used to communicate can withstand the threat model it faces.

2. Italy: when senior officials' phone numbers become intelligence

In April 2025, the disclosure of personal phone numbers associated with some of Italy's highest-ranking state officials attracted public attention. The names connected to the contacts included the President of the Republic and the President of the Council of Ministers.
The Rome Prosecutor's Office opened an investigation into the origin and legality of the data collection, while the Italian Data Protection Authority also opened an inquiry. According to ANSA's reporting on the disclosure of the phone numbers, the contacts may have been obtained through lead-generation platforms and data-enrichment services.
There is an important distinction, however: having a phone number does not demonstrate that the device was compromised or that its owner was intercepted.
Italy's National Cybersecurity Agency also clarified that no exfiltration resulting from a compromise of its systems had been identified. ANSA reported these clarifications as well.
The real risk appears at the next stage.
A phone number can act as an identifier to which other information is attached. When names, roles, organisations, email addresses and other contacts are correlated, they can produce a much more complete profile.
That ability to correlate apparently ordinary data is what can turn a basic identifier into a potential source of information for profiling, intelligence collection and cyber intelligence.

3. Portugal: contact data can increase the value of an identity

On 30 July 2026, Expresso reported the online exposure of mobile numbers, email addresses, private residences and other data relating to Portuguese state representatives.
Those affected reportedly included government members, the President of the Republic, judges, police personnel and the head of Portugal's intelligence services. According to the publication, intelligence services and the Judicial Police began investigations into the case.
The case is significant because it shows how the value of information increases when separate elements can be tied to the same person.
A phone number identifies a line. When combined with a name, email address, home address and institutional role, it can define the identity and professional context of its owner with much greater precision.
Again, exposure of this information does not automatically mean that devices were compromised or communications intercepted.
The issue is what can happen next. The more information available, the less effort may be required to identify a target, reconstruct relationships and prepare further information-gathering activity.
ECO also covered the case, reporting the exposure of contacts belonging to government members, the President of the Republic and the head of the intelligence services.

4. Spain: correlation can turn scattered data into a profile

In June 2025, RTVE reported that Spain's National Police was investigating the disclosure on Telegram of personal data belonging to seven government members and several former Partido Popular officials.
The exposed information included phone numbers, identity documents, home addresses and email addresses.
Once again, publication of a phone number or home address does not prove that a smartphone was compromised.
The risk comes from the combination.
Different types of information, when linked to the same individual, can create a far more detailed profile than any single data point. Such a collection can support social engineering, targeted phishing or preliminary intelligence gathering.
RTVE later reported on a new investigation concerning the disclosure of data belonging to ministers and senior officials through Telegram.
The Spanish case therefore adds an important point: the value of data depends not only on the sensitivity of each item, but also on how easily it can be connected to other information.

5. Germany: when a strategic military call is intercepted

In March 2024, the problem took a different form.
An online meeting involving four senior German Luftwaffe officers, during which the possible use and supply of Taurus missiles to Ukraine was discussed, was intercepted. The recording was subsequently circulated by Russian media.
Germany's Ministry of Defence confirmed the incident, later examined by Tagesschau in its reporting on the Bundeswehr interception.
According to Defence Minister Boris Pistorius, one participant, connecting from Singapore during the Singapore Airshow, had used a non-secure line. The initial investigation did not identify a compromise of Bundeswehr communications systems; the incident was reportedly enabled by an operational error in how the meeting was accessed.
Reuters also reported that the interception was connected to this method of connection.
This case differs from the previous examples.
In Italy, Portugal and Spain, the starting point was primarily exposure of personal data. In Germany, the target was a communication containing sensitive military information.
Tagesschau later examined the operational error identified by Pistorius, while another analysis addressed the security of Webex video conferences used by the Bundeswehr. See also Tagesschau's analysis of Webex conference security.
The lesson is broader than the application itself: when information has high value, it is not enough to ask whether an application uses encryption. The communication method, devices, access mechanisms and operating context all have to be assessed.

6. How an identifier can become cyber intelligence

The four cases involve different ways of acquiring information, but they reveal a common progression.
A phone number can be the starting point. Linked to an identity, role, organisation and other personal data, it can help reconstruct a person's network of relationships.
That network may reveal further elements: interlocutors, organisations, contact patterns, communication methods and operational context.
This does not mean that one data point automatically leads to espionage. The critical factor is correlation.
Information from different sources can be associated with the same person until it creates a much more complete picture than any individual data point provides on its own.
At that point, information stops being merely personal data and can become knowledge useful for information gathering and cyber-intelligence activities.
The European cases therefore illustrate a progression that can start with identifying a person, continue with mapping their relationships and, in the German case, reach the direct acquisition of a communication containing strategic information.

7. End-to-end encryption is only one security layer

The security of a communication cannot be judged solely by the presence of end-to-end encryption.
Encryption is essential for protecting content in transit, but it is only one security layer.
A secure messaging platform should be assessed as a system that includes the application, device, digital identity, authentication, key management, infrastructure, metadata and operating procedures.
The right question is not simply “Is the message encrypted?” It is also whether the entire ecosystem through which the communication is created, transmitted and received is secure.
An attacker may not need to break the encryption. They may instead obtain information about participants, exploit a device vulnerability, compromise an application or take advantage of an inadequate access method.
For institutional, military or strategic information, security therefore has to cover the entire communication lifecycle.

8. The smartphone is part of the security boundary

The smartphone is the endpoint where a message is written, received and displayed.
If the device is compromised, an attacker can obtain information before it is encrypted or after it has been decrypted. At that point, protecting the communication channel alone is no longer enough.
Endpoint security should be able to look for spyware, trojans, malware and other indicators of compromise. Higher-criticality environments require broader detection, analysis and response capabilities.
It is important, however, to avoid false certainty. An unusual behaviour, an unknown number or abnormal battery consumption is not, by itself, proof of surveillance.
For a practical overview of warning signs and ways to check a device, see how can I tell if my phone is being tracked.
Device protection therefore has to work together with communication security.

9. Why consumer messaging is not the whole answer

Consumer messaging applications can provide strong protection for many everyday scenarios.
That does not necessarily mean they were designed for the same threat model as government, military or strategic communications.
The required level of protection should be proportional to the value of the information and the capabilities of a potential adversary.
In high-criticality environments, the device, operating system, user identity, authentication, access management, infrastructure, metadata and operational procedures all need to be considered.
A weakness at any one of these layers can undermine overall security.
Using a messaging application with strong security features should therefore be treated as one part of an architecture, not as an isolated guarantee.
Different users may also require different configurations depending on their role, the information they handle and the environment in which communication takes place.

10. Security has to be designed before communication

The cases show that risk can emerge at three different stages: before communication, through data exposure; during communication, through interception; or on the device itself, through endpoint compromise.
Security therefore cannot depend on a single component.
An exposed identity can make profiling a target easier. A vulnerable device can reveal information before encryption or after decryption. An inadequate access method can directly expose a confidential communication, as the German case demonstrated.
Security has to be designed before the communication takes place.
Endpoint, identity, application, authentication, infrastructure, networks and operational procedures have to be considered together.
The objective is not only to make an intercepted message harder to read, but to reduce the opportunities through which an adversary can reach the communication or the information surrounding it.
The risks associated with smartphone interception and surveillance sit squarely within this broader architectural problem.

11. The security perimeter extends to networks, servers and devices

Security does not end at the smartphone.
The servers, networks and data centres supporting communication are also part of the attack surface.
In higher-criticality environments, an organisation may need greater control over the components used to process and protect communications.
The same principle applies to how users and different sites communicate. The more control an organisation needs over its infrastructure, the more important it becomes to assess every point at which a communication could be exposed.
For organisations handling sensitive information, architecture should be designed around the threat model rather than around the convenience of the technology being used.
In some scenarios, this can mean using an encrypted phone or dedicated devices, controlled networks or privately managed infrastructure.

12. Data minimization reduces the blast radius

Security also depends on what remains available after a communication has taken place.
Not every piece of information needs to remain stored indefinitely on a device or inside a conversation.
In some operational scenarios, temporary messages can reduce the amount of stored information and therefore limit potential exposure if a device is compromised later.
This does not remove risk or replace other protective measures, but it can reduce the amount of information available after an incident.
The principle is straightforward: the less unnecessary information remains accessible, the smaller the volume of data that can potentially be exposed in a compromise.

13. What technologies are needed for high-criticality environments?

The answer depends on the scenario.
For everyday communication, a messaging application with strong encryption may provide sufficient protection against many common risks.
For an organisation handling high-value institutional, military, strategic or commercial information, the requirements are different.
In this context, phone antivirus can provide an additional defensive layer, particularly when it combines anomaly detection with the identification of activity potentially associated with spyware or trojans.
The questions should include whether the device is protected, whether identity is under control, whether access is appropriate, whether the infrastructure is trustworthy, whether networks are protected and whether operating procedures reduce the possibility of human error.
No technology can eliminate risk completely.
Claims of “uncompromisable” systems should therefore be understood as an architectural objective, not an absolute guarantee of invulnerability.
It is nevertheless possible to build systems in which compromise of a single component does not automatically result in the loss of the entire communication or information asset.
That ability to create multiple layers of protection is what should be sought when the value of information justifies a higher level of security.

14. Four cases, one European risk surface

The four cases examined do not demonstrate that a single coordinated operation exists against European institutions.
It would be wrong to draw that conclusion from these incidents alone.
They do show, however, that different types of information can be exposed or intercepted and that European institutions face a risk surface combining personal data, devices, applications, networks, infrastructure and human behaviour.
Italy, Portugal and Spain illustrate how personal data can expand the information available about a target.
Germany shows that a strategic communication can be intercepted directly when there is an error in how it is conducted.
The common factor is not necessarily the technique used, but the need to protect the entire communication chain.
The question is no longer simply whether a message is encrypted.
It is who controls the device, who controls the infrastructure, how the communication is established, what information remains available and what happens if one component is compromised.

15. From channel protection to system security

The cases show that exposure of data relating to political, government and military figures is not merely a privacy issue or a collection of isolated incidents. Information about people in sensitive roles can be obtained, combined and correlated through commercial sources and data-brokerage services, creating increasingly detailed profiles of individuals and organisations.
Last week, I personally investigated data-brokerage services and found that contacts belonging to legislators, government officials, government members, senior military officers and intelligence personnel across the West can be obtained relatively easily and at low cost. This highlights a structural weakness in protecting the identity and contact data of people holding sensitive positions.
As new cases continue to emerge, the issue goes beyond technology: does Europe have a sufficiently robust structural response to this problem, rather than reacting only to individual incidents?
When sensitive communications are involved, protecting the channel is necessary; protecting the entire system is indispensable.

Top comments (0)