At a glance: A hacktivist group announces cyberattacks against EU systems to stop Chat Control regulations, highlighting a core problem: communication surveillance mechanisms can themselves create security vulnerabilities.
The hacktivist group LunarisSec has issued an ultimatum to the EU via Telegram and threatened to exploit vulnerabilities in EU systems should the EU not abandon its Chat Control plans. The group demands the abandonment of Chat Control 1.0 and 2.0 as well as legal safeguards for end-to-end encryption.
LunarisSec, a Telegram channel active since January 2026, has published multiple posts in which the group claims to have already identified vulnerabilities in EU systems and announces their exploitation. The hacktivists specifically demand: immediate and permanent abandonment of Chat Control 1.0 and the proposed Chat Control 2.0 under negotiation, legal protection of end-to-end encryption throughout the EU, full transparency in data-sharing agreements with third parties, and the establishment of an independent supervisory authority for data collection practices.
For CISOs, the threat is relevant insofar as it reveals how intensely the Chat Control debate is perceived in the technical security community. LunarisSec does not describe itself as criminal, but as a defender of digital rights and criticizes Chat Control plans for creating a backdoor in communications that exposes users to both government access and cybercriminals. This argument underscores a well-known security dilemma: procedures for searching encrypted or unencrypted communications can themselves create new attack surfaces.
To support their claims, the group published edited screenshots that allegedly show access to internal EU systems and contact details of officials. Without actual data samples, however, these claims cannot be verified. Major cybersecurity providers have not yet assessed LunarisSec, and there are no reliable assessments of the group’s actual technical capabilities. According to their own previous statements, the group had identified vulnerabilities at French organizations and reported them responsibly; an earlier Telegram channel was shut down over the course of the year.
Chat Control 1.0 in its currently applicable form, limited until 2028, provides a voluntary option for providers such as Gmail or Facebook Messenger to search unencrypted private messages for child sexual abuse material. Chat Control 2.0 would replace this regulation permanently; debate over mandatory searching of all private messages, including encrypted communications, remains unresolved. Digital rights organizations have repeatedly warned that client-side scanning mechanisms create new security risks for users themselves and can undermine fundamental data protection principles.
Source: www.it-daily.net · Published August 2, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.