The hacktivist group LunarisSec has threatened European Union institutions with cyberattacks if Brussels does not scrap the regulations known as ‘Chat Control’. The collective claims to have found vulnerabilities in EU systems and is demanding end-to-end encryption, greater transparency regarding data transfers and independent oversight. However, it has not provided any technical evidence to substantiate its claims of access to EU infrastructure, and its assertions therefore remain unverifiable.
The ultimatum comes at a time when the regulatory situation is more complex than the group’s message suggests. On 23 July 2026, the Council of the EU approved the reintroduction of temporary provisions which, until 3 April 2028, allow service providers to voluntarily detect material relating to child sexual abuse. End-to-end encrypted communications have been excluded from the regulations. At the same time, negotiations are ongoing to find a permanent solution. The Council’s position calls for risk assessments by platforms and the continuation of voluntary scanning, whilst the European Parliament advocates targeted measures and the protection of encryption.
The threat itself does not imply a successful breach, but it should not be ignored. ENISA points out that hacktivism accounted for nearly 80 per cent of the incidents analysed in the EU, mainly DDoS attacks. The public administration sector was the most frequently targeted. Most such campaigns have limited operational impact, but the actual exploitation of vulnerabilities could result in data breaches, service disruptions and increased security costs for institutions and their suppliers.
The most likely outcome will be a tightening of security audits and further polarisation of the debate on privacy. The threat of cyber-attacks is unlikely to halt the legislative process, but it may hinder a substantive discussion on how to protect children without undermining the confidentiality of communications.
