Hackers threaten the EU directly: end Chat Control or else
A threat actor frames their cyber-threats as a political manifesto: “We will not remain silent in the face of this unacceptable attack on our fundamental freedoms.”

Image by Cybernews.
- Hacktivist group LunarisSec has issued a direct ultimatum, threatening cyberattacks on EU systems unless Chat Control is abandoned.
- The group claims to have identified significant vulnerabilities in European infrastructure but has provided no verifiable evidence.
- The group’s capabilities and technical sophistication have not yet been assessed by major cybersecurity vendors.
A hacktivist group calling itself LunarisSec released a series of posts threatening the EU. The hackers claim they identified vulnerabilities in the bloc’s systems and plan to exploit them unless the Chat Control projects are abandoned.
LunarisSec is a relatively new hacking group that explicitly rejects the criminal label. France appears to be one of its main areas of focus – several of its previous posts mentioned identifying and responsibly disclosing vulnerabilities in French organizations.
Its current Telegram account has been active since January 2026. However, the group had its previous accounts banned last year. Major cybersecurity vendors haven’t yet flagged LunarisSec or its activities.
But after Chat Control 1.0 was reactivated by the European Parliament, the group is taking a loud political stance – claiming it has identified several vulnerabilities in EU systems and is threatening to exploit them unless Chat Control projects are abandoned.
The group also released some heavily edited screenshots suggesting they have unconfirmed access to certain internal systems and to the contacts of some officials, but this can’t be verified without actual data samples.
“Be aware that we have already identified the vulnerabilities in your systems. Your technological arrogance will be your downfall,” one of the hacktivists’ Telegram posts reads.
LunarisSec issued what it describes as an “ultimatum” and demands “immediate and definitive” abandonment of Chat Control 1.0 and 2.0, the two laws requiring online platforms to scan private communications for CSAM (child sexual abuse material) and constitutional protection of end-to-end encryption in the EU.
The temporary 1.0 version of Chat Control is in force until 2028. This rule is voluntary, allowing platforms such as Gmail and Facebook Messenger to scan unencrypted private messages for CSAM.
The Chat Control 2.0 version, currently a proposal, is intended to be a permanent regulation that replaces 1.0, and the debate over the mandatory scanning of all private messages, including the encrypted ones, is ongoing.
“We are not criminals, but defenders of digital freedom. Chat Control creates a ‘backdoor’ in our communications that threatens the security of all users, making them vulnerable not only to authorities' actions but also to those of cybercriminals,” LunarisSec’s post reads.
“We will not remain silent in the face of this unacceptable attack on our fundamental freedoms.”
Additionally, the group demands complete transparency over data-sharing agreements with third parties and the creation of an independent watchdog of data collection practices.
In a later post, the group also mocked the EU for having “poorly secured” systems, warning that poorly designed frameworks only weaken security, harm the internet, and can expose “everything.”
There is no sufficient evidence to assess the group's real capabilities or technical sophistication, and they are unlikely to influence the EU’s political course in any meaningful way.
However, the group’s messaging aligns with broader privacy concerns about the potential impact of legislation that undermines end-to-end encryption. Digital rights advocates previously warned that client-side scanning exposes users to additional security risks and undermines privacy, and the Chat Control proposals sparked public backlash.