The European Union’s controversial Chat Control proposals have become the focus of threats from a little-known hacktivist group that claims it is prepared to target EU systems if lawmakers continue pursuing the legislation. Although the group says it has already identified security weaknesses within European institutions, there is no publicly available evidence confirming those claims or showing that any EU systems have been compromised.
The threats were published on Telegram by a group calling itself LunarisSec, which issued what it described as an ultimatum demanding that the European Union abandon both the existing Chat Control 1.0 framework and the proposed Chat Control 2.0 legislation. The group argues that the measures would weaken the privacy and security of online communications by expanding the scanning of private messages for child sexual abuse material.
The current legal framework allows online platforms to voluntarily scan unencrypted communications for child sexual abuse material and is scheduled to remain in force until 2028. Chat Control 2.0, which is still under discussion and has not been adopted, is intended to replace those temporary rules with permanent legislation. The proposal has generated significant debate because of concerns about its potential impact on end-to-end encrypted services.
LunarisSec claims it has discovered vulnerabilities affecting European Union systems and warned that those weaknesses could be exploited if its demands are ignored. The group also published several heavily edited screenshots that it says demonstrate access to internal resources and contact information belonging to EU officials. However, it did not release technical evidence or data samples that would allow independent verification of those assertions.
Beyond calling for the withdrawal of the legislation, the group also demanded greater transparency around data-sharing arrangements and stronger independent oversight of data collection practices within the European Union. In subsequent messages, it criticised what it described as inadequate security measures protecting EU infrastructure, arguing that poorly designed digital policies ultimately increase cyber risk rather than reduce it.
Despite its public statements, relatively little is known about LunarisSec. The group’s current Telegram channel has been active since January 2026, although it says previous accounts were removed. Earlier posts primarily referenced the identification and responsible disclosure of vulnerabilities affecting organisations in France. To date, however, major cybersecurity companies have not publicly attributed confirmed cyberattacks or significant vulnerability discoveries to the group, and its technical capabilities remain unclear.
The group’s threats emerged shortly after discussions surrounding Chat Control resumed in the European Parliament, but there is no indication they have influenced the legislative process. Separately from LunarisSec’s campaign, privacy organisations and digital rights advocates have continued to oppose aspects of the proposed legislation through legal and political channels, arguing that measures affecting encrypted communications could introduce new security and privacy risks. Supporters of the proposals, meanwhile, maintain that stronger tools are needed to help detect and combat the online distribution of child sexual abuse material.