U.S. — The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) issued a public service announcement warning that a phishing campaign targeting Signal users has evolved to steal Signal Backup Recovery Keys. The campaign, attributed to Russian Intelligence Services (RIS), allows attackers to access victims' historical messages.
The campaign targets individuals of high intelligence value, including current and former U.S. and international government officials, military personnel, political figures, journalists, and key officials in Ukraine. RIS, including officers embedded with Russia's Federal Security Service (FSB) Border Guards and other actors working on behalf of the Russian military, are identified as perpetrating this activity. The campaign is publicly tracked under the names UNC5792 and UNC4221.
The announcement updates a March 2026 advisory that warned of threat actors targeting users of commercial messaging applications, particularly Signal, through phishing campaigns designed to hijack accounts by attempting to steal verification codes or account PINs, or to trick users into linking attacker-controlled devices.
The FBI stated in the announcement: "RIS cyber threat actors continue to masquerade as automated CMA support accounts in updated phishing messages but have evolved their tactics to attempt to elicit victims' Backup Recovery Keys." The threat actors impersonate Signal support teams and send phishing messages claiming Signal is introducing mandatory two-factor verification following an alleged wave of attacks. A second phishing message warns that data is at risk of loss due to a synchronization issue, stating: "Your Signal Account data (messages and media) is at risk of permanent loss due to a sync issue."
Victims are prompted to copy their recovery key to the clipboard and paste it into the message to prevent the loss of stored data. Signal's Secure Backups feature stores encrypted copies of conversations on Signal's cloud servers, with the data end-to-end encrypted using a recovery key created during setup. Anyone with this recovery key can use it to recover backed-up data on their own devices. Once attackers obtain the recovery key, they can restore the backup to their own devices and access the victim's historical messages.
If an attacker obtains a user's Backup Recovery Key, creating a new Signal account with the same phone number does not invalidate the stolen key. Users must generate a new Backup Recovery Key through Signal's backup settings to invalidate the previous key for future backup downloads. However, generating a new recovery key will not prevent attackers from accessing backups they have already downloaded using the compromised key. Legitimate messaging application support teams communicate only through official company email addresses, never request verification codes within the application, and do not send links asking users to verify or restore their accounts. The FBI encourages anyone who believes they have been victimized by this campaign to report the incident to the FBI's Internet Crime Complaint Center (IC3), a local FBI field office, or CISA.
forum Comments (0)
No comments yet. Be the first to comment.