Russian Hackers Target Signal Users through Phishing Campaign
A recent security alert has revealed that hackers linked to Russian intelligence agencies have evolved their tactics to specifically target users of the popular messaging app, Signal. By focusing on the backup recovery keys, these hackers are able to gain full access to user accounts and their historical message archives while bypassing the app’s robust end-to-end encryption. This alarming development has prompted warnings from the FBI and the Cybersecurity and Infrastructure Security Agency (CISA).
Shift in Tactics
The phishing campaign, which has gained attention for its complexities, primarily aims at high-value targets across the globe. The attackers exploit user trust by misusing "support" messaging within the Signal app. These malicious actors have been identified as affiliated with the Russian Federal Security Service (FSB) Border Guards and groups linked to Russian military services. They prioritize individuals of significant intelligence interest, such as government officials, military personnel, journalists, political figures, and key officials from Ukraine.
The initial Public Service Announcement (PSA) issued on March 20, 2026, outlined how these Russian Intelligence Services (RIS) actors managed to compromise thousands of accounts across various commercial messaging applications. They did this by phishing for verification codes and personal identification numbers (PINs), subsequently linking their devices to the victims’ accounts. However, a June update clarified a crucial point: while many accounts have indeed been compromised, neither Signal’s encryption nor the underlying application itself has been broken. This indicates that the attack relies on social engineering tactics rather than any exploit at the cryptographic or application level.
Sophisticated Phishing Techniques
Recent intelligence indicates that RIS operators have adopted new strategies to impersonate automated Signal support or "CMA support" bots. They send highly tailored phishing messages that appear legitimate within the app. Victims of these attacks are misled into believing that Signal has introduced mandatory two-factor authentication following investigations purportedly conducted with U.S. government agencies and European partners regarding attacks from hackers originating in Iran and post-Soviet regions.
The phishing attempts typically instruct victims to "secure" their accounts by activating backups, ultimately leading them to share their Backup Recovery Key. This often occurs through a fraudulent in-app process that guides users through the Settings menu, encouraging them to enable backups and view their recovery keys, which they are then prompted to send to the bogus "support" source.
Ongoing Cyber Threat
In a Public Service Announcement dated June 25, 2026, the FBI and CISA identified clusters of cyber actors traced back to RIS operating groups labeled UNC5792 and UNC4221. This sustained campaign targets various commercial messaging applications, including Signal. Once the attackers successfully obtain the Backup Recovery Key, they can decrypt and then download full account backups, which contain private messages, group chats, and media files. Consequently, they gain complete control over the compromised account.
A significant concern arises from the fact that if a user deletes their Signal account and subsequently registers a new one with the same phone number, the previously compromised Backup Recovery Key remains valid for any future backup restorations unless the user takes the proactive step of manually creating a new key within the app Settings. This opens a potential window for attackers to regain access or restore message histories from the new account, effectively undermining any perceived fresh start by the user.
Official Guidance and Best Practices
In response to this evolving threat landscape, both the FBI and CISA emphasize that legitimate support communication from Signal or any commercial messaging application will never request verification codes, account PINs, or Backup Recovery Keys through in-app messages. Official communications will always utilize recognized company email channels, with no requests for users to verify or restore accounts by sharing sensitive codes or cryptographic keys.
To mitigate the risks, users are strongly urged to generate a new Backup Recovery Key in the app’s settings to invalidate any potentially compromised keys. It is imperative to note that while this action will prevent future backup downloads, it will not retroactively revoke access to any backups that have already been improperly accessed by the attackers.
CISA has issued broader guidance on spyware targeting messaging applications, emphasizing the importance of treating unusual or unknown in-app messages as suspicious. Users are encouraged to scrutinize links and QR codes, as well as maintain robust device security to prevent spyware from intercepting their secure messaging sessions.
Individuals who suspect they may be victims of this campaign are urged to report incidents to the Internet Crime Complaint Center (IC3), contact their local FBI field office, and share incidents with CISA through its Incident Reporting System. Additional resources and defensive guidance can be found in the FBI’s materials on spoofing and phishing, along with CISA advisories detailing best practices for protecting against cyber threats to messaging applications.
