Skip to content
Data Breach

Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages

Russian intelligence-linked hackers are trying to seize Signal accounts by posing as support staff and asking targets for backup recovery keys. The campaign targets people with access to sensitive conversations, including officials, military personnel, political figures, journalists, and Ukrainian l...

· Jul 29, 2026 · 4 min read · 👁 0 views
Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages

Russian intelligence-linked hackers are trying to seize Signal accounts by posing as support staff and asking targets for backup recovery keys.

The campaign targets people with access to sensitive conversations, including officials, military personnel, political figures, journalists, and Ukrainian leaders.

It relies on deception, not a break in Signal’s end-to-end encryption, but the possible loss of private messages is still serious.

These messages create urgency by claiming that chats, media, or account data are about to disappear because of a synchronization problem.

A recipient is directed through backup settings, told to copy the recovery key, and then instructed to paste it into the chat.

The FBI has identified multiple Russian Intelligence Services clusters behind the ongoing commercial messaging application phishing activity against high-value individuals.

This change makes account recovery data a particularly valuable prize. When a target follows the directions, shares the key, and has stored messages in a backup, attackers can download historic private and group chats before assuming control of the account.

The agency stressed that individual accounts have been compromised, while the app itself and its encryption have not.

Russian Federal Security Service officers working with border guards, alongside people acting for Russian military services, are associated with the targeting.

The activity is publicly tracked as UNC5792 and UNC4221, and it continues a pattern covered in this earlier Signal phishing campaign

The FBI said in a report shared with Cyber Security News (CSN) that the operation remains ongoing and needs close attention from targeted communities.

Russian Intelligence Hackers Phish Signal Backup Keys

The attackers impersonate automated support accounts inside the messaging application, using language that appears official and presses victims to act quickly.

Some lures ask for verification codes or account PINs, while the updated messages focus on backup recovery keys. That switch is important because a recovery key can expose archived content that an attacker could not otherwise read from the service.

Victims face a lasting problem if they disclose one. The stolen key remains valid even when they set up a new account with the same phone number, potentially letting the intruders return later.

Generating a new backup recovery key in Settings invalidates the old key for future downloads, although it cannot undo a backup that has already been copied.

Sample Phishing Messages (Source - IC3)
Sample Phishing Messages (Source – IC3)

The Sample Phishing Message 1 shows a fake notice about changes to the messenger and mandatory two-factor verification. The Sample Phishing Message 2 uses a claimed data recovery issue and explicitly tells recipients to paste a recovery key into a chat.

The tactic aligns with a Signal backup theft wave that has targeted the trust users place in service notifications.

Protecting Sensitive Conversations

People who receive an unexpected account warning should not follow instructions contained in the message, even if the account looks legitimate.

Real support channels do not request verification codes inside the app, send links to verify or restore accounts, or ask users to disclose a recovery key. Recent FBI and CISA phishing guidance similarly stresses treating unsolicited security alerts with caution.

Users who may have shared a recovery key should generate a replacement in the backup settings immediately, then consider the historic backup exposed.

They should review active devices and account activity, change related credentials when appropriate, and retain the deceptive message for reporting.

The FBI asks victims to submit a complaint to IC3, contact a local FBI field office, or report the incident to CISA. Do not reuse a compromised key in any later recovery process.

Organizations supporting high-risk staff should make clear that an encrypted service can remain technically sound while an account is lost through social engineering.

Regular briefings on impersonation attempts can reduce the chance that urgent messages override good judgment.

The threat also reinforces lessons from Russian attacks on telecom networks, where access to communications can create wide operational and personal consequences. That risk extends beyond individual privacy to mission continuity and safety.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you