Russian intelligence-linked hackers have shifted tactics to target Signal users’ backup recovery keys, enabling full account takeover and access to historical message archives without breaking Signal’s end-to-end encryption.
The FBI and CISA are warning that this evolving phishing campaign focuses on high-value targets worldwide and abuses user trust in “support” messaging inside the app.
These groups are associated with Russian Federal Security Service (FSB) Border Guards and actors working on behalf of Russian military services, and they prioritize individuals of high intelligence value such as government officials, military personnel, journalists, political figures, and key Ukrainian officials.
The March 20, 2026 PSA (I-032026-PSA) initially detailed how RIS actors compromised thousands of commercial messaging application (CMA) accounts by phishing for verification codes and PINs, then linking attacker-controlled devices to victims’ accounts.
The June update clarifies that, while individual accounts have been compromised, neither Signal’s encryption nor the underlying application platform has been compromised, underscoring that the attack vector is social engineering rather than a cryptographic or application-level exploit.
Recent intelligence shows RIS operators now masquerade as automated Signal support or “CMA support” bots to push highly tailored phishing messages inside the messaging app.
The lures falsely claim that Signal has introduced mandatory two-factor verification following investigations allegedly conducted with the U.S. government and European partners into attacks by hackers from Iran and post-Soviet countries.
Victims are instructed to “secure” their accounts by enabling backups and then sharing their Backup Recovery Key, often via a fraudulent in-app flow that walks them through Settings → Backups → Enable backups → View recovery key and then prompts them to transmit that key to “support.”
FBI–CISA Public Service Announcement issued on June 25, 2026, clusters of Russian Intelligence Services (RIS) cyber actors tracked as UNC5792 and UNC4221 are running a sustained global campaign against commercial messaging applications, including Signal.
Once the actor obtains the Backup Recovery Key, they can decrypt and download full account backups, including historical private and group messages and media, and can then take over the account.
Signal Keys targeted
Critically, if a user later deletes their account and registers a new Signal account with the same phone number, the compromised Backup Recovery Key remains valid for future backup restores unless the user manually generates a new key in Settings.
This allows the actor to potentially re-take over the new account or re-access restored message history, even after an apparent “fresh start.”
FBI and CISA emphasize that legitimate CMA or Signal support will not request verification codes, account PINs, or Backup Recovery Keys via in-app messages.
Official support communication will use company email channels; they do not send links to “verify” or “restore” accounts, and they will never ask users to share sensitive codes or cryptographic keys as part of support interactions.
Users should immediately generate a new Backup Recovery Key within the app’s Settings to invalidate a suspected compromised key, recognizing this only prevents future backup downloads and does not retroactively revoke access to backups already exfiltrated by the actor.
CISA’s broader guidance on spyware targeting messaging apps, phishing defense, and mobile communications best practices underscores the need to treat unknown or unusual in-app messages as suspicious, scrutinize links and QR codes, and maintain hardened device security to prevent spyware-based interception of secure messaging sessions.
Victims or targeted individuals are urged to file complaints with the Internet Crime Complaint Center (IC3), notify their local FBI field office, and report incidents to CISA via the Incident Reporting System or the agency’s 24/7 Operations Center.
Additional technical and defensive guidance is available in FBI’s spoofing and phishing resources and CISA advisories on spyware targeting messaging applications, phishing lifecycle disruption, and mobile communications.
What Features Should AI SOC Have in 2026? A Complete Checklist : Download the AI SOC Features Checklist





