VYPR
advisoryPublished Jul 29, 2026· 1 source

Russian Intelligence Hackers Target Signal Users with Backup Key Phishing

Russian intelligence-linked hackers are impersonating Signal support staff to trick high-value individuals into revealing their backup recovery keys, potentially compromising past messages and accounts.

Russian intelligence-linked hackers are actively targeting high-profile individuals, including government officials, journalists, and political figures, with a sophisticated phishing campaign designed to steal Signal backup recovery keys. The attackers impersonate Signal support staff, fabricating urgent scenarios such as synchronization problems or impending data loss to coerce victims into sharing their sensitive recovery keys. This tactic, while not exploiting Signal's end-to-end encryption, poses a significant threat to user privacy by enabling access to historical messages and account hijacking.

The campaign's primary objective is to obtain the Signal backup recovery key, a crucial element for restoring encrypted chat histories. Attackers leverage social engineering by creating a sense of urgency, prompting victims to navigate to their backup settings, copy their recovery key, and then paste it directly into the chat with the fake support agent. The FBI has identified multiple Russian Intelligence Services (RIS) clusters, specifically tracking this activity under UNC5792 and UNC4221, indicating a coordinated and ongoing effort.

Successful phishing attempts allow attackers to download past private and group chats stored in a backup. Crucially, the stolen recovery key remains valid even after a user generates a new account with the same phone number. While generating a new key invalidates the old one for future backups, it cannot undo data that has already been exfiltrated. This persistent threat means compromised accounts could be revisited by attackers.

The FBI's report highlights that the Signal application and its encryption remain secure, with compromises occurring solely through social engineering tactics targeting user credentials and recovery data. The operation is reportedly linked to Russian Federal Security Service (FSB) officers and individuals acting on behalf of Russian military intelligence, underscoring the state-sponsored nature of the attacks.

This campaign represents an evolution from previous phishing attempts against Signal, with a specific focus on the backup recovery key as a more valuable target than simple verification codes or account PINs. The attackers exploit the trust users place in official-looking notifications and the perceived security of encrypted messaging applications.

To mitigate this threat, users are advised to exercise extreme caution with unsolicited account warnings or support messages, even if they appear legitimate. Genuine Signal support channels do not request verification codes within the app, send external links for verification, or ask for recovery keys. Users who may have inadvertently shared a recovery key should immediately generate a replacement in their backup settings, consider their historic backup compromised, review active devices, and change related credentials.

The FBI urges victims to report such incidents to the Internet Crime Complaint Center (IC3), a local FBI field office, or CISA. The ongoing nature of this threat necessitates heightened awareness among targeted communities, particularly those handling sensitive information, to prevent the compromise of private communications and ensure the continuity of operations and personal safety.

Synthesized by Vypr AI