VYPR
breachPublished Jun 26, 2026· Updated Jun 29, 2026· 4 sources

Ukraine and FBI Uncover Russian Social Engineering Campaign Targeting Messaging Accounts

Ukraine's SBU, working with the FBI, has exposed a long-running Russian operation that uses fake tech-support messages to steal credentials for messaging apps from officials and activists across Ukraine, Europe, and the US.

Ukraine's Security Service (SBU) announced on Thursday that it has uncovered, in coordination with the FBI, a sustained Russian campaign to compromise the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe, and the United States. The operation, which has been active for an extended period, aims to steal sensitive military, political, and economic information exchanged through messaging applications, as well as victims' personal data.

The attackers rely on social engineering rather than exploiting technical vulnerabilities in the messaging apps themselves. According to the SBU, one of the most common methods involves sending text messages that impersonate official messaging platform support services, urging users to disclose their account credentials. "The messages are sent in the morning hours, when users are particularly vulnerable due to their physical and emotional state," the SBU said in its statement.

The campaign targeted a broad range of victims, including government institutions, public officials, activists, and ordinary Ukrainian citizens. The SBU did not identify which Russian intelligence service is responsible, nor did it specify which messaging platforms were primarily targeted or how many victims have been affected. The FBI did not immediately respond to a request for comment.

This disclosure follows a series of warnings from Ukraine and Western intelligence agencies about Russian efforts to compromise secure messaging platforms used by government and military personnel. Earlier this year, Dutch intelligence agencies warned that Russian state-backed hackers were conducting a global campaign to hijack Signal and WhatsApp accounts belonging to government officials, diplomats, and military personnel. In those attacks, the perpetrators typically posed as customer support workers to trick victims into sharing one-time verification codes or PINs.

Ukraine has previously reported Russian espionage operations targeting messaging applications used by its military, including campaigns involving data-stealing malware and attempts to extract encrypted Telegram and Signal communications from mobile phones captured on the battlefield. The latest SBU disclosure underscores the persistent and evolving nature of Russian cyber espionage tactics, which increasingly focus on compromising communication channels rather than exploiting software flaws.

The SBU's collaboration with the FBI highlights the international scope of the threat and the importance of cross-border intelligence sharing. The campaign's targeting of individuals across multiple countries suggests a coordinated effort to gather intelligence on a wide range of geopolitical and military matters. As messaging apps become integral to both personal and professional communication, such social engineering attacks pose a significant risk to national security and individual privacy.

Organizations and individuals are advised to remain vigilant against unsolicited messages requesting credentials or verification codes, even if they appear to come from legitimate support services. Enabling multi-factor authentication and using unique, strong passwords can help mitigate the risk of account compromise. The SBU's warning serves as a reminder that the human element remains the most vulnerable link in cybersecurity, and that attackers will continue to exploit it.

The SSU and FBI revealed that the attackers specifically targeted Signal and WhatsApp accounts, sending SMS messages impersonating the platforms' support bots to trick victims into disclosing credentials. The campaign extended beyond Ukraine to targets in Europe and the US, with the FBI attributing the activity to Russian Intelligence Services (RIS) as part of an ongoing commercial messaging application phishing campaign. CERT-UA also linked a related spear-phishing campaign using compromised accounts to deliver the OYSTERBLUES information stealer to the Belarus-aligned threat actor UNC1151.

The U.S. State Department has now announced a $10 million reward for information leading to the identification or location of individuals associated with the Russian state-sponsored hacking groups UNC5792 and UNC4221. This escalation highlights the U.S. government's focus on disrupting these specific espionage campaigns that target sensitive communications through social engineering tactics on encrypted messaging platforms.

The latest alert from the FBI and CISA reveals that Russian military hackers have evolved their tactics, now specifically targeting users' backup recovery keys and account PINs for Signal and WhatsApp. This social engineering approach bypasses the apps' end-to-end encryption, allowing attackers to gain direct and persistent access to accounts, even if a user creates a new one with the same phone number. The campaign continues to target high-value individuals across multiple jurisdictions, including government officials and journalists.

Synthesized by Vypr AI