The FBI and CISA have issued an updated warning that Russian intelligence services are actively targeting Signal users through sophisticated phishing campaigns aimed at stealing backup recovery keys. The advisory, building on a March 2026 alert, identifies threat actors tracked as UNC5792 and UNC4221 — groups linked to Russia’s FSB and military intelligence — as specifically going after current and former government officials, military personnel, political figures, journalists, and key Ukrainian officials.

The attackers impersonate automated Signal support accounts, sending messages claiming that Signal is implementing mandatory two-factor verification due to alleged attacks. Victims are instructed to enable Signal backups, copy their Backup Recovery Key, and paste it into the chat under the guise of preventing permanent data loss. With a stolen recovery key, attackers can restore backed-up conversations — including private and group chats — on their own devices.

Critically, the FBI notes that creating a new Signal account with the same phone number does not invalidate a stolen key; users must generate a new recovery key through Signal’s backup settings to mitigate. However, this won’t prevent access to backups already downloaded with the compromised key.

Sources

Commentary

This campaign is a textbook example of why social engineering remains the sharpest tool in any intelligence service’s kit. Signal’s end-to-end encryption isn’t being broken — the attackers are simply convincing targets to hand over the keys. The impersonation of automated support accounts adds a layer of plausibility that catches people off guard, especially when combined with urgency framing.

The operational detail here is worth noting for both red and blue teams. The recovery key mechanism is a backup feature that most users never think about from a security perspective, making it a perfect social engineering target. For anyone in a high-risk role, the takeaway is blunt: never share recovery keys in-app, treat any “Signal support” message requesting credentials as hostile, and consider whether you need cloud backups enabled at all.

By Allan