Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > FBI Warns Russian State Hackers Are Tricking Signal Users Into Handing Over Backup Keys
FBI Warns Russian State Hackers Are Tricking Signal Users Into Handing Over Backup Keys
Read Time:3 Minute, 21 Second

The FBI has issued a warning that hacking clusters linked to Russian intelligence services are running an active phishing campaign designed to steal Signal backup recovery keys from high-value targets, including government officials, military personnel, political figures, journalists, and Ukrainian leadership. The bureau attributes the activity to groups publicly tracked as UNC5792 and UNC4221, tied to Russia’s Federal Security Service and military intelligence.

A Social Engineering Play, Not a Cryptographic Break

Signal’s end-to-end encryption itself remains intact — this campaign works entirely through deception. Attackers pose as automated support accounts inside the messaging app and send urgent-sounding notices claiming a synchronization problem is about to wipe the target’s chats, media, or account data. Earlier waves of this same campaign asked victims to hand over verification codes or account PINs; the newer messages have shifted focus specifically to backup recovery keys.

That shift matters because a recovery key unlocks something an attacker can’t otherwise reach: an offline archive of a user’s message history. Victims are walked through Signal’s own backup settings, told to copy their recovery key, and then instructed to paste it directly into a chat with the impersonator. Once an attacker has that key and the victim has a stored backup, they can download the full archive of historic private and group conversations before moving to take over the account itself.

Why the Threat Doesn’t End When the Message Is Deleted

A stolen recovery key doesn’t expire just because the victim deletes the suspicious conversation. According to the FBI, the key remains usable even if the victim later sets up a new account under the same phone number, potentially giving intruders a way back in down the line. The only way to fully close that door is to generate a new backup recovery key from within Signal’s settings, which invalidates the old one for future downloads — though it can’t undo a backup an attacker has already copied.

  • Lure 1: a fake notice about mandatory two-factor verification tied to app changes.
  • Lure 2: a claimed data recovery issue that explicitly instructs the recipient to paste their recovery key into the chat.
  • Both lures rely on urgency and the appearance of an official support channel to override normal caution.

Real Support Never Asks for This

The FBI’s guidance is unambiguous: legitimate Signal support channels do not request verification codes inside the app, send links asking users to “verify” or “restore” an account, or ask anyone to disclose a recovery key under any circumstance. Anyone who receives an unexpected account warning — even one that looks polished and official — should ignore embedded instructions and navigate to account or backup settings independently rather than following a link or prompt from the message itself.

What to Do If You Think You’ve Been Targeted

Anyone who may have shared a recovery key should treat their historic backup as compromised immediately and generate a replacement key through Signal’s settings without delay. From there, the FBI recommends reviewing linked devices and recent account activity, rotating related credentials where appropriate, and preserving the phishing message itself for reporting purposes. Victims can file a complaint with the FBI’s Internet Crime Complaint Center (IC3), contact a local FBI field office, or report the incident to CISA. Under no circumstances should a potentially compromised key be reused in a later recovery process.

A Pattern With Real-World Stakes

This isn’t an isolated incident — it continues a pattern of Signal-focused phishing that CSN and other outlets have tracked for months, and it echoes broader Russian efforts to compromise communications infrastructure used by people covering or participating in the war in Ukraine. For organizations supporting journalists, officials, or military personnel in high-risk roles, the takeaway is that an app’s encryption can be mathematically sound while an individual account is lost entirely to social engineering. Regular briefings on impersonation tactics, and a standing rule that no security prompt inside a messaging app should ever be trusted at face value, remain the most effective defense against this kind of campaign.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on FBI Warns Russian State Hackers Are Tricking Signal Users Into Handing Over Backup Keys, use the discussion on Forum.

>> forum community

Comments

Leave a Reply