TL;DR
FBI warns Russian hackers are phishing Signal users for backup recovery keys, giving persistent access to message history.
The FBI and CISA have warned that Russian intelligence hackers are now targeting Signal users’ backup recovery keys, an escalation of a phishing campaign that has already compromised thousands of accounts worldwide. The updated advisory, published Thursday, says that handing over the key once gives attackers the ability to restore an account’s backup, read its entire private and group message history, and take over the account.
The key keeps working even after the victim changes phones. If a target creates a new account on the same phone number, the old recovery key can still be used to access future backups, the advisory warns. The only fix is to generate a new key in Signal’s settings, which invalidates the old one for future downloads but cannot recover anything the attacker has already pulled.
The advisory, designated PSA I-062626-PSA, adds two public tracking names the FBI’s March notice did not include: UNC5792 and UNC4221. The bureau ties the activity to multiple Russian Intelligence Services groups, including FSB officers embedded with the FSB Border Guards and others working for the Russian military. The campaign targets both Signal and WhatsApp, though the recovery key tactic is specific to Signal.
The targets are individuals the FBI describes as being of “high intelligence value,” including current and former US and international government officials, military personnel, political figures, journalists, and officials in Ukraine. The March advisory said the broader campaign had already compromised thousands of accounts worldwide.
The phishing messages pose as Signal support. Earlier waves asked for SMS verification codes and account PINs, or used doctored “group invite” links that silently linked an attacker’s device to the victim’s account. The updated version walks targets through turning on Signal backups, opening the recovery key screen, and pasting the key into the chat.
The FBI published two sample messages used in the campaign. One is disguised as a mandatory two-factor authentication rollout, and the other poses as an urgent “data recovery” fix for messages supposedly at risk of being lost. Both are social engineering attacks that exploit trust in a platform’s own interface rather than technical vulnerabilities.
The agencies are clear that none of these techniques break Signal’s encryption or the app itself. The attackers compromise individual accounts through social engineering, then walk in through a legitimate feature. It is a pattern that has become increasingly common across security products, where the weakest link is the person holding the device, not the cryptography protecting the data.
Alongside the advisory, the State Department’s Rewards for Justice programme is offering up to $10 million for information on UNC5792. The activity overlaps with earlier warnings from Dutch intelligence agencies AIVD and MIVD, Germany’s BfV and BSI, and France’s ANSSI. Google’s Threat Intelligence Group first documented UNC5792 abusing Signal’s linked-device feature in early 2025 and later observed the same tradecraft targeting WhatsApp and Telegram.
The campaign is a reminder that end-to-end encryption protects messages in transit but cannot protect users who are persuaded to hand over the keys themselves. Anyone who receives a message inside Signal asking for a recovery key, verification code, or PIN should treat it as hostile, regardless of how convincing the sender appears. Signal does not message users inside the app to request credentials.


