Menu Close

FBI Warns Russian Intelligence Is Targeting Signal Backup Recovery Keys to Access Private Messages

Image Credentials: Image Title: FBI Warns Russian Intelligence Is Targeting Signal Backup Recovery Keys to Access Private Messages. Source: (chatgpt.com) Date: June 2026. Attribution: This image was created using AI-generated imagery (chatgpt.com) by Open Chronicle and does not depict a real-world scene.

By Open Chronicle News Desk with Agencies

The US Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued an updated cybersecurity advisory warning that Russian intelligence services have changed tactics in ongoing phishing campaigns targeting users of the encrypted messaging platform Signal.

According to the updated alert, Russian intelligence operators are now attempting to steal Signal Backup Recovery Keys, a move that could allow attackers to gain access to victims’ entire message histories and potentially take long-term control of their accounts.

Russian intelligence changes tactics

The original warning, issued in March 2026, focused on phishing campaigns in which Russian intelligence operatives attempted to obtain Signal verification codes, account PINs, or trick victims into linking an attacker-controlled device to their accounts.

The latest advisory states that the threat actors have now shifted their primary objective toward obtaining Backup Recovery Keys, which provide significantly broader access.

The FBI identifies the activity as being linked to Russian intelligence associated with threat groups tracked as UNC5792 and UNC4221. According to US authorities, the campaigns have primarily targeted government officials, military personnel, journalists, diplomats, and Ukrainian officials.

Recovery Keys present a greater risk

Unlike temporary verification codes, a Signal Backup Recovery Key allows access to a user’s encrypted backup archive.

If a victim enables backups and provides the Recovery Key to an attacker through a phishing message, the attacker may be able to access historical conversations, including private chats and group messages.

The FBI warns that the key remains valid even if the victim later creates a new Signal account using the same phone number, unless a completely new Recovery Key is generated.

Authorities stress that generating a new key only prevents future access and does not remove copies of data that attackers may have already downloaded.

Social engineering rather than encryption flaws

The advisory emphasizes that Signal’s encryption has not been compromised.

Instead, Russian intelligence operators are relying on sophisticated social engineering techniques, impersonating official Signal support accounts and sending convincing in app messages requesting users to enable backups and share their Recovery Keys.

According to the FBI, these messages often claim that users must complete a mandatory security update or urgently recover messages that are supposedly at risk of permanent deletion.

Officials stress that Signal’s support team never contacts users through the application to request Recovery Keys, PINs, or verification codes.

International investigation continues

The updated warning follows earlier assessments by intelligence and cybersecurity agencies in the Netherlands, Germany and France, as well as previous research published by Google’s Threat Intelligence Group documenting Russian efforts to abuse Signal’s linked device functionality.

US authorities say similar tactics have also been observed targeting users of WhatsApp and Telegram.

The US State Department’s Rewards for Justice program has announced a reward of up to $10 million for information leading to the identification or disruption of individuals associated with UNC5792.

FBI urges immediate precautions

The FBI recommends that Signal users regularly review the application’s Linked Devices section and immediately remove any unfamiliar devices.

Users who believe they may have shared a Backup Recovery Key are advised to generate a new key immediately and assume that any backups created before the change may already have been compromised.

Officials conclude that while Signal’s encryption remains secure, attackers are increasingly focusing on exploiting users rather than attempting to break the technology itself.

Leave a Reply

Your email address will not be published. Required fields are marked *