Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

FBI: Russian hackers now target Signal backup recovery keys

0
Low
Phishing
Published: 06/26/2026 (06/26/2026, 22:06:17 UTC)
Source: Bleeping Computer

Description

The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims' historical messages. [...]

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/26/2026, 22:06:31 UTC

Technical Analysis

This threat involves a phishing campaign attributed to Russian Intelligence Services targeting Signal users to steal their Backup Recovery Keys. The attackers impersonate Signal support teams and send messages claiming new mandatory two-factor verification, instructing users to enable backups and share their recovery keys. With the stolen recovery key, attackers can decrypt and access the victim's historical Signal messages stored in Signal's Secure Backups. The campaign targets individuals of high intelligence value, including government and military personnel, journalists, and political figures. The FBI and CISA emphasize that legitimate Signal support never requests recovery keys or verification codes via messaging. Users must generate new recovery keys after compromise to invalidate old keys for future backups, but this does not affect backups already accessed by attackers.

Potential Impact

If successful, attackers gain access to victims' historical Signal messages and media by decrypting backups using stolen recovery keys. This compromises the confidentiality of private and group conversations. The campaign specifically targets high-value individuals, potentially exposing sensitive communications. The compromise persists even if the victim creates a new Signal account with the same phone number unless a new recovery key is generated. However, attackers retain access to any backups already downloaded with the stolen key.

Mitigation Recommendations

No official patch is applicable as this is a phishing campaign exploiting user behavior. Users should be educated that legitimate Signal support never requests recovery keys or verification codes via messages or links. Users who suspect compromise should immediately generate a new Backup Recovery Key via Signal's settings to invalidate the old key for future backups. Reporting suspected incidents to the FBI's IC3, local FBI field offices, or CISA is recommended. Vigilance against phishing attempts impersonating Signal support is critical.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/fbi-russian-hackers-now-target-signal-backup-recovery-keys/","fetched":true,"fetchedAt":"2026-06-26T22:06:24.704Z","wordCount":1064}

Threat ID: 6a3ef7e027e9c7971902c06a

Added to database: 06/26/2026, 22:06:24 UTC

Last enriched: 06/26/2026, 22:06:31 UTC

Last updated: 06/27/2026, 01:47:42 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses