Particle.news
Download on the App Store

Russian Intelligence Hackers Target Signal Backup Recovery Keys

U.S. agencies say the tactic lets attackers restore encrypted cloud backups to read past private and group chats.

Overview

  • The FBI and CISA updated their advisory on June 26, 2026, warning that actors tied to Russian intelligence have evolved phishing tactics to trick Signal users into revealing their Backup Recovery Key.
  • Attackers impersonate in‑app Signal support and guide victims to enable backups, copy the Recovery Key, and paste it into chats so the attacker can restore encrypted backups and access historical messages.
  • The agencies stress this is social engineering that exploits legitimate Signal features rather than a break of the app’s encryption and have publicly tracked the clusters as UNC5792 and UNC4221.
  • Users who believe they shared a key are told to never paste recovery keys into chats, to remove unknown linked devices, and to generate a new Backup Recovery Key in Signal settings because creating a new account alone does not invalidate a stolen key.
  • The update follows months of related tradecraft that stole verification codes and linked devices, draws corroboration from Dutch, German and French agencies and Google, and the State Department is offering up to $10 million for information on UNC5792.