FBI and CISA warn Russian intelligence hackers are phishing for Signal backup recovery keys to read past messages

The FBI and CISA say Russian intelligence-linked hackers are now trying to trick Signal users into handing over backup recovery keys, which can let the attackers restore and read victims’ past messages. The updated June 2026 public service announcement says the campaign, tracked as UNC5792 and UNC4221, previously focused on stealing Signal verification codes, PINs, or linking attacker-controlled devices, but now impersonates Signal support to push victims into enabling Secure Backups and then sending the recovery key needed to decrypt stored message history.
Why it matters: This matters because it can expose not just future chats but a victim’s historical Signal conversations, including sensitive government, military, journalistic, and Ukraine-related communications. At-risk users should treat any messages claiming to be from Signal support as suspicious, never share backup recovery keys, and review linked devices and backup settings immediately.

Sources

FBI: Russian hackers now target Signal backup recovery keys
Lawrence Abrams 2026.06.26 100% relevant
This article establishes a distinct, updated phase of a Russian intelligence phishing campaign: the shift from hijacking Signal accounts via codes or linked devices to stealing Signal Secure Backup recovery keys to access historical messages.
← Back to all stories