
Ukraine’s national cybersecurity team (CERT-UA) has revealed that hackers linked to Russian intelligence have been sending fake “customer support” text messages to trick people into surrendering their one-time login codes for Signal and Telegram. The texts look like official security alerts from the apps, asking you to confirm your identity by sharing a six-digit verification code. Once you do, the attacker uses that code in real time to take over your account — reading your private messages, impersonating you to your contacts, and potentially locking you out permanently.
While the campaign primarily targeted people in Ukraine, the trick itself is old and universal. Scammers worldwide use the same approach — a fake “support” text, a sense of urgency, and a request for a code you should never share — and it can arrive on any phone anywhere.
How to check if you’re affected
Affected devices include any Android or iOS phone or tablet with Signal or Telegram installed. You can take two quick steps to check your accounts:
- In Signal: go to Settings → Linked Devices. Any device listed that you don’t recognise should be unlinked immediately.
- In Telegram: go to Settings → Privacy and Security → Active Sessions. End any session on a device or location you don’t recognise.
If you received an unexpected text claiming to be from app support and you shared a code, treat your account as compromised and follow each app’s account-recovery process right away.
