
The FBI and cybersecurity researchers warn that Russian intelligence operatives — specifically groups tracked as UNC5792 and UNC4221 and linked to the FSB and Russian military — are running a new phishing campaign against Signal users. The attack is simple but effective: imposters pretend to be Signal’s support team and send messages claiming that a mandatory security check is required. They instruct the victim to enable Signal’s Secure Backup feature and then paste their backup recovery key into the chat. Once the attacker has that key, they can restore the victim’s full Signal message history on any device they control.
Signal’s encrypted messages are normally unreadable without the device they’re on. The backup recovery key is essentially a master unlock for a copy stored on Signal’s servers — so handing it over bypasses Signal’s strongest protection. While the campaign has focused on government officials, military personnel, journalists, and Ukrainian officials, phishing attacks rarely stay neatly targeted.
How to check if you’re affected
Affected versions of Signal include any version with the Secure Backups feature enabled. Open Signal, go to Settings → Account → Signal Backups, and check whether backups are active.
- Never share your recovery key with anyone. Signal’s actual support team will never ask for it in a chat, an email, or any message. If someone does, it’s a scam.
- If you’ve already shared a key, generate a new one immediately: Settings → Account → Signal Backups → Change recovery key. Note that this doesn’t undo access already gained from the previous key, but it prevents future use of the stolen one.
- Verify who’s contacting you. Legitimate Signal support only communicates through official channels. Treat any in-app message claiming to be from “Signal Support” as suspicious.
- Report phishing attempts to the FBI’s Internet Crime Complaint Center at ic3.gov.
