discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys

The FBI warns of Russian intelligence hackers targeting Signal users' backup recovery keys. Hackers use social engineering to obtain keys, allowing them to access account backups and message history.

By Swati Khandelwal·Jun 26·thehackernews.com·2 min read

Intelligence analysis by Llama 3.3 70B

FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
Image: thehackernews.com

Russian intelligence hackers are using phishing tactics to obtain Signal users' backup recovery keys, which can be used to access account backups and message history. The FBI has updated its warning to include new tactics used by the hackers.

Why it matters

This story matters to those following Security because it highlights the ongoing threat of Russian intelligence hackers targeting individuals with high intelligence value, including government officials and journalists. The use of social engineering tactics to obtain sensitive information is a significant concern.

Russian hackers are trying to trick people into giving them a special key that can unlock their private messages on Signal. They're doing this by pretending to be Signal support and asking people to hand over the key. If you get a message like this, don't give them the key!

Analysis

Russian Intelligence Hackers' Tactics

The FBI has warned of Russian intelligence hackers using phishing tactics to obtain Signal users' backup recovery keys. The hackers pose as Signal support and ask users to hand over their recovery keys, which can be used to access account backups and message history. The FBI has updated its warning to include new tactics used by the hackers, including the use of doctored 'group invite' links that silently link an attacker's device to the account.

The hackers are targeting individuals with high intelligence value, including current and former U.S. and international government officials, military personnel, political figures, journalists, and officials in Ukraine. The campaign has already compromised thousands of accounts worldwide, according to the FBI.

Impact of the Hack

The impact of the hack is significant, as it allows the hackers to access sensitive information, including private and group message history. The hackers can also use the recovery key to take over the account, allowing them to send messages and make calls on behalf of the user. The FBI has warned that the recovery key can still be used even if the user generates a new one, making it essential for users to take immediate action to protect their accounts.

Protection Measures

To protect themselves, Signal users are advised to treat any in-app message from 'Signal support' as hostile and never paste their backup recovery key, verification code, or PIN into a chat. Users should also check their linked devices and remove any unrecognized devices. If a user thinks they have handed over their recovery key, they should generate a new one immediately and assume any backup made before that is already in someone else's hands.

International Cooperation

The FBI's warning is part of a broader international effort to combat Russian intelligence hackers. The State Department's Rewards for Justice program is offering up to $10 million for information on UNC5792, one of the groups involved in the hacking campaign. The activity overlaps with warnings from Dutch intelligence, Germany's BfV and BSI, and France's ANSSI earlier this year. Google's Threat Intelligence Group first documented UNC5792 abusing Signal's linked-device feature in early 2025, and saw the same tradecraft turn up against WhatsApp and Telegram.

Key points

  • Russian intelligence hackers are targeting Signal users' backup recovery keys
  • Hackers use social engineering tactics to obtain keys
  • The campaign has already compromised thousands of accounts worldwide
  • Users are advised to treat any in-app message from 'Signal support' as hostile
The Upside

The FBI's warning and the international cooperation to combat Russian intelligence hackers may help to reduce the number of compromised accounts and prevent further hacking attempts. Signal users who take immediate action to protect their accounts can also minimize the damage.

The Downside

The hacking campaign has already compromised thousands of accounts worldwide, and the use of social engineering tactics makes it difficult for users to protect themselves. The fact that the recovery key can still be used even if the user generates a new one makes it a significant concern.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityrussian-intelligencesignalphishingsocial-engineering

Author

Swati Khandelwal

Intelligence analysis by

Llama 3.3 70B

Published

Jun 26, 2026

Source

thehackernews.com

Share

Topics

securityrussian-intelligencesignalphishingsocial-engineering

Related

More from this desk

Aug 14·bleepingcomputer.com

Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw

Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts.

Aug 14·schneier.com

Upcoming Speaking Engagements

Bruce Schneier shares his upcoming speaking engagements, including LAcon V in Anaheim, California, USA, a League of Women Voters event, Elevate Festival in Toronto, Canada, CanSecWest 2026 in Vancouver, Canada, and ATTENTION: Democracy, Rebuilt in Montreal, Canada.

Aug 14·bleepingcomputer.com

Hackers Exploit macOS Screen Sharing Flaw to Deploy Monero Miner

NCSC warns of active macOS vulnerability exploitation for cryptocurrency mining.

Aug 14·bleepingcomputer.com

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

The article discusses the evolving attack chain in Google Workspace security, where OAuth tokens become the entry point for attackers, and AI agents are increasingly used to exploit vulnerabilities. The author argues that security teams need to rethink their defenses to a…