FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
The FBI warns of Russian intelligence hackers targeting Signal users' backup recovery keys. Hackers use social engineering to obtain keys, allowing them to access account backups and message history.
Intelligence analysis by Llama 3.3 70B

Russian intelligence hackers are using phishing tactics to obtain Signal users' backup recovery keys, which can be used to access account backups and message history. The FBI has updated its warning to include new tactics used by the hackers.
Russian hackers are trying to trick people into giving them a special key that can unlock their private messages on Signal. They're doing this by pretending to be Signal support and asking people to hand over the key. If you get a message like this, don't give them the key!
Analysis
Russian Intelligence Hackers' Tactics
The FBI has warned of Russian intelligence hackers using phishing tactics to obtain Signal users' backup recovery keys. The hackers pose as Signal support and ask users to hand over their recovery keys, which can be used to access account backups and message history. The FBI has updated its warning to include new tactics used by the hackers, including the use of doctored 'group invite' links that silently link an attacker's device to the account.
The hackers are targeting individuals with high intelligence value, including current and former U.S. and international government officials, military personnel, political figures, journalists, and officials in Ukraine. The campaign has already compromised thousands of accounts worldwide, according to the FBI.
Impact of the Hack
The impact of the hack is significant, as it allows the hackers to access sensitive information, including private and group message history. The hackers can also use the recovery key to take over the account, allowing them to send messages and make calls on behalf of the user. The FBI has warned that the recovery key can still be used even if the user generates a new one, making it essential for users to take immediate action to protect their accounts.
Protection Measures
To protect themselves, Signal users are advised to treat any in-app message from 'Signal support' as hostile and never paste their backup recovery key, verification code, or PIN into a chat. Users should also check their linked devices and remove any unrecognized devices. If a user thinks they have handed over their recovery key, they should generate a new one immediately and assume any backup made before that is already in someone else's hands.
International Cooperation
The FBI's warning is part of a broader international effort to combat Russian intelligence hackers. The State Department's Rewards for Justice program is offering up to $10 million for information on UNC5792, one of the groups involved in the hacking campaign. The activity overlaps with warnings from Dutch intelligence, Germany's BfV and BSI, and France's ANSSI earlier this year. Google's Threat Intelligence Group first documented UNC5792 abusing Signal's linked-device feature in early 2025, and saw the same tradecraft turn up against WhatsApp and Telegram.
Key points
- Russian intelligence hackers are targeting Signal users' backup recovery keys
- Hackers use social engineering tactics to obtain keys
- The campaign has already compromised thousands of accounts worldwide
- Users are advised to treat any in-app message from 'Signal support' as hostile
The FBI's warning and the international cooperation to combat Russian intelligence hackers may help to reduce the number of compromised accounts and prevent further hacking attempts. Signal users who take immediate action to protect their accounts can also minimize the damage.
The hacking campaign has already compromised thousands of accounts worldwide, and the use of social engineering tactics makes it difficult for users to protect themselves. The fact that the recovery key can still be used even if the user generates a new one makes it a significant concern.


