Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests

    July 31, 2026

    Indigenous Fiber Network Connects Remote Subarctic Towns

    July 31, 2026

    Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance

    July 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests
    • Indigenous Fiber Network Connects Remote Subarctic Towns
    • Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance
    • A fundamental flaw leaves LLMs strikingly vulnerable to attack
    • IEEE Publishing Ethics Team Upholds Research Integrity
    • Why a Tiny Social Media Post Has Mathematicians Rethinking AI
    • Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic
    • Montana’s plan to become an experimental medical hub just pushed forward
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Russian hackers now target Signal backup recovery keys
    Cybersecurity

    Russian hackers now target Signal backup recovery keys

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 27, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Signal
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims’ historical messages.

    The updated public service announcement is an update to a March 2026 advisory that warned the threat actors were targeting users of commercial messaging applications, particularly Signal, through phishing campaigns designed to hijack accounts rather than break end-to-end encryption.

    “RIS cyber threat actors continue to masquerade as automated CMA support accounts in updated phishing messages but have evolved their tactics to attempt to elicit victims’ Backup Recovery Keys,” warns an FBI PSA published today.

    According to the FBI, the campaign continues to target individuals of high intelligence value, including current and former US and international government officials, military personnel, political figures, journalists, and key officials located in Ukraine.

    The agencies attribute the activity to Russian Intelligence Services (RIS), including officers embedded with Russia’s Federal Security Service (FSB) Border Guards and other actors working on behalf of the Russian military. The campaign is publicly tracked as UNC5792 and UNC4221.

    New phishing tactic targets Signal backups

    While the original advisory focused on phishing messages that attempted to steal verification codes or account PINs, or to trick users into linking attacker-controlled devices to their Signal accounts, the updated alert says the attackers have evolved their tactics.

    The FBI says the threat actors continue to impersonate Signal support teams, sending phishing messages that falsely claim Signal is introducing mandatory two-factor verification following an alleged wave of attacks by hackers from Iran and post-Soviet countries.

    “Recently, attempts to hack users of our messenger with the connection of third-party devices to the account have become more frequent,” reads the initial phishing message.

    “An investigation conducted jointly with the US government and European partners revealed that the attacks on accounts were carried out by hackers from Iran and post-Soviet countries. In this regard, Signal updates Terms of Service & Privacy Policy, and introduces Mandatory Two-factor Verification for users.”

    “Not to lose your messages and media, set up your Signal Backup (Settings -> Backups -> Enable backups -> View recovery key -> Copy to clipboard -> Next -> Enter the recovery key -> Next -> Continue -> Choose your backup plan). Click the “Accept” button in the pop-up and stay tuned for security updates on our messenger.”

    When a target follows these instructions, their Signal messages are backed up using Signal’s Secure Backups feature, which stores encrypted copies of conversations on Signal’s cloud servers.

    The data is end-to-end encrypted using the recovery key created in the steps above and should never be given to anyone else, as anyone with the key can use it to recover the backed-up data on their own devices.

    The threat actors later send a second phishing message, still posing as Signal support, warning that your data is at risk of loss due to a synchronization issue.

    “Your Signal Account data (messages and media) is at risk of permanent loss due to a sync issue,” reads the second Signal message.

    The threat actors then prompt you to go into the Backup settings, copy your recovery key to the clipboard, and paste it into the message to prevent the loss of your stored data.

    However, once you provide your recovery key, they can restore the backup to their own devices and gain access to the victim’s historical messages, including private and group conversations.

    The updated advisory also warns of a recovery scenario that users may miss after their account was compromised.

    The FBI warns that if an attacker obtains a user’s Backup Recovery Key, creating a new Signal account using the same phone number does not invalidate the old stolen key.

    Instead, users must generate a new Backup Recovery Key through Signal’s backup settings, which invalidates the previous key for future backup downloads.

    However, the agencies warn that generating a new recovery key will not prevent attackers from accessing backups they already downloaded using the compromised key.

    The updated advisory reminds users that legitimate messaging application support teams only communicate through official company email addresses, never request verification codes within the application, and do not send links asking users to verify or restore their accounts.

    Anyone who believes they have fallen victim to the campaign is encouraged to report the incident to the FBI’s Internet Crime Complaint Center (IC3), a local FBI field office, or CISA.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Backup hackers keys Recovery Russian signal target
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests
    • Indigenous Fiber Network Connects Remote Subarctic Towns
    • Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance
    • A fundamental flaw leaves LLMs strikingly vulnerable to attack
    • IEEE Publishing Ethics Team Upholds Research Integrity

    Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests

    July 31, 2026

    Indigenous Fiber Network Connects Remote Subarctic Towns

    July 31, 2026

    Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance

    July 31, 2026

    A fundamental flaw leaves LLMs strikingly vulnerable to attack

    July 31, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.