Cybertech Europe 2026-IT Industry Official Media Partner

FBI warns: Russian hackers now targeting Signal's backup keys

The FBI warns that Russian hackers are targeting Signal's backup keys to gain access to encrypted conversations. The FBI warns that Russian hackers are targeting Signal's backup keys to gain access to encrypted conversations.
The FBI and CISA are warning of a new phishing campaign in which Russian cyber actors are attempting to steal Signal's Backup Recovery Keys to access users' encrypted backups and historical conversations.

The FBI and the U.S. Cybersecurity Agency CISA are warning that Russian cyber actors have evolved their attacks on Signal users. Instead of just trying to hijack accounts, the attackers are now trying to obtain users' Backup Recovery Keys, which could give them access to historical, encrypted conversations.

The FBI and CISA have updated their previous security alert from March 2026 regarding targeted phishing attacks targeting users of the encrypted messaging service Signal. According to authorities, the campaign has evolved and now focuses on stealing users' backup keys instead of verification codes or PINs.

FBI – FBI warns: Russian hackers are now targeting Signal's backup keys | IT Industry

In it FBI writes updated warning that the Russian cyber actors continue to pose as Signal's support team, but that their methods have become significantly more advanced.

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

“RIS cyber threat actors continue to pose as automated Signal support accounts, but have evolved their tactics to attempt to obtain victims” backup keys,” the FBI writes.

The campaign is aimed at high-priority goals

According to the FBI, the attacks are primarily aimed at individuals with high intelligence value, including:

  • Current and former U.S. and international government officials
  • Military personnel
  • Politician
  • Journalists
  • Key figures with connections to Ukraine

Authorities link the campaign to Russian intelligence services (RIS), including actors affiliated with the Russian security service FSB, border guards, and other groups working for the Russian military. The campaign is publicly tracked under the designations UNC5792 and UNC4221.

New phishing method exploits Signal backups

The new attack method is based on tricking users into activating Signal's secure cloud backup feature themselves.

Victims first receive a fake message purporting to be from Signal support. The message claims that Signal introduces mandatory two-factor authentication after a massive wave of attacks by hackers in Iran and post-Soviet countries.

The user is then prompted to enable backup and show their Backup Recovery Key, the unique recovery key used to encrypt the backup.

Signal backups are protected with end-to-end encryption and can only be restored with this key. If the key falls into the wrong hands, an attacker could restore the backup to their own device and gain access to past messages, photos, and other stored information.

The attackers request the recovery key

After the backup is created, a new phishing message is sent to the victim.

This time, the attackers claim that the user's data is at risk of being lost due to a synchronization error. To avoid data loss, the user is advised to open the backup settings, copy their Backup Recovery Key, and paste it into the message.

If the user follows the instructions, the attackers will gain access to the recovery key and be able to restore the backup to their own devices, allowing them to read historical private conversations, group chats, and shared media without having to break into the device. Signals end to end encryption.

New recovery key required after a compromise

The FBI also highlights an important detail that many users risk missing after an account has been compromised.

If an attacker has already obtained a Backup Recovery Key, it will not automatically become invalid just because the user registers a new Signal account with the same phone number.

To protect future backups, the user must instead generate a completely new recovery key via Signal's backup settings. This will make the previous key no longer work for future backups.

At the same time, the authorities emphasize that a new recovery key does not affect backups that the attackers have already downloaded using the compromised key.

FBI recommendations

FBI and CISA urges Signal users to be especially vigilant against messages purporting to come from support.

Authorities remind that legitimate support teams never:

  • requests verification codes or recovery keys via messages,
  • asks users to share their Backup Recovery Key,
  • contacts users from unofficial email addresses,
  • sends links asking users to verify or recover their accounts.

The most important recommendation is therefore to never share your Backup Recovery Key with anyone. It serves as the only key to Signals encrypted backups and provides full access to the backed up conversations for whoever comes across it.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT