The FBI and the U.S. Cybersecurity Agency CISA are warning that Russian cyber actors have evolved their attacks on Signal users. Instead of just trying to hijack accounts, the attackers are now trying to obtain users' Backup Recovery Keys, which could give them access to historical, encrypted conversations.
The FBI and CISA have updated their previous security alert from March 2026 regarding targeted phishing attacks targeting users of the encrypted messaging service Signal. According to authorities, the campaign has evolved and now focuses on stealing users' backup keys instead of verification codes or PINs.

In it FBI writes updated warning that the Russian cyber actors continue to pose as Signal's support team, but that their methods have become significantly more advanced.
“RIS cyber threat actors continue to pose as automated Signal support accounts, but have evolved their tactics to attempt to obtain victims” backup keys,” the FBI writes.
The campaign is aimed at high-priority goals
According to the FBI, the attacks are primarily aimed at individuals with high intelligence value, including:
- Current and former U.S. and international government officials
- Military personnel
- Politician
- Journalists
- Key figures with connections to Ukraine
Authorities link the campaign to Russian intelligence services (RIS), including actors affiliated with the Russian security service FSB, border guards, and other groups working for the Russian military. The campaign is publicly tracked under the designations UNC5792 and UNC4221.
New phishing method exploits Signal backups
The new attack method is based on tricking users into activating Signal's secure cloud backup feature themselves.
Victims first receive a fake message purporting to be from Signal support. The message claims that Signal introduces mandatory two-factor authentication after a massive wave of attacks by hackers in Iran and post-Soviet countries.
The user is then prompted to enable backup and show their Backup Recovery Key, the unique recovery key used to encrypt the backup.
Signal backups are protected with end-to-end encryption and can only be restored with this key. If the key falls into the wrong hands, an attacker could restore the backup to their own device and gain access to past messages, photos, and other stored information.
The attackers request the recovery key
After the backup is created, a new phishing message is sent to the victim.
This time, the attackers claim that the user's data is at risk of being lost due to a synchronization error. To avoid data loss, the user is advised to open the backup settings, copy their Backup Recovery Key, and paste it into the message.
If the user follows the instructions, the attackers will gain access to the recovery key and be able to restore the backup to their own devices, allowing them to read historical private conversations, group chats, and shared media without having to break into the device. Signals end to end encryption.
New recovery key required after a compromise
The FBI also highlights an important detail that many users risk missing after an account has been compromised.
If an attacker has already obtained a Backup Recovery Key, it will not automatically become invalid just because the user registers a new Signal account with the same phone number.
To protect future backups, the user must instead generate a completely new recovery key via Signal's backup settings. This will make the previous key no longer work for future backups.
At the same time, the authorities emphasize that a new recovery key does not affect backups that the attackers have already downloaded using the compromised key.
FBI recommendations
FBI and CISA urges Signal users to be especially vigilant against messages purporting to come from support.
Authorities remind that legitimate support teams never:
- requests verification codes or recovery keys via messages,
- asks users to share their Backup Recovery Key,
- contacts users from unofficial email addresses,
- sends links asking users to verify or recover their accounts.
The most important recommendation is therefore to never share your Backup Recovery Key with anyone. It serves as the only key to Signals encrypted backups and provides full access to the backed up conversations for whoever comes across it.








