Hackers Exploit Signal Backup Keys in Phishing Attacks

A recent phishing campaign has emerged, targeting users of the encrypted messaging app Signal. Attackers are impersonating Signal Support to deceive individuals into revealing their backup recovery keys, granting unauthorized access to their encrypted message archives.

The fraudulent scheme begins with a text message that appears to be from Signal Support. The message warns users of a potential data loss due to a synchronization issue and instructs them to navigate through the app’s settings to retrieve their backup recovery key. Users are then prompted to paste this key into the chat, ostensibly to link their existing backup to their account. This tactic exploits the trust users place in official communications and creates a sense of urgency to prompt immediate action. ([malwarebytes.com](https://www.malwarebytes.com/blog/news/2026/05/signal-users-targeted-in-backup-stealing-phishing-attacks?utm_source=openai))

Several red flags can help identify these phishing attempts:

  • The sender’s name is not verified within the app.
  • The message contains grammatical errors and unusual phrasing.
  • Legitimate support channels do not request sensitive information through in-app messages.

The FBI, in collaboration with the Cybersecurity and Infrastructure Security Agency (CISA) and Ukraine’s Security Service (SSU), has issued a warning regarding this campaign. The attacks are attributed to Russian Intelligence Services, specifically the Federal Security Service (FSB). The campaign primarily targets high-value individuals such as government officials, military personnel, political figures, journalists, and key officials in the U.S., Europe, and Ukraine. ([techradar.com](https://www.techradar.com/pro/security/fbi-warns-of-russian-intelligence-phishing-campaign-abusing-signal-support-services-to-target-vips-and-high-value-government-and-military-targets-this-is-how-to-secure-your-account?utm_source=openai))

Once attackers obtain a user’s backup recovery key, they can access the account’s message history, including private and group messages, and potentially take over the account. This method allows them to hijack both current and future Signal accounts associated with the same phone number. The FBI advises users who suspect their key has been compromised to generate a new backup recovery key through Signal’s settings, which will invalidate all previous keys. ([techradar.com](https://www.techradar.com/pro/security/fbi-warns-of-russian-intelligence-phishing-campaign-abusing-signal-support-services-to-target-vips-and-high-value-government-and-military-targets-this-is-how-to-secure-your-account?utm_source=openai))

To protect against such phishing attacks, users should:

  • Be cautious of unsolicited messages requesting sensitive information.
  • Verify the authenticity of messages by contacting official support channels directly.
  • Never share verification codes, PINs, or recovery keys through chat messages.
  • Regularly monitor linked devices and account activity for any unauthorized access.

This incident underscores the importance of vigilance in the face of sophisticated social engineering attacks. Even with robust encryption protocols, user awareness and proactive security measures are crucial in safeguarding personal and sensitive information.