The images in this article were generated with artificial intelligence. How we publish
The recent joint update of the FBI and CISA on the phishing campaign against Signal users is not just another variant: it describes a tactic change that dramatically increases the attacker's reach. Instead of conforming to SMS codes or manipulated links to add a device, operators now induce victims to copy and paste their Signal Backup Recovery Key inside a fake "support" chat. With that key the attacker can download and decipher back-up, read private and group records, and in many cases retake control of the number even though the victim creates a new account with the same phone.
Understanding why this is so dangerous requires separating cryptography from social engineering. Signal maintains its encryption from end to end; there is no break of protocol. What fails is the security of the human point: the Recovery Key is not an ephemeral code, but the key that unlocks the encrypted copy of your local messages. If you hand it over, the attacker gets persistent access to that backup. The notice highlights another disturbing property: the key remains valid to restore backups even if the victim recesses the account in the same number, until the victim explicitly generates a new recovery key from Adjustments, which invalidate the previous one for future downloads but cannot recover information already exfiltered.

The attribution that accompanied the update increases the risk: the FBI links the campaign to Russian intelligence groups publicly labeled as UNC5792 and UNC4221 and links activity to FSB officers and Russian military actors. The objectives are people of high information value - government officials, military, journalists and political actors - and the pattern fits with previous warnings from European agencies. In addition, the State Department has offered rewards through its Rewards for Justice programme; anyone with information can consult this programme to collaborate with the research ( Rewards for Justice).
For users and security equipment the lesson is double: on the one hand, the legitimate functionality of the application allows for restorations and synchronies; on the other, the path of intrusion is purely human. Treat any message within the application that is presented as "Signal support" asking you for a code, your PIN or the Recovery Key as inherently hostile. Nothing legitimate requests these elements within a chat. The official Signal website offers documentation on how copies and restorations work; contact it to familiarize you with backup and recovery options ( Signal - Support).

If you suspect that you delivered the Recovery Key, it acts as if the backup had already been compromised: it immediately generates a new Recovery Key from Settings to prevent future downloads with the old key, it eliminates all linked devices that you do not recognize from the Related Devices section, and considers temporarily disable the backup or recording the number on another device with a new key. It activates the PIN registration / registration protection offered by Signal so that no one can reregister your number without that PIN, informs your organization and follows the incident response procedures: it retains evidence, changes related credentials and notifies potentially affected contacts if appropriate. If you are in a high-risk position, it values the possibility of changing the phone number and reviewing the security of other associated services.
Beyond individual responses, there are strategic implications: the campaign shows that even applications with robust cryptography can be subverted through directed social engineering and abuse of legitimate characteristics. Best technical practices help, but real defense goes through repeated training, phishing simulations and clear processes to verify extraordinary support requests. The agencies that issued the warning (and other national security agencies) recommend not responding to support messages within the app and reporting incidents to the competent authorities; in the United States, CISA and the FBI are among the relevant contact points ( CISA).
In short, Signal's cryptography continues to protect the messages, but the account and the person who controls it remain the weak link. The defense is simple in concept and demanding in practice: do not share codes or keys within chats, review and clean related devices, rotate the Recovery Key if there is suspicion of loss, and scale the incident to the appropriate equipment or authorities. The threat described by the FBI and CISA is deliberate and directed; it treats every unexpected message of "support" as an attempt at intrusion and acts accordingly.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...