FBI CISA Phishing Alert directed at Signal Steals Recovery Key and Control of Your Messages

Author: Published 4 min de lectura 190 reading

The images in this article were generated with artificial intelligence. How we publish

The recent joint update of the FBI and CISA on the phishing campaign against Signal users is not just another variant: it describes a tactic change that dramatically increases the attacker's reach. Instead of conforming to SMS codes or manipulated links to add a device, operators now induce victims to copy and paste their Signal Backup Recovery Key inside a fake "support" chat. With that key the attacker can download and decipher back-up, read private and group records, and in many cases retake control of the number even though the victim creates a new account with the same phone.

Understanding why this is so dangerous requires separating cryptography from social engineering. Signal maintains its encryption from end to end; there is no break of protocol. What fails is the security of the human point: the Recovery Key is not an ephemeral code, but the key that unlocks the encrypted copy of your local messages. If you hand it over, the attacker gets persistent access to that backup. The notice highlights another disturbing property: the key remains valid to restore backups even if the victim recesses the account in the same number, until the victim explicitly generates a new recovery key from Adjustments, which invalidate the previous one for future downloads but cannot recover information already exfiltered.

FBI CISA Phishing Alert directed at Signal Steals Recovery Key and Control of Your Messages
Image generated with IA.

The attribution that accompanied the update increases the risk: the FBI links the campaign to Russian intelligence groups publicly labeled as UNC5792 and UNC4221 and links activity to FSB officers and Russian military actors. The objectives are people of high information value - government officials, military, journalists and political actors - and the pattern fits with previous warnings from European agencies. In addition, the State Department has offered rewards through its Rewards for Justice programme; anyone with information can consult this programme to collaborate with the research ( Rewards for Justice).

For users and security equipment the lesson is double: on the one hand, the legitimate functionality of the application allows for restorations and synchronies; on the other, the path of intrusion is purely human. Treat any message within the application that is presented as "Signal support" asking you for a code, your PIN or the Recovery Key as inherently hostile. Nothing legitimate requests these elements within a chat. The official Signal website offers documentation on how copies and restorations work; contact it to familiarize you with backup and recovery options ( Signal - Support).

FBI CISA Phishing Alert directed at Signal Steals Recovery Key and Control of Your Messages
Image generated with IA.

If you suspect that you delivered the Recovery Key, it acts as if the backup had already been compromised: it immediately generates a new Recovery Key from Settings to prevent future downloads with the old key, it eliminates all linked devices that you do not recognize from the Related Devices section, and considers temporarily disable the backup or recording the number on another device with a new key. It activates the PIN registration / registration protection offered by Signal so that no one can reregister your number without that PIN, informs your organization and follows the incident response procedures: it retains evidence, changes related credentials and notifies potentially affected contacts if appropriate. If you are in a high-risk position, it values the possibility of changing the phone number and reviewing the security of other associated services.

Beyond individual responses, there are strategic implications: the campaign shows that even applications with robust cryptography can be subverted through directed social engineering and abuse of legitimate characteristics. Best technical practices help, but real defense goes through repeated training, phishing simulations and clear processes to verify extraordinary support requests. The agencies that issued the warning (and other national security agencies) recommend not responding to support messages within the app and reporting incidents to the competent authorities; in the United States, CISA and the FBI are among the relevant contact points ( CISA).

In short, Signal's cryptography continues to protect the messages, but the account and the person who controls it remain the weak link. The defense is simple in concept and demanding in practice: do not share codes or keys within chats, review and clean related devices, rotate the Recovery Key if there is suspicion of loss, and scale the incident to the appropriate equipment or authorities. The threat described by the FBI and CISA is deliberate and directed; it treats every unexpected message of "support" as an attempt at intrusion and acts accordingly.

Coverage

Related

More news on the same subject.