The images in this article were generated with artificial intelligence. How we publish
The joint FBI and CISA public alert on a phishing campaign for Signal users represents a remarkable evolution of tactics: it is no longer just about stealing verification codes or linking devices, but about inducing victims to deliver their Backup Recovery Key, the key to decipher the protected backup in Signal's cloud.
Those responsible, attributable by the agencies to Russian intelligence services and publicly traced as UNC5792 and UNC4221 they have focused their messages on people of high interest: public officials, military, journalists and political figures, especially with links to Ukraine. The social engineering used simulates official communications from Signal support, claiming security changes or data loss to justify the user to copy and paste his recovery key.

It is important to understand the technical vector behind the deception: Signal offers encrypted backup whose encryption is linked to a user-generated recovery key; anyone who gets that key can restore and read the message history even if he has not compromised end-to-end protection in transit. Signal explained the design of that function on his official blog: Introduction to Secure Backups.
The implications are clear and dangerous: the historical confidentiality of conversations ceases to depend only on the messaging channel and goes through the secret of the backup key. Generate a new, invalid key for future downloads, but does not prevent an attacker already in possession of the key from downloading and retaining copies of the backups. The FBI notes this clarification in its public notice: FBI PSA on the campaign.
From a practical perspective, attackers use a stable pattern: first message that urges to create or activate backup, second message that simulates a synchronization problem and literally requests that the user stick the key to the chat to "recover" the data. That gesture is the voluntary delivery of the key that allows deciphering out of the owner's control.
For users and security equipment the recommendation is double: technical measures and operational habits. In technical terms, consider deactivating cloud backup if you communicate extremely sensitive information, or at least protect the device with strong lock and not store the key in clear text. In operational terms, never share codes or keys through chats, check support communications through official channels and immediately record any suspicious activity in related accounts.

If you suspect your key was compromised, generate a new backup key from Signal's options and assume that any previous backup may have been downloaded by third parties; change number not automatically invalidated old keys. In addition, review the devices linked to Signal and close unknown sessions, and launch additional controls on the device (strong screen lock, device encryption, and minimum applications with access to clipboard).
Organizations should complement these recommendations with specific training on targeted phishing, simulations of attacks to measure resilience and response procedures that include notification to authorities. Victims or organizations that detect incidents should report it to the FBI IC3 or CISA, for example through the CISA response form and incident reports: CISA Incident Reporting and consider contact with the FBI regional office for investigation.
Finally, this campaign recalls that real security combines robust cryptography with prudent human practices: the best encryption can be overturned by a convincing message. Maintaining the security position requires reducing the surface of deception (less copies in the cloud where possible), verifying the authenticity of sensitive requests and treating recovery keys as critical information that should never be shared.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...