FBI: Russian Hackers Now Target Signal Backup Recovery Keys
The FBI and CISA warn that Russian intelligence-backed actors have escalated phishing campaigns against Signal users to steal Backup Recovery Keys, enabling attackers to access victims’ historical messages. The attackers impersonate Signal support, instruct users to enable Secure Backups and copy their recovery key, then use that key to restore backups on their own devices. An update to the March 2026 advisory notes that a stolen recovery key remains valid even if a new Signal account is created with the same phone number; users should rotate keys, never share verification codes or recovery keys, and report incidents to IC3 or CISA. The operation targets high-value individuals—government officials, military personnel, journalists, political figures, and Ukraine-related officials—and is tracked as UNC5792/UNC4221 by RIS.

FBI: Russian Hackers Now Target Signal Backup Recovery Keys
OverviewThe FBI and CISA have issued an updated public safety alert describing how phishing operations connected to Russian intelligence have evolved to steal Signal Backup Recovery Keys. These keys, once compromised, can give attackers access to a victim’s historical messages stored in Signal backups. The advisory expands on an earlier March 2026 warning that attackers sought to hijack accounts rather than break Signal’s end-to-end encryption.
Targets and Motivations
- The operation continues to focus on high-value individuals, including current or former government officials, military personnel, political figures, journalists, and key figures in Ukraine.
- The activity is attributed to Russian intelligence services, with officers connected to the FSB and allied actors acting on behalf of the Russian military. The campaign is tracked publicly under UNC5792 and UNC4221.
How the Campaign Has Evolved
- Early phishing efforts aimed to harvest verification codes or PINs, or to trick users into linking attacker-controlled devices to their Signal accounts.
- The updated threat landscape shows attackers still posing as Signal support teams but shifting tactics to obtain Backup Recovery Keys directly from victims.
- A recurring narrative involves signaling that Signal is introducing mandatory two-factor verification after alleged waves of attacks from Iran and post-Soviet actors.
Operational Tactics in Detail
- Initial phishing message: Attackers claim that a routine security update or verification is required to prevent a cascade of account compromises, prompting users to follow steps that appear legitimate.
- Backup activation prompt: Victims are guided to enable Signal backups and view their recovery key, with instructions to copy the key to the clipboard during the backup setup.
- The recovery key as the pivot: With the recovery key in hand, attackers can initiate a recovery on their own devices, thereby gaining access to the victim’s encrypted message history when the backup is restored.
- Follow-up threat framing: A second phishing message warns of data risk due to a synchronization issue, urging the user to paste their recovery key again to prevent data loss.
- Undermining trust in the legitimate app: The messages are crafted to mimic official communications, encouraging recipients to trust the allegedly routine maintenance activity while blindsiding them with a key theft.
Technical and Privacy Implications
- The attack leverages Signal’s Secure Backups feature, which stores encrypted copies of conversations on cloud servers, with decryption tied to the recovery key.
- If the attacker obtains a valid Recovery Key, they can decrypt and access the backed-up data on their own devices, regardless of whether the target’s account later changes the key.
- Generating a new Recovery Key after a compromise invalidates the old key for future backups, but does not undo backups already downloaded by the attacker.
- The schemes emphasize that legitimate support channels will not request verification codes inside the app, will not direct users to verify or restore accounts via external links, and will communicate through official company channels only.
Backups, Keys, and Security Nuances
- The Recovery Key is a critical control for backup accessibility. Losing control of this key means losing exclusive control over past conversations stored in backups.
- Attackers aim to exploit confidence in official-sounding prompts and the perceived urgency of “data at risk” to extract the key.
- Even after a key is rotated or replaced, previously downloaded backups remain accessible to those who captured the original key.
Official Warnings and Public Safety Messaging
- The FBI and CISA PSA emphasizes careful scrutiny of any messages that claim to come from Signal support or reference updates to Terms of Service, Privacy Policy, or security features.
- Micro-details in the messaging, such as references to specific wave-of-attacks scenarios or “mandatory” security measures, can be signals of social engineering rather than genuine notices.
- Designated reporting channels include the FBI’s Internet Crime Complaint Center (IC3) and CISA, should a user believe they have encountered or fallen victim to the campaign.
What This Means for Signal Users
- The focus on Backup Recovery Keys adds a layer of risk beyond standard phishing, elevating the importance of safeguarding backup credentials.
- Targeted individuals should be aware that attackers are attempting to impersonate legitimate support communications to steal recovery information.
- The distinction between legitimate support processes and fraudulent prompts is subtle but critical, hinging on trust cues, official domains, and verifiable sources of instruction.
Context and Related Security Alerts
- The update follows a March 2026 advisory that highlighted broader phishing campaigns aimed at hijacking accounts on messaging platforms, with a particular emphasis on Signal.
- The threat landscape includes a spectrum of actors misrepresenting themselves as trusted entities to manipulate users into divulging sensitive data or enabling data access paths for attackers.
Reporting and Continuing Vigilance
- Victims or witnesses of suspicious activity are encouraged to contact official reporting channels through IC3 or CISA, and to engage with the appropriate local authorities as needed.
- Public safety notices underscore the ongoing need for skepticism around prompts that appear to be security updates, especially when they request access to backup keys or verification details.
Summary
- The FBI and CISA have issued a renewed warning about sophisticated phishing campaigns linked to Russian intelligence that aim to steal Signal Backup Recovery Keys.
- The attackers’ evolving TTPs (tactics, techniques, and procedures) center on impersonating Signal support, prompting users to enable backups and copy recovery keys, and then using those keys to access historical messages stored in backups.
- High-value targets remain the focus, with the risk extending to journalists, government personnel, and political figures, among others.
- The protective message from authorities remains clear: verify official channels, be cautious with recovery keys, and report suspicious activity promptly to official bodies.


