Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
CVEVulnerability

FBI Warns Russian Hackers Steal Signal Backup Recovery Keys

By ogwatermelon
June 27, 2026 4 Min Read
0
June 27, 2026

The FBI and CISA issued an updated public service advisory on June 26, 2026, warning that Russian Intelligence Services (RIS) have evolved their Signal phishing campaign to steal Backup Recovery Keys. Consequently, attackers who obtain these keys can restore victims’ encrypted message backups and read private and group conversations.

The advisory updates a March 2026 warning about Russian phishing campaigns targeting Signal users. Moreover, it assigns two new public tracking names to the activity: UNC5792 and UNC4221. The campaign targets current and former government officials, military personnel, political figures, journalists, and key officials in Ukraine.

What Happened: Russian Intelligence Targets Signal Backup Recovery Keys

The updated FBI PSA (I-062626-PSA) reveals a significant tactical shift. Previously, the attackers relied on phishing messages to steal verification codes, account PINs, or to link attacker-controlled devices to victim Signal accounts. However, the new approach focuses on Signal’s Secure Backups feature.

Signal’s Secure Backups encrypt copies of conversations on Signal’s cloud servers. Furthermore, each backup is protected by a unique Backup Recovery Key generated on the user’s device. Therefore, anyone holding that key can restore the backup on another device and access the full message history.

The FBI attributes this activity to multiple Russian Intelligence Services groups. In addition, the advisory identifies officers embedded with the FSB Border Guards and actors working for Russian military services. The agencies publicly track these groups as UNC5792 and UNC4221.

Technical Details of the Signal Backup Phishing Campaign

The threat actors impersonate automated Signal support accounts in updated phishing messages. First, the attackers send an initial message claiming Signal is introducing mandatory two-factor verification following alleged attacks by hackers from Iran and post-Soviet countries.

The phishing message instructs the target to set up Signal Backups via Settings, view the recovery key, copy it to the clipboard, and paste it into a reply. However, the recovery key is never meant to be shared with anyone. Once the attacker receives the key, they can restore the victim’s backup on their own devices.

After the initial phish, the attackers send a second message posing as Signal support. This message warns that the user’s data is at risk of permanent loss due to a synchronization issue. Moreover, it again prompts the victim to copy and share the recovery key.

A Critical Recovery Gap

The updated advisory highlights a recovery scenario that many users may overlook. If an attacker obtains a Backup Recovery Key, creating a new Signal account on the same phone number does not invalidate the old key.

Therefore, victims must generate a new Backup Recovery Key through Signal’s backup settings. This action invalidates the previous key for future backup downloads. However, the agencies warn that generating a new key will not prevent attackers from accessing backups they already downloaded using the compromised key.

Business and Operational Impact

This campaign poses significant risks to organizations and individuals alike. The impact extends beyond personal privacy to national security, journalism safety, and organizational confidentiality.

  • National security exposure: Government and military officials risk leaking classified or sensitive communications through compromised Signal backups.
  • Journalist safety: Reporters covering sensitive topics may expose sources and contacts if their message history is restored by attackers.
  • Organizational confidentiality: Private and group conversations containing strategic plans, negotiations, or operational details become accessible to adversaries.
  • Persistent access: Unlike one-time code theft, a stolen Backup Recovery Key can enable repeated restoration attempts until the victim generates a new key.

Mitigation and Recommendations

Defenders should act immediately to reduce exposure to this evolving threat. The FBI and CISA recommend several concrete steps for individuals and organizations.

Immediate Actions for Defenders

  1. Educate users about recovery keys: Make clear that Signal Backup Recovery Keys must never be shared with anyone, including support teams.
  2. Rotate compromised keys immediately: Any user who may have shared their recovery key should generate a new key via Signal Settings.
  3. Report incidents to authorities: Victims should contact the FBI IC3, a local FBI field office, or CISA.
  4. Review communication channels: Organizations should verify that Signal accounts used for sensitive work are not linked to attacker-controlled devices.

Best Practices for Signal Users

Users can take additional steps to protect their Signal communications. First, enable Signal’s registration lock to prevent account takeover via SMS verification. Second, regularly review linked devices in Signal Settings and remove any unrecognized entries. Third, avoid clicking links or following instructions from unsolicited messages claiming to be from Signal support.

Furthermore, legitimate messaging application support teams only communicate through official company email addresses. They never request verification codes within the application, and they do not send links asking users to verify or restore accounts.

Bottom line: Russian intelligence actors are now targeting Signal Backup Recovery Keys to access victims’ encrypted message history. Organizations must immediately educate high-value users, enforce recovery key hygiene, and report suspected compromises to federal authorities.

Incident Summary

CVE ID / Incident: UNC5792 / UNC4221 Signal Backup Recovery Key Phishing
Affected Systems: Signal messenger users on Android, iOS, and Desktop
Disclosure Date: June 26, 2026 (FBI/CISA PSA I-062626-PSA)
Patch Status: No software patch required; mitigation through user awareness and key rotation

References

  1. FBI and CISA, “Public Service Announcement I-062626-PSA: Russian Intelligence Services Targeting Signal Backup Recovery Keys,” June 26, 2026, https://www.ic3.gov/PSA/2026/PSA260626, accessed June 27, 2026.
  2. Bill Toulas, “FBI: Russian hackers now target Signal backup recovery keys,” BleepingComputer, June 26, 2026, https://www.bleepingcomputer.com/news/security/fbi-russian-hackers-now-target-signal-backup-recovery-keys/, accessed June 27, 2026.
  3. Signal, “Introducing Secure Backups,” Signal Blog, https://signal.org/blog/introducing-secure-backups/, accessed June 27, 2026.

Tags:

CVEVulnerability
Author

ogwatermelon

Follow Me
Other Articles
Previous

Amazon Q Developer CVE Malicious MCP Configs Steal Cloud Credentials

Next

Polymarket Supply-Chain Attack Drains Million in Crypto via Frontend Compromise

AI Botnet Breach CVE Exploit Hack Incident Linux Malware Network Ransomware supply chain Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Linux
  • Malware
  • Phishing
  • Ransomware
  • supply-chain
  • Uncategorized
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.