Russian Hackers Bypass Signal Encryption by Phishing Users for Account Secrets

Russian Intelligence Services (RIS) linked hackers are not breaking Signal’s encryption; instead, they are tricking users into handing over the very secrets that protect their accounts and backups, allowing full access to past and future conversations.

This evolving phishing campaign targets high‑value individuals and exploits trust in “support” messages to capture verification codes, PINs, and Backup Recovery Keys.

U.S. authorities have linked multiple clusters of Russian Intelligence Services cyber actors, including officers embedded with the FSB Border Guards and operatives working for Russian military services, to a broad phishing campaign against commercial messaging applications such as Signal.

These campaigns focus on people of “high intelligence value,” including current and former U.S. and international government officials, military personnel, political figures, journalists, and key officials in Ukraine.

Public reporting tracks this activity under threat clusters UNC5792 and UNC4221, highlighting it as a sustained, state‑aligned operation rather than random criminal activity.

Signal Account Phishing

Crucially, investigators emphasize that these actors have compromised individual accounts, not the underlying encryption protocols or the Signal application itself.

Instead of attacking cryptography, the hackers rely on highly convincing social engineering that abuses user trust in automated support messages and in‑app security prompts.

The phishing flow begins with messages that impersonate automated support accounts for the messaging platform (often framed as urgent security or data‑loss warnings).

RIS‑linked actors pretend to be “CMA support” and claim that the user must perform immediate steps to avoid losing messages or to complete new security requirements.

These messages instruct victims to navigate to their app’s backup settings, enable backups, and then reveal their Backup Recovery Key, supposedly to “link” or “restore” existing data.

At the same time, these campaigns still attempt to collect one‑time verification codes and account PINs, enabling full account takeover.

With verification codes and PINs, the attackers can register the victim’s number on a device they control; with the Backup Recovery Key, they can restore and read the victim’s entire message history.

Authorities stress that official support services for commercial messaging apps will never ask users to send verification codes, PINs, or Backup Recovery Keys through chat windows or external links.

Legitimate support will only communicate via official company email addresses. It will not push users to “verify” or “restore” accounts via links sent in random messages.

Before sharing any code, users should independently confirm that the request originates from a trusted channel, such as the app’s own website or documented support email.

If you suspect you’ve been targeted or have already shared a verification code, PIN, or Backup Recovery Key, authorities urge you to report the incident.

Victims can file complaints with the Internet Crime Complaint Center (IC3), contact their local FBI field office, and report to CISA via its Incident Reporting System, 24/7 Operations Center email, or hotline.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories