FBI and CISA Warn Russian Intelligence Campaign Now Steals Signal Backup Recovery Keys

The FBI and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have issued an updated advisory warning that a phishing campaign linked to Russian intelligence services has taken a significant step forward: attackers are now specifically targeting Signal Backup Recovery Keys. The campaign, which the Security Service of Ukraine (SSU) has also been tracking in coordination with the FBI, appears to be targeting government officials, military personnel, politicians, and civil society activists across Ukraine, Europe, and the United States.

The escalation matters because of what a stolen backup key enables. Unlike a session hijack, which requires ongoing access, obtaining a Signal Backup Recovery Key allows an attacker to restore the victim’s encrypted message archive on a device they control — recovering the full history of private and group conversations. Once the key is taken, it remains valid, meaning the attacker retains access to any backup the victim generates going forward, not just what was available at the time of theft. Victims may have no indication that their communications have been compromised.

The attackers have reportedly been using phishing messages crafted to impersonate technical support contacts, luring targets into providing the key under the guise of account verification or recovery assistance. Both agencies are urging Signal users — particularly those in sensitive roles — to treat any unsolicited message asking for a backup key as malicious, to enable registration lock, and to report suspicious activity to relevant authorities.

Read the original report →