Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks

June 30, 2026

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

June 30, 2026

FBI Sounds Alarm Over Russian Intelligence Signal Phishing

June 30, 2026
Facebook X (Twitter) Instagram
Tuesday, June 30
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»FBI Sounds Alarm Over Russian Intelligence Signal Phishing
News

FBI Sounds Alarm Over Russian Intelligence Signal Phishing

Team-CWDBy Team-CWDJune 30, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Russian intelligence officers are trying to steal backup recovery keys from the Signal accounts of high-risk users, the FBI has warned.

A new public service announcement (PSA) issued on June 26 revealed that “multiple clusters” of Russian spies, including Federal Security Service (FSB) officers and military hackers, are involved. They are actively targeting current and former US and international government officials, military personnel, political figures, journalists, and Ukrainian officials.

The PSA cited “commercial messaging applications” (CMAs) generically, but the two sample phishing messages it included in the update were both related to Signal.

“Russian Intelligence Services (RIS) cyber-threat actors continue to masquerade as automated CMA support accounts in updated phishing messages but have evolved their tactics to attempt to elicit victims’ Backup Recovery Keys,” it said.

“RIS cyber threat actors continue to elicit victims’ verification codes and account PINs. If a targeted user backs up their CMA messages … and later provides their Backup Recovery Key, RIS cyber threat actors can view the account’s historical messages, private and group messages, and take over the victim’s account.”

Read more on Russian activity targeting messaging apps: Russian Hackers Target Ukrainian Servicemen via Messaging Apps

The FBI warned users that if they share their recovery keys, these will remain valid even if they create a new account using the same phone number – putting the new accounts at risk in the future.

“To mitigate this risk, the user must generate a new backup recovery key within the Settings control; this action will invalidate the previous key for all future backup downloads,” it continued. “However, please note that this does not prevent the actor from having already downloaded a backup of the original account.”

Some Signal Security Tips

The Russian campaign first came to light in March 2026 when the Dutch domestic (AIVD) and military intelligence (MIVD) services warned that some of the country’s government employees had been victimized in a hacking campaign targeting Signal and WhatsApp accounts.

Victims typically received a phishing message purporting to come from a Signal chatbot requesting they enter their PIN or verification code. In another variation, the hackers tried to abuse the linked devices function, as per previous campaigns targeting Ukrainian officials.

The FBI PSA cited several reminders for Signal users:

  • CMA support services only communicate with users via official company email addresses
  • Legitimate CMA support services will not request verification codes within the application
  • CMA support services do not send users links to “verify” or “restore” accounts
  • Never provide a verification code without confirming the request comes from a legitimate CMA communication channel

Image credit: Camilo Concha / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous Article29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests
Next Article ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Team-CWD
  • Website

Related Posts

News

UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks

June 30, 2026
News

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

June 30, 2026
News

29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests

June 30, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

The hidden risks of browser extensions – and how to avoid them

September 13, 2025

AI-powered financial scams swamp social media

September 11, 2025

Is it time for internet services to adopt identity verification?

January 14, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.