The Evidence Pack: How Russian Intelligence is Bypassing Signal's Encryption via Backup Keys
A joint FBI and CISA advisory reveals that Russian state-sponsored hackers are using sophisticated social engineering to steal Signal Backup Recovery Keys, granting them access to historical message archives without breaking the app's underlying encryption.
By Naina Verma
- Federal Cyber Agencies
- Focuses on tracking state-sponsored actors, attributing attacks to Russian intelligence, and issuing actionable warnings to high-value targets.
- Cybersecurity Researchers
- Analyzes the technical mechanics of the attack, emphasizing that the underlying encryption remains unbroken while the human element is exploited.
- Privacy Advocates
- Highlights the risk to journalists and human rights workers, advocating for better user education and in-app warnings to prevent social engineering.
Perspectives this story doesn't cover
- Signal Development Team
- Targeted Ukrainian Officials
Summary
- Russian intelligence services are targeting Signal users to steal their 64-character Backup Recovery Keys.
- The attackers impersonate Signal support bots, falsely claiming the user's data is at risk due to a sync issue.
- Stealing the key allows hackers to download and decrypt a victim's entire historical message archive.
- The campaign targets high-value individuals, including government officials, military personnel, and journalists.
- Signal's underlying end-to-end encryption remains secure; the attack relies entirely on social engineering.
- Users must manually generate a new key in their settings to lock attackers out of future backups.
The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued an updated joint Public Service Announcement warning that Russian Intelligence Services are actively targeting users of encrypted messaging applications, primarily Signal. The advisory, designated PSA I-062626-PSA, details a sophisticated phishing campaign designed to hijack accounts and extract sensitive historical data.[1][2]
The core mechanism of the attack is notable for what it does not do: the threat actors are not breaking Signal's robust end-to-end encryption. Instead, they are bypassing the cryptographic protocols entirely through highly targeted social engineering. Their primary objective is to trick victims into handing over their 64-character Signal Backup Recovery Key.[2][3]
This cyber espionage campaign is meticulously aimed at individuals of high intelligence value. According to the FBI, the targets include current and former United States and international government officials, military personnel, influential political figures, prominent journalists, and key officials located in Ukraine.[1][2][4]
The malicious activity is publicly tracked under the threat actor designations UNC5792 and UNC4221. The FBI attributes these groups to multiple branches of the Russian Intelligence Services (RIS), including officers embedded with the Federal Security Service (FSB) Border Guards and other operatives working on behalf of Russian military intelligence.[1][2]
The stakes surrounding this espionage campaign are exceptionally high. The U.S. State Department considers the threat severe enough that its Rewards for Justice program is currently offering a bounty of up to $10 million for information leading to the identification or location of operators associated with the UNC5792 group.[2]
The attack sequence begins with an in-app message from a fraudulent profile posing as an automated support channel. These profiles utilize authoritative names such as "Signal Security Support ChatBot" or "Signal Security Team" to appear legitimate, exploiting the inherent trust users place in official platform communications.[3][4]
To manufacture a sense of urgency, the attackers falsely claim that the user's account has experienced a data leak, or that suspicious login attempts were detected from foreign locations. In recent iterations, the messages warn that the user's data is at risk of permanent loss due to a critical "sync issue."[1][4]
In recent iterations, the messages warn that the user's data is at risk of permanent loss due to a critical "sync issue."
The fraudulent support account then instructs the target to navigate through their application settings—specifically directing them to the "Backups" menu—and copy their 64-character recovery key. The user is told to paste this alphanumeric key directly into the chat to "secure" their account and prevent the fabricated data loss.[1][3]
If the victim complies and surrenders the key, the consequences are severe. The attacker gains the ability to restore the user's encrypted backup archive onto their own device. This grants the hackers silent, retroactive access to the victim's entire historical message log, including private conversations, group chats, photos, and sensitive documents.[1][4]
The FBI advisory highlights a critical vulnerability in how users attempt to recover from these attacks. If an attacker obtains the Backup Recovery Key, simply creating a new Signal account utilizing the same phone number does not automatically invalidate the stolen key. The compromised key remains active and can be used against the new account.[1][2]
To truly sever the attacker's access to future backups, the victim must manually generate a new Backup Recovery Key within Signal's settings. However, the federal agencies explicitly note that this mitigation will not prevent the attackers from accessing any historical backup archives they have already downloaded using the compromised key.[1][2]
This campaign represents an evolution of tactics observed earlier in the year. In a March 2026 advisory, intelligence agencies warned that the same actors were using doctored "group invite" links and requesting SMS verification codes to silently tether attacker-controlled devices to victim accounts.[1][2]
In response to the ongoing threat, Signal has repeatedly emphasized that its support team operates strictly through official company email addresses. The platform will never proactively contact users via in-app messages, nor will representatives ever request registration codes, PINs, or backup recovery keys through chat interfaces.[1][3]
The evidence supporting the existence and scale of this campaign is robust, corroborated by multiple international intelligence agencies. Earlier this year, Dutch intelligence services (AIVD and MIVD), Germany's BfV, and France's ANSSI issued similar, coordinated warnings regarding these specific Russian state-backed actors.[2]
Ultimately, the UNC5792 campaign underscores a fundamental reality of modern cybersecurity. As cryptographic protocols and zero-knowledge architectures become mathematically impenetrable, state-sponsored attackers will inevitably pivot their resources toward exploiting the human element managing the keys.[4]
Definitions
- Backup Recovery Key
- A unique 64-character alphanumeric code generated on a user's device that is required to decrypt their cloud message archive.
- Advanced Persistent Threat (APT)
- A stealthy and continuous computer network threat actor, typically a nation-state or state-sponsored group, that gains unauthorized access to a network.
- Social Engineering
- The psychological manipulation of people into performing actions or divulging confidential information, rather than using technical hacking methods.
- Zero-Knowledge Architecture
- A security model where the service provider stores encrypted data but does not possess the keys required to decrypt it.
Sources
[1]BleepingComputerCybersecurity ResearchersFBI: Russian hackers now target Signal backup recovery keys
Read on BleepingComputer →
[2]The Hacker NewsFederal Cyber AgenciesFBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
Read on The Hacker News →
[3]MalwarebytesCybersecurity ResearchersSignal users targeted in backup-stealing phishing attacks
Read on Malwarebytes →
[4]Simply Secure GroupCybersecurity ResearchersFBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal
Read on Simply Secure Group →
Comments
More in Technology
See all →Foldable Hardware
Huawei Releases Mate XT 2 Tri-Fold, Debuting LogicFolding Tau Chip Architecture
7 sources
Video DRM
Why Downloading a YouTube Video Violates Google's Contract, but Not Necessarily Copyright Law
7 sources
Humanoid Robotics
Why the Humanoid Robotics Industry is Mass-Producing Hardware Before the Software is Ready
7 sources
Data Structures
Why Hash Maps Default to a 0.75 Load Factor, and When to Change It
7 sources
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.




