The Evidence Pack: How Russian Intelligence is Bypassing Signal's Encryption via Backup Keys
A joint FBI and CISA advisory reveals that Russian state-sponsored hackers are using sophisticated social engineering to steal Signal Backup Recovery Keys, granting them access to historical message archives without breaking the app's underlying encryption.
By Factlen Editorial Team
- Federal Cyber Agencies
- Focuses on tracking state-sponsored actors, attributing attacks to Russian intelligence, and issuing actionable warnings to high-value targets.
- Cybersecurity Researchers
- Analyzes the technical mechanics of the attack, emphasizing that the underlying encryption remains unbroken while the human element is exploited.
- Privacy Advocates
- Highlights the risk to journalists and human rights workers, advocating for better user education and in-app warnings to prevent social engineering.
What's not represented
- · Signal Development Team
- · Targeted Ukrainian Officials
Why this matters
As messaging apps deploy mathematically impenetrable encryption, state-sponsored hackers are pivoting to exploit the humans using them. Understanding this attack vector is critical for anyone relying on secure communications to protect sensitive personal, corporate, or government data.
Key points
- Russian intelligence services are targeting Signal users to steal their 64-character Backup Recovery Keys.
- The attackers impersonate Signal support bots, falsely claiming the user's data is at risk due to a sync issue.
- Stealing the key allows hackers to download and decrypt a victim's entire historical message archive.
- The campaign targets high-value individuals, including government officials, military personnel, and journalists.
- Signal's underlying end-to-end encryption remains secure; the attack relies entirely on social engineering.
- Users must manually generate a new key in their settings to lock attackers out of future backups.
The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued an updated joint Public Service Announcement warning that Russian Intelligence Services are actively targeting users of encrypted messaging applications, primarily Signal. The advisory, designated PSA I-062626-PSA, details a sophisticated phishing campaign designed to hijack accounts and extract sensitive historical data.[1][2]
The core mechanism of the attack is notable for what it does not do: the threat actors are not breaking Signal's robust end-to-end encryption. Instead, they are bypassing the cryptographic protocols entirely through highly targeted social engineering. Their primary objective is to trick victims into handing over their 64-character Signal Backup Recovery Key.[2][3]
This cyber espionage campaign is meticulously aimed at individuals of high intelligence value. According to the FBI, the targets include current and former United States and international government officials, military personnel, influential political figures, prominent journalists, and key officials located in Ukraine.[1][2][4]
The malicious activity is publicly tracked under the threat actor designations UNC5792 and UNC4221. The FBI attributes these groups to multiple branches of the Russian Intelligence Services (RIS), including officers embedded with the Federal Security Service (FSB) Border Guards and other operatives working on behalf of Russian military intelligence.[1][2]

The stakes surrounding this espionage campaign are exceptionally high. The U.S. State Department considers the threat severe enough that its Rewards for Justice program is currently offering a bounty of up to $10 million for information leading to the identification or location of operators associated with the UNC5792 group.[2]
The attack sequence begins with an in-app message from a fraudulent profile posing as an automated support channel. These profiles utilize authoritative names such as "Signal Security Support ChatBot" or "Signal Security Team" to appear legitimate, exploiting the inherent trust users place in official platform communications.[3][4]
To manufacture a sense of urgency, the attackers falsely claim that the user's account has experienced a data leak, or that suspicious login attempts were detected from foreign locations. In recent iterations, the messages warn that the user's data is at risk of permanent loss due to a critical "sync issue."[1][4]
In recent iterations, the messages warn that the user's data is at risk of permanent loss due to a critical "sync issue."
The fraudulent support account then instructs the target to navigate through their application settings—specifically directing them to the "Backups" menu—and copy their 64-character recovery key. The user is told to paste this alphanumeric key directly into the chat to "secure" their account and prevent the fabricated data loss.[1][3]
If the victim complies and surrenders the key, the consequences are severe. The attacker gains the ability to restore the user's encrypted backup archive onto their own device. This grants the hackers silent, retroactive access to the victim's entire historical message log, including private conversations, group chats, photos, and sensitive documents.[1][4]

The FBI advisory highlights a critical vulnerability in how users attempt to recover from these attacks. If an attacker obtains the Backup Recovery Key, simply creating a new Signal account utilizing the same phone number does not automatically invalidate the stolen key. The compromised key remains active and can be used against the new account.[1][2]
To truly sever the attacker's access to future backups, the victim must manually generate a new Backup Recovery Key within Signal's settings. However, the federal agencies explicitly note that this mitigation will not prevent the attackers from accessing any historical backup archives they have already downloaded using the compromised key.[1][2]
This campaign represents an evolution of tactics observed earlier in the year. In a March 2026 advisory, intelligence agencies warned that the same actors were using doctored "group invite" links and requesting SMS verification codes to silently tether attacker-controlled devices to victim accounts.[1][2]

In response to the ongoing threat, Signal has repeatedly emphasized that its support team operates strictly through official company email addresses. The platform will never proactively contact users via in-app messages, nor will representatives ever request registration codes, PINs, or backup recovery keys through chat interfaces.[1][3]
The evidence supporting the existence and scale of this campaign is robust, corroborated by multiple international intelligence agencies. Earlier this year, Dutch intelligence services (AIVD and MIVD), Germany's BfV, and France's ANSSI issued similar, coordinated warnings regarding these specific Russian state-backed actors.[2]
Ultimately, the UNC5792 campaign underscores a fundamental reality of modern cybersecurity. As cryptographic protocols and zero-knowledge architectures become mathematically impenetrable, state-sponsored attackers will inevitably pivot their resources toward exploiting the human element managing the keys.[4]
How we got here
March 2026
FBI and CISA issue an initial warning about Russian hackers using doctored group invites to hijack Signal accounts.
May 2026
Cybersecurity researchers observe a new wave of phishing attacks specifically targeting Signal Backup Recovery Keys.
June 26, 2026
The FBI and CISA release an updated joint advisory detailing the new recovery key extraction tactics used by UNC5792.
Viewpoints in depth
Federal Cyber Agencies
Focuses on tracking state-sponsored actors and issuing actionable warnings to high-value targets.
For federal intelligence and cybersecurity agencies like the FBI and CISA, the primary concern is the strategic compromise of high-value targets. Their advisories emphasize attribution, linking the UNC5792 and UNC4221 threat groups directly to Russian military intelligence and the FSB. By exposing the specific tactics used in these campaigns, agencies aim to inoculate government officials, military personnel, and international allies against sophisticated social engineering. The State Department's $10 million bounty further underscores the national security implications of these targeted data breaches.
Cybersecurity Researchers
Analyzes the technical mechanics of the attack and the exploitation of the human element.
Security analysts and threat researchers view this campaign as a textbook example of how attackers adapt to impenetrable cryptography. Because Signal's zero-knowledge architecture prevents even the company from accessing user data, hackers must target the endpoints—the users themselves. Researchers emphasize that while the app's encryption remains mathematically sound, the introduction of cloud backups creates a new attack surface. Their focus is on the mechanics of the phishing lures and the persistence of the compromised keys, noting that technical security is only as strong as a user's ability to recognize a fraudulent support request.
Privacy Advocates
Highlights the risk to vulnerable demographics and advocates for better in-app safeguards.
Privacy and digital rights organizations are particularly concerned with how this campaign impacts journalists, human rights workers, and dissidents. For these users, a compromised message archive can lead to severe real-world consequences, including the exposure of confidential sources. Advocates stress the need for platforms to implement stronger anti-phishing guardrails, such as Signal's 'Name not verified' labels, and to continuously educate users that legitimate support channels will never demand sensitive cryptographic keys via chat.
What we don't know
- The exact number of high-value accounts that have had their historical archives successfully decrypted.
- Whether the threat actors have automated the extraction process or are manually operating the fraudulent support accounts.
- How the attackers are initially selecting and identifying the phone numbers of their high-value targets.
Key terms
- Backup Recovery Key
- A unique 64-character alphanumeric code generated on a user's device that is required to decrypt their cloud message archive.
- Advanced Persistent Threat (APT)
- A stealthy and continuous computer network threat actor, typically a nation-state or state-sponsored group, that gains unauthorized access to a network.
- Social Engineering
- The psychological manipulation of people into performing actions or divulging confidential information, rather than using technical hacking methods.
- Zero-Knowledge Architecture
- A security model where the service provider stores encrypted data but does not possess the keys required to decrypt it.
Frequently asked
Is Signal's end-to-end encryption broken?
No. The attackers are bypassing the encryption entirely by tricking users into handing over the keys needed to decrypt their own backups.
What happens if I give an attacker my recovery key?
The attacker can download and decrypt your entire historical message archive, including private conversations, photos, and documents.
How can I secure my account if my key was stolen?
You must manually generate a new Backup Recovery Key in Signal's settings. However, this will not protect any backups the attacker has already downloaded.
Will Signal support ever ask for my recovery key?
No. Signal has explicitly stated that its support team will never proactively contact users via chat or ask for PINs, registration codes, or recovery keys.
Sources
[1]BleepingComputerCybersecurity Researchers
FBI: Russian hackers now target Signal backup recovery keys
Read on BleepingComputer →[2]The Hacker NewsFederal Cyber Agencies
FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
Read on The Hacker News →[3]MalwarebytesCybersecurity Researchers
Signal users targeted in backup-stealing phishing attacks
Read on Malwarebytes →[4]Simply Secure GroupCybersecurity Researchers
FBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal
Read on Simply Secure Group →
Every angle. Every day.
Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.






