The FBI and CISA have issued an updated advisory warning that Russian intelligence groups are now targeting Signal users to steal Backup Recovery Keys and access private message archives.
Key Points
- Russian intelligence groups UNC5792 and UNC4221 are masquerading as Signal support to trick users into revealing their Backup Recovery Keys.
- Unlike temporary verification codes, a stolen Recovery Key allows attackers to access a victim's entire historical message archive and maintain persistent account access.
- The State Department’s Rewards for Justice program is offering up to $10 million for information leading to the identification of the UNC5792 threat group.
- Signal’s encryption remains secure, as the attackers are exploiting user trust rather than technical vulnerabilities within the application itself.
- Users who suspect their account is compromised should immediately generate a new Recovery Key in settings to invalidate the previous one.