AUTO-UPDATED

New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages

The FBI and CISA have issued an updated advisory warning that Russian intelligence groups are now targeting Signal users to steal Backup Recovery Keys and access private message archives.

Key Points

  • Russian intelligence groups UNC5792 and UNC4221 are masquerading as Signal support to trick users into revealing their Backup Recovery Keys.
  • Unlike temporary verification codes, a stolen Recovery Key allows attackers to access a victim's entire historical message archive and maintain persistent account access.
  • The State Department’s Rewards for Justice program is offering up to $10 million for information leading to the identification of the UNC5792 threat group.
  • Signal’s encryption remains secure, as the attackers are exploiting user trust rather than technical vulnerabilities within the application itself.
  • Users who suspect their account is compromised should immediately generate a new Recovery Key in settings to invalidate the previous one.

Why it Matters

This campaign highlights a shift toward social engineering tactics that bypass robust encryption by targeting the human element of account management. Because a compromised recovery key provides long-term access to message history, users in sensitive roles must remain vigilant against fraudulent support requests to protect their data.
Securityaffairs.com Published by Pierluigi Paganini
Read original