Russian Spies Would Like Your Signal Recovery Key, Pretty Please

Russian Spies Would Like Your Signal Recovery Key, Pretty Please

Signal's encryption has a reputation: famously, frustratingly, NSA-botheringly unbreakable. So Russian intelligence apparently decided to stop trying to pick the lock and simply ask you to hand over the key — politely, with a convincing little support badge pinned to its lapel.

Fake Support, Very Real Consequences

The FBI and CISA have issued an updated advisory warning that Russian Intelligence Services are phishing Signal users to surrender their Backup Recovery Keys. It builds on a March 2026 alert, and the actors are still masquerading as Signal's automated support accounts — just with a sharper script.

The con goes like this: a message claims Signal is rolling out mandatory two-factor verification after a supposed wave of attacks. A follow-up, still posing as support, warns your data is at risk from a "synchronization issue." The fix they offer? Copy your recovery key to the clipboard and paste it straight into the chat. Please, for the love of all that is encrypted, do not.

The Encryption Held. The Human Folded.

This attack doesn't break end-to-end encryption — it strolls right around it. Hand over that recovery key and attackers restore your backup onto their own device, reading your historical private and group messages at their leisure. The nastiest twist: creating a fresh Signal account on the same phone number does NOT invalidate the stolen key.

Tracked as UNC5792 and UNC4221, the campaign zeroes in on high-value targets — current and former US and international officials, military personnel, political figures, journalists, and key Ukrainian officials. The FBI attributes it to actors tied to Russia's FSB Border Guards and its military. This is precision spear-phishing, not a spray-and-pray.

The takeaway is gloriously, almost insultingly low-tech: no software update can save you from voluntarily typing your master key into a stranger's DM. Signal support will never ask for your recovery key — and neither will anyone you should actually trust.

Source: BleepingComputer