:

RUSSIAN HACKERS TARGET SIGNAL BACKUP KEYS

SECURITY DESK1 MIN READ
FRI, JUN 26, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The FBI and CISA warn of an evolving phishing campaign tied to Russian intelligence services targeting Signal users to steal backup recovery keys. Attackers can use these keys to access victims' encrypted message history.

Russian-linked threat actors have escalated their campaign against Signal users by focusing on stealing Signal Backup Recovery Keys through phishing attacks. These keys grant access to encrypted message archives, exposing sensitive communications even when the app itself remains secure. The FBI and Cybersecurity and Infrastructure Agency (CISA) issued the warning as the campaign evolved from initial reconnaissance. Phishing emails are designed to trick users into revealing their recovery credentials. Signal's backup feature encrypts messages locally before storing them, but possession of the recovery key allows decryption. Users are advised to guard recovery keys as closely as passwords and enable additional authentication protections. The campaign reflects a shift in tactics by state-sponsored actors targeting encrypted messaging platforms. Instead of breaking encryption, adversaries now pursue user credentials to bypass security layers directly. Organizations and individuals using Signal for sensitive communications should review their backup security settings immediately.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 for failing to adequately protect the personal data of 727,000 patients and their relatives.

6H AGOSecurity Desk

The FBI is investigating a possible security breach at an ID verification company that may have exposed driver's license scans belonging to millions of Americans. The agency confirmed the investigation to Bloomberg News on Thursday.

6H AGOSecurity Desk

Attackers compromised Coder's Cloudflare infrastructure and injected malicious Terraform modules designed to steal credentials. The unauthorized registry servers delivered the infected packages to users.

8H AGOIndustry Desk

A US senator has called on the NSA to provide official guidance on virtual private network selection and usage, citing confusion over the growing array of available options.

9H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.