FBI: Russian hackers now target Signal backup recovery keys
Russian intelligence operatives have evolved their Signal-targeting campaigns to steal backup recovery keys, granting access to full message histories — a significant escalation beyond real-time interception.
Summary written by editorial AI · Source link below
The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims' historical messages. [...]
Editorial Analysis
Stealing backup recovery keys gives attackers persistent, retroactive access to encrypted communications — a qualitative escalation that undermines the trust model of secure messaging apps used across European enterprises.
Alert staff to this campaign, enforce multi-factor authentication on Signal accounts, and restrict backup recovery key storage to enterprise-managed vaults.
Russian intelligence now targets Signal backup keys for full message history access — a direct threat to secure executive communications.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at BleepingComputer in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d