The U.S. Department of State is offering up to $10 million for information leading to the identification or location of members of two Russian state-linked hacker groups: UNC5792 and UNC4221. Both are tied to Russian intelligence and military services.
The bounty comes through the Rewards for Justice program, which targets foreign state actors conducting cyberattacks against U.S. critical infrastructure. UNC5792 is associated with the Russian Federal Security Service (FSB) Border Guards, while UNC4221 operates on behalf of Russian military services.
Here’s what they’ve been doing: widespread phishing campaigns targeting Signal and WhatsApp accounts of U.S. government officials, military leadership, and allied personnel. The FBI and CISA updated a March 2026 advisory last week with new tactics, including stealing Signal Backup Recovery Keys.
The attack method is social engineering. Hackers impersonate Signal support agents in direct messages, telling targets they need to complete a mandatory two-factor verification. The goal is to trick users into handing over their data backup key — which gives the attacker access to all previous communications on the platform.
The U.S. government emphasizes that the encryption itself hasn’t been broken. The platforms are secure. The attacks succeed because humans get tricked, not because the math failed. Thousands of accounts for commercial messaging applications have been compromised this way.
Targets include U.S. and NATO government officials, diplomats, defense and intelligence personnel, journalists covering Russia and Ukraine, NGOs supporting Ukraine, and security researchers.
If you use Signal, remember: real support teams only contact you through official company email addresses. They will never ask for verification codes inside the app or send links requesting account recovery.
