FBI Warns Russian Hackers Now Steal Signal Backup Recovery Keys

Russian intelligence-linked hackers have escalated their campaign against Signal users. Instead of just trying to hijack accounts, they’re now going after Backup Recovery Keys — the one piece of data that unlocks your entire encrypted message history stored in Signal’s cloud.

The FBI and CISA published an updated advisory on June 26, expanding on a March 2026 warning. Back then, the threat was phishing messages designed to steal verification codes or trick users into linking attacker-controlled devices. Now the tactic has shifted.

Here’s how it works. The attackers, tracked as UNC5792 and UNC4221, impersonate Signal support. They send a message claiming Signal is introducing mandatory two-factor verification due to attacks from Iranian and post-Soviet hackers. The instructions walk you through enabling backups and viewing your recovery key. Then comes a second message — still posing as Signal support — warning that your data is at risk of permanent loss due to a sync issue. To prevent data loss, you’re told to copy your recovery key and paste it into the chat.

That’s the trap. Anyone with your recovery key can restore your backup on their own device and read all your historical messages — private and group conversations alike.

The advisory also flags a recovery gap that’s easy to miss: if an attacker already grabbed your recovery key, simply creating a new Signal account with the same phone number won’t invalidate the stolen key. You need to generate a new Backup Recovery Key through Signal’s settings, which invalidates the old one for future downloads. However, any backups already downloaded with the compromised key remain accessible to the attacker.

The targets are specific — current and former government officials, military personnel, journalists, and figures connected to Ukraine. But the technique is broadly applicable. If you use Signal, the advice is simple: never share your recovery key with anyone, and remember that legitimate support teams never request verification codes or send links within the app.

References