
Russian Hackers Are Phishing for Your Signal Backup Keys, FBI Warns
Federal agencies warn that Russian intelligence is targeting Signal users with phishing attacks designed to steal backup recovery keys and hijack encrypted accounts.
Source
GetCyberRight Intelligence
Original headline: Signal Backup Key Phishing Alert
Plain-English summary by GetCyberRight. Read the full report at the source above.
What's Happening Right Now
The FBI and CISA have issued a public warning about a sophisticated phishing campaign targeting Signal users. Russian intelligence operatives are sending fake messages designed to trick people into sharing their Signal backup recovery keys. Once they have your key, attackers can hijack your encrypted account and read all your messages.
The Details: How This Attack Works
Most Signal users think their backup recovery key is just a safety net in case they lose their phone. You're right to think that, but that's exactly what makes this phishing attack so dangerous. The backup key is actually a master password that unlocks all your encrypted messages and contacts.
Here's how the scam works: You receive what looks like an official message from Signal or a trusted contact. The message claims there's a security problem, an account verification needed, or that your backup is at risk. It asks you to confirm or enter your backup recovery key to fix the issue. The moment you share that key, attackers gain complete access to your Signal account.
The attackers are not random scammers. Russian intelligence services are running this operation with specific targets in mind. They're creating convincing fake websites and messages that look almost identical to legitimate Signal communications.
Who Is Affected
This threat primarily targets professionals who handle sensitive information: journalists, activists, lawyers, government employees, and business executives. If you use Signal for work communications or discussions that need privacy, you're at higher risk.
However, anyone using Signal should pay attention. Attackers often cast a wide net, hoping to catch a few valuable targets among many attempts. If you've ever set up Signal backups on your phone, you have a recovery key that could be targeted.
What You Should Do Right Now
Never share your Signal backup recovery key with anyone, ever. Signal will never ask you for this key through a message, email, or phone call. Treat it like your bank PIN.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
Delete any suspicious messages asking about your Signal account or backup. Don't click links in these messages. If you're unsure, open Signal directly from your phone and check settings there.
Review who can message you on Signal. Go to Settings > Privacy > Messaging and consider limiting who can add you to groups or send you messages.
Write down your backup key and store it somewhere secure offline. A locked drawer or safe is better than a digital note on your phone. This prevents both phishing and digital theft.
Enable a registration lock PIN in Signal settings. This adds another layer of protection if someone tries to register your number on a different device.
The Bigger Picture
This attack highlights a critical shift in how sophisticated attackers operate. They're not just hacking systems anymore. They're hacking trust and exploiting our own security tools against us. As more people adopt encrypted messaging for privacy, attackers are finding creative ways to bypass that encryption without breaking the technology itself.
How GetCyberRight Can Help
Our GCR Scam Guard tool helps families recognize phishing attempts before they become problems. It trains you to spot the warning signs when someone is trying to trick you into sharing recovery keys, passwords, or other credentials. Think of it as practice for real-world threats, so when a sophisticated attack like this one arrives in your inbox, you'll recognize it immediately and delete it without hesitation.
Curated from trusted cybersecurity sources by GetCyberRight
Source: GetCyberRight IntelligenceStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Russian Hackers Are Targeting Signal Backup Keys to Read Your Messages
Intelligence agencies warn that Signal users are being phished for backup recovery keys, giving attackers access to encrypted message history.
4 min readPrime Day Scams: The Fake Deal Sites Targeting Your Family This Week
Scammers create thousands of fake shopping sites during Prime Day to steal your payment information. Here's how to spot them and shop safely.
3 min readPrime Day Phishing Myth Busted: Scammers Have Upped Their Game
Think you can spot fake Amazon emails by spelling errors? Today's scammers are more sophisticated, and Prime Day shoppers are prime targets.
3 min readPrime Day Phishing Scams: What Families Need to Know Before They Shop
Scammers exploit Prime Day's shopping frenzy with fake emails, texts, and cloned websites designed to steal your payment information and personal data.
3 min read