Signal backup recovery key phishing: FBI warning
FBI and CISA warn that Russian-linked actors are phishing Signal backup recovery keys. Learn how the attack works and how to respond safely.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 10 July 2026
- READING TIME
- 8 min read
- TOPIC
- Human Security
An encrypted messenger can protect messages correctly in transit while an attacker still takes over an account or restores its backup. That distinction is central to the campaign described by the FBI and CISA on 26 June 2026. Actors tracked publicly as UNC5792 and UNC4221 impersonate support staff and request verification codes, PINs and, in the latest variant, Signal Backup Recovery Keys.
This is not a breach of Signal’s infrastructure or a break in end-to-end encryption. It is targeted social engineering designed to make the owner voluntarily provide the secret required to restore protected data.
What the agencies confirmed
The joint advisory links the activity clusters to Russian intelligence services and says the campaign targets high-value individuals, including current and former officials, military personnel, politicians, journalists and people with key roles in Ukraine. The agencies describe compromise of individual messaging accounts—not the encryption protocol or application itself.
The June update expands a 20 March 2026 warning. Earlier variants attempted to obtain a verification code or PIN, persuade the victim to scan a QR code that linked an attacker-controlled device, or impersonate automated support.
In the newer scenario, fake support claims that message synchronisation has failed or that history may be lost. The victim is told to enable backups and paste the recovery key into the conversation.
Why the backup key matters
A recovery key is not a short-lived login code. It can enable restoration of a backup containing historical private and group conversations. The FBI also warns about a less obvious consequence: if the victim recreates the account with the same phone number, the old recovery key may still let the attacker access the existing backup.
Generate a new backup recovery key to invalidate a disclosed one. This prevents future retrieval with the old key, but it cannot delete information that an attacker already downloaded. Fast action limits additional harm; it does not guarantee reversal of the disclosure.
Encryption still works—the attack goes around it
End-to-end encryption protects a message between correctly authenticated devices. It cannot help when the user approves an unknown device, sends an account-takeover code or reveals the key to an encrypted backup. The attacker does not need to defeat cryptography; they persuade the owner to open a legitimate access path.
The same principle explains why phishing can defeat a technically secure service. The effective boundary becomes the credibility of the message and the pressure placed on the recipient.
How to recognise the attempt
- Real support does not ask for your recovery key, PIN or verification code in a chat. Do not share it with an account that has a convincing name or logo.
- Do not follow account “verification” or “restoration” links. Open the application’s settings or the vendor’s official website yourself.
- Stop when urgency appears. Threats of message loss, immediate suspension or compulsory migration are intended to prevent verification.
- Confirm unusual requests through another channel. Call a known number or speak to the person directly.
- Review linked devices and members of sensitive groups. An unknown device or duplicate identity can be the first visible trace.
MFA remains valuable, but a code handed to an attacker in real time is no longer a protective factor. Where supported, phishing-resistant methods such as passkeys and hardware security keys reduce this class of risk.
What to do after disclosing a key or code
Stop the conversation and do not follow further instructions. Then:
- generate a new backup recovery key;
- remove unknown linked devices;
- change the PIN and any other disclosed credentials;
- warn contacts if messages may have been sent from the account;
- preserve screenshots, account names, links and timestamps;
- report the incident through your organisation’s security channel;
- investigate other accounts or devices exposed through the same conversation.
Journalists, government, defence and organisations supporting Ukraine should have a predefined reporting path for suspicious messenger contacts. A private messenger used for professional communication belongs in the organisation’s threat model.
What the alert does not prove
The advisory does not report a mass compromise of Signal, and it does not provide a new victim count limited to the backup-key variant. It confirms an ongoing targeted campaign and an evolution in tactics. A similar-looking message should not be attributed to a specific Russian operator without technical evidence.
The practical rule is simple: messaging support does not need your recovery key, PIN or verification code. If anyone asks for one, end the conversation and verify the situation independently.
Sources: FBI/CISA advisory, 26 June 2026, FBI/CISA advisory, 20 March 2026, CERT-EU Cyber Brief, June 2026.


