The bottom line: Russian intelligence services compromise Signal backup recovery keys via phishing to gain persistent access to accounts.
Russian intelligence services are conducting phishing campaigns to steal backup recovery keys from the Signal messaging app. The theft of these keys enables attackers to gain permanent access to Signal accounts, with government employees and journalists being particularly targeted.
Security researchers have documented that Russian intelligence services are conducting a targeted campaign against Signal users. The attackers use phishing emails to steal backup recovery keys – cryptographic keys that Signal uses to protect encrypted local backups.
Anyone whose backup recovery key is compromised can decrypt the backup file using the stolen key. This enables the attacker not only to access archived messages, but also potentially to access the Signal account itself. This is particularly critical for users with sensitive contacts or confidential conversations.
For CISOs, this means: government employees and journalists in their own organization face elevated risks. Swift response to suspected incidents – such as unusual phishing attempts or suspicious recovery key requests – is required. Recommended measures include enhanced awareness training on Signal security features, multi-factor authentication where technically feasible, and securing backup keys.
Source: www.security-insider.de · Published 22 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.