# FBI and CISA Sound Alarm: Russian Intelligence Now Targeting Signal Backup Recovery Keys
Russian intelligence-backed threat actors have escalated their phishing campaign against Signal users, shifting from simple account compromise to a more sophisticated attack targeting the messaging app's backup recovery mechanism. According to an updated alert from the FBI and CISA, the operators have refined their tactics to extract Signal Backup Recovery Keys from targets—a credential that grants persistent access to account backups and complete message histories, even if the original password is changed.
## The Threat
The FBI and CISA warned that Russian intelligence operators, following an initial phishing attempt to compromise Signal accounts, are now taking an additional step: coercing targets into voluntarily surrendering their Signal Backup Recovery Key. Once obtained, attackers can restore the account's backup data and gain complete access to:
The critical difference in this new phase is that the recovery key persists as a valid credential. Changing the Signal account password does not invalidate the backup recovery key, meaning attackers retain continued access to the backup even if the user detects the compromise and resets their account.
## Background and Context
This alert represents an evolution of a March 2026 warning from the same agencies about Russian intelligence phishing Signal accounts. At that time, the threat was straightforward: spear-phishing attacks designed to steal Signal account credentials directly.
The transition to targeting backup recovery keys suggests operators have developed a deeper understanding of Signal's architecture and are now employing a multi-stage compromise strategy. Rather than relying solely on stolen passwords—which can be changed and potentially detected through unusual access patterns—the attackers are targeting a key designed for account recovery scenarios.
Signal, developed by the Signal Foundation and used by security professionals, journalists, and activists worldwide, has positioned backup recovery as a security feature to prevent account lockouts. The backup recovery key is a unique credential separate from the account password, intended to allow users to regain access to their accounts if they forget their password or lose access to their devices.
For Russian intelligence operators, this represents an attractive target because:
## Technical Details: How the Attack Works
### Initial Compromise
The attack begins with spear-phishing: operators send carefully crafted messages impersonating Signal support, security warnings, or other trusted entities. These messages direct targets to fraudulent Signal login pages or phishing portals designed to harvest credentials.
### The New Escalation: Recovery Key Extraction
Once the initial phishing succeeds and operators confirm they have valid credentials, they employ social engineering to convince targets that:
Victims, believing they are protecting their account, provide the recovery key—which operators likely request through a secondary phishing message or fake Signal interface.
### Account Takeover
With the backup recovery key in hand, attackers can:
1. Restore the account backup on a device they control
2. Access all historical messages without sending login notifications to the legitimate user's registered devices
3. Maintain persistent access that survives password changes
4. Pose as the account holder in group chats and private conversations, potentially gathering intelligence, conducting additional social engineering, or harvesting information from contacts
## Signal Backup Architecture
Signal's backup system is designed to store an encrypted copy of account data that can be restored during account recovery. The backup recovery key is a separate credential—typically a numeric PIN or passphrase—that protects this backup. Because the backup is encrypted and stored locally (or optionally synced), Signal itself cannot authenticate the recovery key through normal login mechanisms, making it a particularly valuable target for attackers seeking offline persistence.
## Who Is At Risk?
The FBI and CISA specifically assess that Russian intelligence services are targeting:
However, the general techniques—spear-phishing and social engineering to obtain recovery credentials—pose a risk to any Signal user if targeted by sophisticated threat actors. The attack does not require exploits or zero-days; it relies entirely on convincing users to voluntarily surrender credentials.
## Implications for Organizations
Government and Defense Contractors: Personnel with access to classified or sensitive information face increased risk if their Signal accounts are compromised. A complete message history breach could expose intelligence sources, operational details, or negotiating positions.
Media and NGOs: Journalists and human rights organizations operating in contested regions have long relied on Signal for secure communication with sources. Backup key compromise could expose source identities and sensitive investigations.
General Security Posture: The attack highlights that no single security tool, including Signal, is a complete solution. Even end-to-end encrypted messaging can be compromised if users are socially engineered into surrendering the keys that protect offline backups.
## Recommendations
### For Signal Users
### For Organizations
---
## HackWire Analysis
This escalation reveals a fundamental tension in secure communications design: backup and recovery mechanisms are attractive targets precisely because they exist to restore access when normal authentication fails. Russian intelligence operators have identified that most users neither understand nor actively protect backup recovery keys, making them lower-hanging fruit than primary credentials.
What stands out is the *sophistication of the social engineering component*. These aren't indiscriminate phishing attacks; operators are conducting targeted reconnaissance to identify high-value individuals, crafting believable pretexts, and developing layered exploitation chains. The fact that they're taking time to extract recovery keys suggests they've assessed that persistent, password-independent access is worth the additional steps—a strong indicator that their targets include individuals with ongoing, high-value communications.
The persistence of the recovery key after password changes is not a bug but a feature of Signal's design. If the recovery key were invalidated by password resets, users who had forgotten their passwords could not restore their backups. But this design choice means defenders cannot simply change passwords to revoke access; users must manually rotate recovery keys or disable backups entirely—actions most users don't know how to take. Signal could address this by implementing optional automatic recovery key rotation or by alerting users when recovery keys are used on new devices, but such changes have not been announced.
The broader pattern here mirrors earlier Russian intelligence operations: targeting specific individuals, layering multiple compromise vectors, and seeking to establish persistent, durable access. If your organization or role makes you a plausible target, assume Russian intelligence is already studying your communication patterns. Signal remains secure as an *individual tool*, but organizational security requires defense-in-depth beyond encrypted messaging—offline verification protocols, anomaly detection on communication patterns, and personnel who understand that their recovery credentials are as sensitive as passwords.
— HackWire Editorial
---
## Related Coverage