# FBI and CISA Sound Alarm: Russian Intelligence Now Targeting Signal Backup Recovery Keys


Russian intelligence-backed threat actors have escalated their phishing campaign against Signal users, shifting from simple account compromise to a more sophisticated attack targeting the messaging app's backup recovery mechanism. According to an updated alert from the FBI and CISA, the operators have refined their tactics to extract Signal Backup Recovery Keys from targets—a credential that grants persistent access to account backups and complete message histories, even if the original password is changed.


## The Threat


The FBI and CISA warned that Russian intelligence operators, following an initial phishing attempt to compromise Signal accounts, are now taking an additional step: coercing targets into voluntarily surrendering their Signal Backup Recovery Key. Once obtained, attackers can restore the account's backup data and gain complete access to:


  • Private messages and conversations
  • Group message history
  • Account authentication tokens
  • Stored media and attachments

  • The critical difference in this new phase is that the recovery key persists as a valid credential. Changing the Signal account password does not invalidate the backup recovery key, meaning attackers retain continued access to the backup even if the user detects the compromise and resets their account.


    ## Background and Context


    This alert represents an evolution of a March 2026 warning from the same agencies about Russian intelligence phishing Signal accounts. At that time, the threat was straightforward: spear-phishing attacks designed to steal Signal account credentials directly.


    The transition to targeting backup recovery keys suggests operators have developed a deeper understanding of Signal's architecture and are now employing a multi-stage compromise strategy. Rather than relying solely on stolen passwords—which can be changed and potentially detected through unusual access patterns—the attackers are targeting a key designed for account recovery scenarios.


    Signal, developed by the Signal Foundation and used by security professionals, journalists, and activists worldwide, has positioned backup recovery as a security feature to prevent account lockouts. The backup recovery key is a unique credential separate from the account password, intended to allow users to regain access to their accounts if they forget their password or lose access to their devices.


    For Russian intelligence operators, this represents an attractive target because:


  • It provides persistent, password-independent access to account backups
  • It is rarely rotated by users unfamiliar with Signal's security architecture
  • Recovery from a backup can be performed without triggering standard login notifications
  • The backup contains a complete archive of message history and metadata

  • ## Technical Details: How the Attack Works


    ### Initial Compromise


    The attack begins with spear-phishing: operators send carefully crafted messages impersonating Signal support, security warnings, or other trusted entities. These messages direct targets to fraudulent Signal login pages or phishing portals designed to harvest credentials.


    ### The New Escalation: Recovery Key Extraction


    Once the initial phishing succeeds and operators confirm they have valid credentials, they employ social engineering to convince targets that:


  • Their account has been compromised (true, but they don't reveal they did it)
  • They must provide their "backup recovery key" or "backup PIN" to restore security
  • Time is critical, and the user must act immediately

  • Victims, believing they are protecting their account, provide the recovery key—which operators likely request through a secondary phishing message or fake Signal interface.


    ### Account Takeover


    With the backup recovery key in hand, attackers can:


    1. Restore the account backup on a device they control

    2. Access all historical messages without sending login notifications to the legitimate user's registered devices

    3. Maintain persistent access that survives password changes

    4. Pose as the account holder in group chats and private conversations, potentially gathering intelligence, conducting additional social engineering, or harvesting information from contacts


    ## Signal Backup Architecture


    Signal's backup system is designed to store an encrypted copy of account data that can be restored during account recovery. The backup recovery key is a separate credential—typically a numeric PIN or passphrase—that protects this backup. Because the backup is encrypted and stored locally (or optionally synced), Signal itself cannot authenticate the recovery key through normal login mechanisms, making it a particularly valuable target for attackers seeking offline persistence.


    ## Who Is At Risk?


    The FBI and CISA specifically assess that Russian intelligence services are targeting:


  • U.S. government officials and agency employees
  • Diplomatic personnel
  • Security and policy experts
  • Individuals working in sensitive industries
  • Journalists and activists in regions of Russian strategic interest

  • However, the general techniques—spear-phishing and social engineering to obtain recovery credentials—pose a risk to any Signal user if targeted by sophisticated threat actors. The attack does not require exploits or zero-days; it relies entirely on convincing users to voluntarily surrender credentials.


    ## Implications for Organizations


    Government and Defense Contractors: Personnel with access to classified or sensitive information face increased risk if their Signal accounts are compromised. A complete message history breach could expose intelligence sources, operational details, or negotiating positions.


    Media and NGOs: Journalists and human rights organizations operating in contested regions have long relied on Signal for secure communication with sources. Backup key compromise could expose source identities and sensitive investigations.


    General Security Posture: The attack highlights that no single security tool, including Signal, is a complete solution. Even end-to-end encrypted messaging can be compromised if users are socially engineered into surrendering the keys that protect offline backups.


    ## Recommendations


    ### For Signal Users


  • Do not share your backup recovery key with anyone, including Signal support (Signal staff will never ask for it)
  • Memorize your recovery key or store it in a secure physical location—not in email or cloud storage
  • Disable Signal backups entirely if you do not need them; this eliminates the attack surface
  • Verify requests for account recovery by contacting Signal through official channels independently
  • Enable registration lock in Signal settings to prevent account transfer without additional authentication
  • Monitor for unusual account activity, including logins from unknown devices or locations

  • ### For Organizations


  • Provide security awareness training on backup recovery scams and phishing indicators
  • Establish incident response procedures for Signal account compromise, including immediate password resets and backup key rotations
  • Monitor for leaked recovery credentials through threat intelligence feeds and breach databases
  • Consider Signal infrastructure alternatives for highly sensitive communications (e.g., dedicated networks with additional physical security)
  • Implement email authentication standards (SPF, DKIM, DMARC) to reduce phishing of internal communications

  • ---


    ## HackWire Analysis


    This escalation reveals a fundamental tension in secure communications design: backup and recovery mechanisms are attractive targets precisely because they exist to restore access when normal authentication fails. Russian intelligence operators have identified that most users neither understand nor actively protect backup recovery keys, making them lower-hanging fruit than primary credentials.


    What stands out is the *sophistication of the social engineering component*. These aren't indiscriminate phishing attacks; operators are conducting targeted reconnaissance to identify high-value individuals, crafting believable pretexts, and developing layered exploitation chains. The fact that they're taking time to extract recovery keys suggests they've assessed that persistent, password-independent access is worth the additional steps—a strong indicator that their targets include individuals with ongoing, high-value communications.


    The persistence of the recovery key after password changes is not a bug but a feature of Signal's design. If the recovery key were invalidated by password resets, users who had forgotten their passwords could not restore their backups. But this design choice means defenders cannot simply change passwords to revoke access; users must manually rotate recovery keys or disable backups entirely—actions most users don't know how to take. Signal could address this by implementing optional automatic recovery key rotation or by alerting users when recovery keys are used on new devices, but such changes have not been announced.


    The broader pattern here mirrors earlier Russian intelligence operations: targeting specific individuals, layering multiple compromise vectors, and seeking to establish persistent, durable access. If your organization or role makes you a plausible target, assume Russian intelligence is already studying your communication patterns. Signal remains secure as an *individual tool*, but organizational security requires defense-in-depth beyond encrypted messaging—offline verification protocols, anomaly detection on communication patterns, and personnel who understand that their recovery credentials are as sensitive as passwords.


    HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)