# U.S. Puts $10 Million Price on Russian Hacker Groups Targeting Signal and WhatsApp


The U.S. Department of State has announced a substantial bounty as part of its escalating response to coordinated Russian state-sponsored cyberattacks against encrypted messaging platforms. The government is offering up to $10 million for information identifying or locating members of two Russian hacker groups—UNC5792 and UNC4221—linked to the Russian Federal Security Service (FSB) and the Russian military, respectively.


The bounty, announced through the department's "Rewards for Justice" (RFJ) program, marks a significant governmental intervention in the ongoing battle against state-sponsored cyber espionage. Both groups have conducted sophisticated phishing campaigns specifically targeting the encrypted messaging accounts of U.S. government officials, military leaders, diplomatic personnel, and NATO allies.


## The Threat


UNC5792 and UNC4221 represent a coordinated threat to communications security at the highest levels of government and allied nations. These groups have demonstrated a particular focus on compromising Signal and WhatsApp accounts—two of the world's most widely trusted encrypted messaging platforms.


Primary targets include:

  • U.S. government officials and military leadership
  • NATO diplomatic and defense personnel
  • Journalists covering Russia and the Ukraine conflict
  • Non-governmental organizations supporting Ukraine
  • Security researchers and Russian affairs specialists
  • Intelligence community personnel

  • The FBI and CISA reported in a March 2026 advisory that thousands of individual commercial messaging accounts have already been compromised through these campaigns. Despite the alarming number of compromised accounts, U.S. authorities have emphasized that the encryption protocols underlying Signal and WhatsApp have not been broken. Instead, the attackers rely on sophisticated social engineering to manipulate users into voluntarily revealing sensitive authentication data.


    ## Background and Context


    UNC5792 operates under the umbrella of the Russian Federal Security Service (FSB), specifically its Border Guards division. The group represents a continuation of Russia's broader cyber campaign against Western governments and institutions, particularly those supporting Ukraine or analyzing Russian military activities.


    UNC4221 is identified as working directly on behalf of Russian military services, adding a second dimension to Russia's coordinated cyber offensive. The attribution of these groups to specific Russian government entities underscores the state-sponsored nature of the operations—a key factor in the State Department's decision to invoke the Rewards for Justice program, typically reserved for information on foreign state actors.


    The RFJ program, established to combat terrorism and provide intelligence on foreign threats, has been expanded to include cyber threats against U.S. critical infrastructure and national security interests. This expansion reflects the growing recognition of cyber operations as a matter of national security equivalent to traditional intelligence threats.


    ## Technical Details: The Signal Backup Recovery Key Attack


    The most sophisticated aspect of these campaigns centers on a social engineering attack targeting Signal Backup Recovery Keys—a critical authentication mechanism that grants access to encrypted message history.


    How the attack works:


    1. Impersonation: Attackers contact targets via direct messaging, impersonating legitimate Signal support personnel

    2. False urgency: The fraudulent support agents claim a mandatory two-factor verification process is required

    3. Key extraction: Targets are manipulated into revealing their backup recovery key through fake verification procedures

    4. Account compromise: Once the backup key is obtained, attackers gain full access to the victim's encrypted message history


    The attack exploits a fundamental trust vulnerability: most users assume that support contacts within the messaging platform itself are legitimate. Attackers leverage this assumption by creating convincing fake verification requests that mimic authentic platform communications.


    What legitimate Signal support never does:

  • Request verification codes within the application
  • Ask users to provide recovery keys
  • Send links requesting account verification or restoration
  • Communicate through direct messages rather than official company email

  • ## Implications for Organizations and Users


    The scope and sophistication of these campaigns reveal several critical vulnerabilities:


    | Risk Factor | Impact |

    |---|---|

    | Credential exposure | Thousands of government and diplomatic communications potentially disclosed |

    | Intelligence collection | Russia gains insights into U.S. and NATO strategic planning and personnel networks |

    | Operational security | Officials and journalists covering Ukraine face heightened targeting and surveillance |

    | Supply chain risk | NGOs and researchers supporting Ukraine become intelligence targets |


    Organizations with personnel in diplomatic, military, intelligence, or policy roles face disproportionate risk. However, the broader implications extend to any organization whose employees communicate sensitive information via Signal or WhatsApp—platforms chosen specifically for their encryption capabilities.


    The attacks underscore a persistent challenge in cybersecurity: encryption alone is insufficient protection against determined social engineering. Even platforms with military-grade encryption can be compromised when users are manipulated into surrendering authentication credentials.


    ## Recommendations for Defense


    For government and organizational leadership:

  • Implement mandatory security awareness training focused on social engineering and impersonation attacks
  • Establish clear communication protocols for legitimate support requests
  • Use hardware security keys where possible to add multi-factor authentication layers
  • Audit access logs for messaging platform accounts, particularly those belonging to sensitive personnel
  • Brief personnel on the specific tactics described in this campaign

  • For individual users:

  • Verify all support requests through official company channels (Signal's support email, not in-app messages)
  • Never share backup recovery keys or two-factor authentication codes, regardless of the stated reason
  • Treat unsolicited requests from "support" as suspicious, even if they appear to come from within the platform
  • Consider using Signal's "Safety Number" verification feature to confirm contact identity
  • Enable disappearing messages for sensitive communications where appropriate

  • For security teams:

  • Monitor for suspicious in-platform messaging patterns targeting high-value accounts
  • Log and investigate any recovery key access requests or backup restoration attempts
  • Implement detection rules for bulk phishing campaigns targeting government and diplomatic email domains
  • Coordinate with messaging platform security teams on threat indicators

  • ## HackWire Analysis


    The $10 million bounty signals a significant escalation in the U.S. government's response to Russian cyber espionage, but the real story lies in what it reveals about the state of communications security in 2026. Despite investing heavily in encryption technology, the U.S. government continues to lose access to its most sensitive communications through attacks that don't require breaking encryption at all—they merely require convincing humans to surrender the keys.


    This pattern reflects a broader reality that security practitioners have long recognized: cryptography secures data, but authentication, user behavior, and operational security determine who actually gets compromised. The sophistication of Signal and WhatsApp's encryption becomes irrelevant the moment a user is socially engineered into revealing a backup recovery key.


    What's particularly notable is the targeting profile. This isn't indiscriminate cybercriminal activity. UNC5792 and UNC4221 have systematically targeted the specific personnel most valuable to Russian intelligence: those making decisions about Ukraine support, those analyzing Russian military capabilities, those coordinating NATO response. This selective, high-value targeting combined with sophisticated impersonation tactics suggests these groups are well-resourced, well-trained, and operating with clear intelligence objectives.


    The timing is also significant. As the Ukraine conflict continues to evolve, Russia appears to be doubling down on human intelligence collection to offset kinetic losses and understand Western strategic intentions. Compromised messaging accounts provide direct windows into policy deliberations, military planning, and intelligence assessments.


    For defenders, the lesson is uncomfortable: no amount of encryption protects against users who willingly provide authentication credentials. The solution requires moving beyond technology-only approaches toward comprehensive security cultures that treat social engineering as a first-order threat rather than an afterthought. The $10 million bounty may help identify some threat actors, but the more enduring challenge is transforming how organizations train and support personnel to resist these increasingly sophisticated attacks.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)