← All stories
● Covered by 2 sources · 2 reportsHigh impact

FBI and CISA Warn of Russian Phishing Attacks on Signal and WhatsApp Accounts

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • FBI and CISA update warning on Russian phishing tactics.
  • Attackers use Signal Backup Recovery Keys to hijack accounts.
  • U.S. offers $10 million for information on attackers.
  • Thousands of accounts, including officials and journalists, compromised.
  • Campaign attributed to Russian intelligence groups.

Overview of the Attack

The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) have updated their warning about Russian intelligence phishing campaigns. The campaigns target Signal and WhatsApp accounts, particularly through tactics involving Signal Backup Recovery Keys.

Russian hackers prompt targets to share their Signal Backup Recovery Key, enabling them to hijack accounts by restoring backups. The attackers can read messages and maintain account access even if the phone number is reactivated with a new account.

Background and Targets

Initially warned in March, these phishing operations have been operational since at least then. They involve fake support messages that trick users into relinquishing account information, enabling attackers to compromise accounts completely.

The affected targets are individuals of high intelligence value, such as current and former U.S. and international government officials, military personnel, journalists, and political figures.

Efforts to Counteract the Threat

In response to the ongoing threat, the U.S. government has announced a reward of up to $10 million for information that can help identify or locate the cyber group responsible. This group is linked to Russian intelligence services and has already compromised thousands of accounts.

The updated advisory also outlines steps for users to protect themselves, such as generating a new Signal Backup Recovery Key to invalidate the compromised one and secure future backups.

Why It Matters

This campaign represents a significant cybersecurity threat, as it impacts sensitive communications of government officials and influential figures. The potential access to sensitive information poses national security risks.

The exploitation of Signal's recovery feature highlights the need for enhanced account security measures and vigilance against phishing tactics, particularly those associated with state-sponsored cyber threats.

Takeaways

Users of Signal and WhatsApp, especially those in high-value roles, should be cautious about phishing attempts that seek account recovery information.

Implementing proactive security measures, like regular key updates, and being skeptical of unsolicited messages can mitigate these risks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~11 min · 9 stories · Aug 16

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The US government announces a reward of up to $10 million for information about a Russian cyber group compromising Signal and WhatsApp accounts. The attackers have targeted thousands of accounts belonging to US government officials and journalists since at least March, utilizing phishing tactics to gain access to sensitive communications.

The FBI and CISA have updated a warning about Russian intelligence phishing tactics that now include prompting users to share their Signal Backup Recovery Key. This allows attackers to hijack accounts, read messages, and maintain access even if the account is reactivated with a different number.