SSU and FBI Expose Russian Intelligence Campaign Targeting Signal Users With Evolved Recovery Key Theft Technique
The SSU and FBI jointly disclosed a sustained Russian intelligence campaign targeting messaging accounts of officials, military, politicians, and activists across Ukraine, Europe, and the United States, with SSU citing collection of sensitive military and political data as the objective
The pivot to Backup Recovery Keys closes the escape route account rotation previously offered: operators who harvest a key before detection retain read access to full prior message history regardless of subsequent account recreation. An FBI/IC3 primary advisory grounds the assessment that the campaign's tiered posture, sophisticated tooling for senior officials alongside mass SMS phishing, marks this as a scalable collection platform. The shift from verification codes may reflect target hardening after March 2026 rather than capability expansion, since rotation had become common defensive practice, making durable credentials the logical next target class. Officials who accepted rotation as sufficient mitigation after March require reassessment of exposure and of contacts reached since suspected compromise.