Allied Intelligence — 2026-07-02
Dutch AIVD and MIVD Warn Russian State Hackers Shifted to Stealing Signal Backup Recovery Keys in Ongoing Espionage Campaign
BLUFRussia's pivot to recovery-key phishing converts encrypted messaging from a defensive asset into a bulk-collection vulnerability for any official who treats Signal as a secure channel.
The Dutch MIVD and AIVD said Monday that Russian state hackers have shifted tactics against Signal accounts, moving from stealing verification codes to phishing for Signal Backup Recovery keys, and that the agencies corroborate a warning US services issued on June 26 based on their own research 12. The attackers send messages posing as "Signal Support" and create false urgency to induce targets to hand over the 64-character recovery key, which lets them download full message histories, photos, and documents from the past 45 days or take full control of the account; agencies advise anyone who shared a key to generate a new one immediately, which invalidates it for future backups but cannot undo access to data already downloaded 23. MIVD and AIVD first warned on March 9 that Russia was targeting Signal and WhatsApp accounts of Western and Ukrainian officials, government employees, military personnel, and journalists, and both agencies said the campaign remains large-scale and successful, with attackers obtaining sensitive information, including messages belonging to Dutch government employees 124. MIVD Director Vice Admiral Peter Reesink said encrypted apps like Signal and WhatsApp are unsuitable for confidential communication despite their encryption, while AIVD Director-General Simone Smit said the new method shows attackers continually adapting; both agencies stressed the Signal app itself has not been compromised, only individual accounts 12.
Analysis
The shift from verification-code theft to recovery-key phishing targets user behavior rather than Signal's encryption, and both agencies confirm the application itself remains uncompromised. A stolen 64-character key hands attackers a rolling 45-day archive of messages, photos, and documents, or full account takeover, converting episodic interception into bulk collection against officials, military personnel, and journalists across NATO and Ukraine. Dutch corroboration of the US warning issued June 26 shows the operation running in parallel against multiple national target sets rather than resting on one service's isolated observation. The campaign's persistence since the March 9 initial warning indicates the tactic shift is an operational adaptation to defensive awareness, not an abandonment of the broader effort.
4 sources
- Russian hackers use phishing to get access to message backups, Dutch spy agencies say - NL Times
- Russische hackers richten zich op Signal-backups via nieuwe phishing-methode - AIVD
- AIVD waarschuwt voor phishingaanvallen gericht op Signal-back-ups - Security.NL
- Russische hackers richten zich op Signal-backups via nieuwe phishing-methode - Ministry of Defence (Netherlands)
View in full brief →