CISA and FBI Issue 10 Million Dollar Bounty for Russian UNC5792 Group Targeting Signal Backup Keys
The State Department's Rewards for Justice program is offering up to $10 million for information identifying or locating members of
The $10 million reward functions as public attribution rather than near-term disruption, since the core technique, stolen backup recovery keys, persists across account resets and leaves previously compromised officials, journalists, and NGO personnel exposed unless they explicitly regenerate or revoke those keys rather than merely re-registering. Targeting NATO officials and Ukraine-focused civil society alongside US government personnel indicates Moscow is treating the messaging-app vector as a standing collection channel rather than a one-off operation. Friday's FBI advisory on key theft is now paired with formal attribution to FSB Border Guard and GRU units, converting a technical warning into a named accusation, though that unit-level attribution rests on government designations without independently verifiable sourcing, and Washington may instead be crowdsourcing identifications of individuals it cannot yet make on its own. Moderate confidence reflects three secondary outlets converging independently atop the primary Rewards for Justice posting.
4 sources
- UNC5792 -
Rewards for Justice (U.S. Department of State) - US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp -
The Record from Recorded Future News - US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve -
SecurityWeek - U.S. offers $10 million for hackers targeting WhatsApp, Signal users -
BleepingComputer