IC Technology & Surveillance — 2026-06-27
FBI and CISA Update Advisory Warning Russian Intelligence Now Targeting Signal Backup Recovery Keys for Permanent Account Takeover
BLUFSignal is unlikely to patch the Backup Recovery Key vector within six months of the June 26 advisory, leaving RIS with persistent access that survives account recreation on compromised numbers.
FBI and CISA on June 26 updated their March 2026 Signal phishing advisory, reporting that Russian Intelligence Services actors tracked as UNC5792 and UNC4221, including FSB officers embedded with the FSB Border Guards, now solicit Backup Recovery Keys in addition to verification codes and account PINs 1. Phishing messages impersonate Signal support and walk targets through enabling backups, surfacing the Recovery Key, and pasting it into attacker-controlled chat 1. The IC3 advisory states a surrendered key grants access to the account's historical private and group messages and enables full account takeover 12. The key remains valid even if the victim creates a new account on the same phone number; manual key regeneration in settings is the only way to revoke it, and does not prevent the actor from retaining any backup already downloaded 1. Stated targets include current and former U.S. and international government officials, military personnel, political figures, journalists, and officials in Ukraine; the advisory confirms no compromise of Signal's encryption or the application itself, and the State Department's Rewards for Justice program is offering up to $10 million for information on UNC5792 1.
AnalysisSignal is
unlikely to close the Backup Recovery Key vector through a product update with explicit notification or automatic regeneration within six months of the June 26 advisory, leaving the designated target population exposed during that window. Low analytic confidence reflects the absence of observable development signals from Signal and the historical lag between government advisories and consumer application security updates. The tactic's strategic weight derives from its persistence: a compromised key survives account recreation on the same phone number, converting a single successful phish into indefinite access against targets who consider the compromise remediated. RIS actors will continue exploiting this vector for as long as the architectural gap remains open.
3 sources
- Russian Intelligence Services Continue to Target Commercial Messaging Applications - FBI Internet Crime Complaint Center (IC3)
- FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys - The Hacker News
- Russian Intelligence Phishing Strikes Encrypted Messaging, CISA and FBI Warn Windows Users - Windows News
View in full brief →