The message looked entirely routine. A Signal notification warned users that hackers from Iran and "post-Soviet countries" had been attacking accounts — and that, for their own protection, they should immediately create an encrypted backup and share its recovery key. It was, of course, the attack itself. By crafting a warning that mimicked Signal's own language and interface, Russian intelligence operatives had found a way to make their victims hand over the keys to their entire message history.
Federal authorities in the United States have now placed a reward of up to $10 million on information leading to the identification or location of the two Russian state-linked groups behind the campaign, which has been tracked under the designations UNC5792 and UNC4221. Thousands of Signal and WhatsApp accounts have already been compromised, belonging to current and former US government officials, military personnel, political figures, and investigative journalists. The FBI first published an advisory about the phishing operation in March, but updated its warning last week after the campaign evolved in sophistication and reach. The operation exploits a genuine tension at the heart of encrypted messaging.
Signal is widely trusted precisely because of its security architecture: a feature built into the platform prevents attackers from reading past conversations even after an account is linked to a new device.