CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-06-27
HIGHupdatedthreat

FBI/CISA: Russian intelligence now phishing Signal Backup Recovery Keys for persistent account takeover

Analysis

The FBI and CISA issued an updated joint advisory (PSA I-062626-PSA, 2026-06-26) escalating their March 2026 warning about Russian Intelligence Services operators tracked as UNC5792 (FSB-linked) and UNC4221 (military-linked) (FBI IC3, 2026-06-26). The new tactic abuses Signal's optional encrypted-backup feature rather than any flaw in the Signal Protocol: operators impersonate Signal support, walk the target through Settings → Chats → Chat Backups, then elicit the 30-character Backup Recovery Key. With that key an attacker can download and decrypt the complete private and group message history offline. Critically, the advisory states the compromised key remains valid even if the victim later re-registers a new account on the same phone number, generating a new key in Settings invalidates future downloads but does not undo data already exfiltrated (FBI IC3, 2026-06-26). Stated targets are current and former government officials, military personnel, political figures, journalists, and Ukraine-related officials. This is T1598.003 (spearphishing via service) leading to T1078 (valid-account takeover via the backup mechanism), with no platform-layer sensor, detection relies on user reporting and MDM telemetry for backup-enable events. Why it matters to us: Swiss federal, cantonal-police, and parliamentary staff using Signal for sensitive coordination sit squarely in the named target population. Issue policy now: high-risk personnel should regenerate their Signal Backup Recovery Key, treat any unsolicited "Signal support" message as hostile, and on managed devices disable Signal backups via MDM where operational security requires it.

Updates1

Update

The US Department of State's Rewards for Justice program posted a $10 million reward on 2026-06-29 for information on members of UNC5792 (assessed associated with Russia's FSB) and UNC4221 (assessed associated with the GRU), and the FBI/CISA advisory was updated with a newly observed tactic, theft of Signal Backup Recovery Keys (Rewards for Justice, 2026-06-29 · BleepingComputer, 2026-06-29).

The recovery-key tactic is the operationally material change: a stolen backup recovery key is persistent, even after the victim rotates their phone number or reinstalls, the attacker can restore the full message backup, including prior history and group content, so access survives the initial social-engineering window (SecurityWeek, 2026-06-29). Targets are current/former government and military officials, political figures, journalists, and Ukraine-based officials across Europe and the US. Swiss federal and cantonal officials using Signal should treat backup-recovery-key protection (and re-checking the NCSC-CH Signal guidance covered 2026-06-25) as an action item, not a watch item.

Sources5

Revision history

  1. Published 2026-06-27-40e791d4
  2. Update 2026-06-30-9aaa1114

    UPDATE (originally covered 2026-06-27): The US Department of State's Rewards for Justice program posted a $10 million reward on 2026-06-29 for information on members of UNC5792 (assessed associated with Russia's FSB) and UNC4221 (assessed associated with the GRU), and the FBI/CISA advisory was updated with a newly …

    Changed: sources body

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.