ctipilot.ch
← Back to Daily brief 2026-06-30
NOTABLEupdatethreat

US posts $10M bounty on the Russia-nexus Signal/WhatsApp crews and adds Signal Backup-Recovery-Key theft to the advisory

discovered 2026-06-30 05:10 UTCrun 2026-06-30-9aaa11143 sourcesmulti-source

UPDATE · originally covered FBI/CISA: Russian intelligence now phishing Signal Backup Recovery Keys for persistent account takeover (2026-06-27)

The US Department of State's Rewards for Justice program posted a $10 million reward on 2026-06-29 for information on members of UNC5792 (assessed associated with Russia's FSB) and UNC4221 (assessed associated with the GRU), and the FBI/CISA advisory was updated with a newly observed tactic — theft of Signal Backup Recovery Keys (Rewards for Justice, 2026-06-29 · BleepingComputer, 2026-06-29).

The recovery-key tactic is the operationally material change: a stolen backup recovery key is persistent — even after the victim rotates their phone number or reinstalls, the attacker can restore the full message backup, including prior history and group content, so access survives the initial social-engineering window (SecurityWeek, 2026-06-29). Targets are current/former government and military officials, political figures, journalists, and Ukraine-based officials across Europe and the US. Swiss federal and cantonal officials using Signal should treat backup-recovery-key protection (and re-checking the NCSC-CH Signal guidance covered 2026-06-25) as an action item, not a watch item.

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.