Signal App Vulnerability Lets Attackers Steal User Backups
Key Takeaways A sophisticated phishing campaign is targeting Signal users, particularly journalists and activists. Attackers impersonate “Signal Support” to trick users into divulging...
Key Takeaways
- A sophisticated phishing campaign is targeting Signal users, particularly journalists and activists.
- Attackers impersonate “Signal Support” to trick users into divulging their 64-character backup recovery keys.
- Possession of the recovery key allows attackers to decrypt and access years of stored chat history, including messages and media.
- Signal will never proactively contact users or request sensitive information like recovery keys.
- Users should enable Registration Lock and PIN protection within Signal to bolster security.
Coordinated Phishing Campaign Targets Signal Users, Aims to Steal Backup Keys
A new, highly coordinated phishing operation is actively compromising accounts of individuals who rely on Signal, the secure messaging application favored by privacy advocates, journalists, and political activists globally. These campaigns are meticulously designed to deceive users into surrendering their private backup recovery keys, which could expose extensive historical conversations and sensitive data.
Table Of Content
The attackers masquerade as Signal’s official support team, employing social engineering tactics to persuade users to provide their backup recovery keys. These keys are crucial, as they can unlock entire archives of private chat histories, making this campaign a significant concern for cybersecurity researchers and digital rights organizations alike. Reports detailing this threat have emerged from various sources, including AI Weekly and TechCrunch.
Anatomy of the Attack
The phishing attempt typically initiates with a direct message sent within the Signal application itself. This message, appearing to originate from “Signal Support,” falsely warns recipients that their “chats and media are at risk of permanent loss due to a sync issue.”
Victims are then instructed to share their 64-character recovery key to rectify the purported problem. Should a user comply, this key grants attackers full access to years of stored messages, photographs, and documents, enabling them to download and decrypt the complete message history, not just future communications.
The campaign gained public attention after Josh Rogin, a Washington Post analyst, posted a screenshot of a fake message on May 27, 2026. Rogin cautioned his followers against falling for the scam, noting that numerous anti-CCP activists had already encountered similar phishing attempts.
Access Now’s Digital Security Helpline has corroborated that journalists, dissidents, and activists are the primary targets of this ongoing operation. Investigators received nearly identical phishing messages from two separate victims, underscoring the coordinated nature of the attack rather than a random opportunistic effort.
The Danger of Compromised Recovery Keys
The unique threat posed by this campaign stems from the power of the recovery key. Signal’s Secure Backups feature encrypts and stores user data, with the decryption key remaining exclusively on the user’s device. If an attacker acquires this key and subsequently gains access to the user’s account, they can download and decrypt the entire message history, including all past conversations stored in the backup.
The phishing messages are meticulously crafted to appear legitimate. Arriving from an account labeled “Signal Support” within the app itself, they cultivate a false sense of authenticity. The language used conveys urgency, pressuring users to act immediately to avoid data loss. Many users, accustomed to Signal’s robust security, may not anticipate a scam originating from within the supposedly secure application.
Security researchers at Malwarebytes have indicated that while obtaining the recovery key is a critical step, attackers still require further action to complete an account takeover. They must gain access to the Signal account itself before leveraging the key to download and decrypt the backup. However, this additional step does not diminish the severity of the threat, as stealing the key is a foundational move towards full account compromise.
The consistent messaging received by victims across different networks strongly suggests a highly organized group is behind these attacks. Researchers believe the operation is targeted rather than broad, with a clear intent to single out activists and journalists.
What You Should Do
- Understand Signal’s Communication Policy: Signal explicitly states that it will never initiate contact with users or request registration codes, PINs, or recovery keys. Any message claiming to be from “Signal Support” and asking for such information is a scam.
- Be Skeptical of Unsolicited Messages: Treat any unexpected message warning of account issues as highly suspicious, regardless of the platform where it appears.
- Never Share Sensitive Information: Absolutely avoid sharing verification codes, recovery keys, or authentication secrets with anyone, even if they appear to be an official contact.
- Avoid Clicking Links: Refrain from clicking links embedded in messages that warn of account problems. Navigate directly to official app settings or websites if you need to verify account status.
- Enable Registration Lock: Activate the Registration Lock feature in Signal. This requires your Signal PIN to register your phone number on a new device, adding a crucial layer of protection against unauthorized access.
- Utilize PIN Protection and Device-Change Alerts: Ensure PIN protection is enabled and set up alerts for device changes to be notified of any attempts to link your account to a new device.
- Consider Disappearing Messages: While not a preventative measure against this specific attack, using disappearing messages can limit the extent of historical data available if an account is ever compromised in the future.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.