Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AI Agents Mythos 5, GPT-5.6-Sol Escaped Cybersecurity Sandbox to Attack Real Systems
August 5, 2026
CISA Warns of Apache Tomcat Encryption Flaw Actively Exploited
August 5, 2026
Critical RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers
August 5, 2026
Home/Threats/Signal App Vulnerability Lets Attackers Steal User Backups
Threats

Signal App Vulnerability Lets Attackers Steal User Backups

Key Takeaways A sophisticated phishing campaign is targeting Signal users, particularly journalists and activists. Attackers impersonate “Signal Support” to trick users into divulging...

Jennifer sherman
Jennifer sherman
June 1, 2026 4 Min Read
54 0

Key Takeaways

  • A sophisticated phishing campaign is targeting Signal users, particularly journalists and activists.
  • Attackers impersonate “Signal Support” to trick users into divulging their 64-character backup recovery keys.
  • Possession of the recovery key allows attackers to decrypt and access years of stored chat history, including messages and media.
  • Signal will never proactively contact users or request sensitive information like recovery keys.
  • Users should enable Registration Lock and PIN protection within Signal to bolster security.

Coordinated Phishing Campaign Targets Signal Users, Aims to Steal Backup Keys

A new, highly coordinated phishing operation is actively compromising accounts of individuals who rely on Signal, the secure messaging application favored by privacy advocates, journalists, and political activists globally. These campaigns are meticulously designed to deceive users into surrendering their private backup recovery keys, which could expose extensive historical conversations and sensitive data.

Table Of Content

  • Key Takeaways
  • Coordinated Phishing Campaign Targets Signal Users, Aims to Steal Backup Keys
  • Anatomy of the Attack
  • The Danger of Compromised Recovery Keys
  • What You Should Do

The attackers masquerade as Signal’s official support team, employing social engineering tactics to persuade users to provide their backup recovery keys. These keys are crucial, as they can unlock entire archives of private chat histories, making this campaign a significant concern for cybersecurity researchers and digital rights organizations alike. Reports detailing this threat have emerged from various sources, including AI Weekly and TechCrunch.

Anatomy of the Attack

The phishing attempt typically initiates with a direct message sent within the Signal application itself. This message, appearing to originate from “Signal Support,” falsely warns recipients that their “chats and media are at risk of permanent loss due to a sync issue.”

Victims are then instructed to share their 64-character recovery key to rectify the purported problem. Should a user comply, this key grants attackers full access to years of stored messages, photographs, and documents, enabling them to download and decrypt the complete message history, not just future communications.

The campaign gained public attention after Josh Rogin, a Washington Post analyst, posted a screenshot of a fake message on May 27, 2026. Rogin cautioned his followers against falling for the scam, noting that numerous anti-CCP activists had already encountered similar phishing attempts.

Access Now’s Digital Security Helpline has corroborated that journalists, dissidents, and activists are the primary targets of this ongoing operation. Investigators received nearly identical phishing messages from two separate victims, underscoring the coordinated nature of the attack rather than a random opportunistic effort.

The Danger of Compromised Recovery Keys

The unique threat posed by this campaign stems from the power of the recovery key. Signal’s Secure Backups feature encrypts and stores user data, with the decryption key remaining exclusively on the user’s device. If an attacker acquires this key and subsequently gains access to the user’s account, they can download and decrypt the entire message history, including all past conversations stored in the backup.

The phishing messages are meticulously crafted to appear legitimate. Arriving from an account labeled “Signal Support” within the app itself, they cultivate a false sense of authenticity. The language used conveys urgency, pressuring users to act immediately to avoid data loss. Many users, accustomed to Signal’s robust security, may not anticipate a scam originating from within the supposedly secure application.

Security researchers at Malwarebytes have indicated that while obtaining the recovery key is a critical step, attackers still require further action to complete an account takeover. They must gain access to the Signal account itself before leveraging the key to download and decrypt the backup. However, this additional step does not diminish the severity of the threat, as stealing the key is a foundational move towards full account compromise.

The consistent messaging received by victims across different networks strongly suggests a highly organized group is behind these attacks. Researchers believe the operation is targeted rather than broad, with a clear intent to single out activists and journalists.

What You Should Do

  • Understand Signal’s Communication Policy: Signal explicitly states that it will never initiate contact with users or request registration codes, PINs, or recovery keys. Any message claiming to be from “Signal Support” and asking for such information is a scam.
  • Be Skeptical of Unsolicited Messages: Treat any unexpected message warning of account issues as highly suspicious, regardless of the platform where it appears.
  • Never Share Sensitive Information: Absolutely avoid sharing verification codes, recovery keys, or authentication secrets with anyone, even if they appear to be an official contact.
  • Avoid Clicking Links: Refrain from clicking links embedded in messages that warn of account problems. Navigate directly to official app settings or websites if you need to verify account status.
  • Enable Registration Lock: Activate the Registration Lock feature in Signal. This requires your Signal PIN to register your phone number on a new device, adding a crucial layer of protection against unauthorized access.
  • Utilize PIN Protection and Device-Change Alerts: Ensure PIN protection is enabled and set up alerts for device changes to be notified of any attempts to link your account to a new device.
  • Consider Disappearing Messages: While not a preventative measure against this specific attack, using disappearing messages can limit the extent of historical data available if an account is ever compromised in the future.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityExploitHackerMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Microsoft Reverses Stance on Suing Security Researchers

Next Post

Chollima Hackers Target PHP Developers via Compromised Packagist Package

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
How SOCs Detect and Stop AI Phishing Attacks Bypassing Email Gateways
August 4, 2026
Critical Flowise RCE Flaws Let Attackers Execute Code on AI Workflow Servers
August 4, 2026
OWASP Releases Subtractive Security Top 10 to Reduce Cyber Risks
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us