Threats & Adversaries · Phishing / BEC

Signal’s Weak Point Is Device Linking, Not Encryption

Signal’s encryption is not the weak point. A single successful QR scan or one-time code share can turn an attacker’s device into a trusted linked device, giving it access to the victim’s chats and contacts through the account itself.

Signal added in-app confirmations, warning messages, and more educational prompts after authorities in the U.S., the Netherlands, and Germany tied bogus “Signal Support” alerts to Russian state-linked attackers abusing the Linked Device flow. The changes are meant to slow users down when a request looks suspicious and to flag unverified contacts, missing shared groups, and fake support messages.

The pattern matters because the account takeover path sits outside the usual “encrypted messenger” mental model. For high-risk users, the threat is not interception of Signal traffic; it is social engineering that converts the victim’s own account into the attacker’s access channel.

2 sources · May 13

Timeline

Sources

Part of the PlainSec briefing for 2026-05-13

Every edition of this story: Signal’s Weak Point Is Device Linking, Not Encryption

More from today