Minacce · 92 giorni fa
Il punto non è più il singolo takeover dell’account. Una Backup Recovery Key rubata può restare valida anche dopo la ricreazione dell’account con lo stesso numero di telefono, quindi un phishing riuscito può lasciare un varco duraturo dentro chat passate e future.
CISA e FBI dicono che UNC5792 e UNC4221 hanno spostato le campagne contro Signal e WhatsApp da codici di verifica e PIN alla richiesta di Backup Recovery Keys. In parallelo, il Dipartimento di Stato ha messo una taglia fino a 10 milioni di dollari sui responsabili, segno che il problema è la persistenza dell’accesso, non solo l’intrusione iniziale.
Per chi usa queste app in contesti governativi, di difesa, media e ONG, la chiave di recupero va trattata come una credenziale permanente: se esce, il ripristino dell’account da solo non basta a chiudere la porta.
4 fonti che coprono questa storia
US offers $10 million for info on group behind Signal and WhatsApp hacking spree
Operation by two Russia-state groups has been ongoing since at least March.
The Record from Recorded Future
US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp
Russia-linked hacking groups tracked as UNC5792 and UNC4221 have socially engineered their way into the messaging accounts of government officials.
U.S. offers $10 million for hackers targeting WhatsApp, Signal users
Department of State is offering up to $10 million for information that helps identify or locate members of the UNC5792 and UNC4221 hacker groups, which are linked to Russia's intelligence and military services.
US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve
UNC5792 and UNC4221 have been targeting US government officials, military leaders, and allied personnel.
Part of the PlainSec briefing for 2026-06-30