Recovery Keys Turn Chat Phishing into Persistent Access
A stolen Backup Recovery Key is harder to unwind than a stolen login. Once an attacker gets that key, they can come back even after the victim makes a fresh account with the same phone number, so one successful phish can turn into long-lived access to past and future chats.
CISA and the FBI say UNC5792 and UNC4221 have shifted from stealing verification codes and account PINs to asking for Backup Recovery Keys in Signal and WhatsApp campaigns aimed at government, defense, media, and allied users. The agencies also say the actors can use compromised accounts to reach other victims through trusted chats, and that the U.S. is offering up to $10 million for information on the groups linked to Russian intelligence.
The practical break is persistence: resetting the account does not necessarily remove the attacker if the old recovery key still works or if a backup of the original account was already taken. That makes the key itself a standing credential, not support information.