Threats · 77 days ago
A stolen Backup Recovery Key is harder to unwind than a stolen login. Once an attacker gets that key, they can come back even after the victim makes a fresh account with the same phone number, so one successful phish can turn into long-lived access to past and future chats.
CISA and the FBI say UNC5792 and UNC4221 have shifted from stealing verification codes and account PINs to asking for Backup Recovery Keys in Signal and WhatsApp campaigns aimed at government, defense, media, and allied users. The agencies also say the actors can use compromised accounts to reach other victims through trusted chats, and that the U.S. is offering up to $10 million for information on the groups linked to Russian intelligence.
The practical break is persistence: resetting the account does not necessarily remove the attacker if the old recovery key still works or if a backup of the original account was already taken. That makes the key itself a standing credential, not support information.
4 sources covering this story
US offers $10 million for info on group behind Signal and WhatsApp hacking spree
Operation by two Russia-state groups has been ongoing since at least March.
The Record from Recorded Future
US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp
Russia-linked hacking groups tracked as UNC5792 and UNC4221 have socially engineered their way into the messaging accounts of government officials.
U.S. offers $10 million for hackers targeting WhatsApp, Signal users
Department of State is offering up to $10 million for information that helps identify or locate members of the UNC5792 and UNC4221 hacker groups, which are linked to Russia's intelligence and military services.
US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve
UNC5792 and UNC4221 have been targeting US government officials, military leaders, and allied personnel.
Part of the PlainSec briefing for 2026-06-30