Signal Phishing Now Steals the Restore Key

The campaign has moved past one-time codes and PINs. The key target is now Signal’s Backup Recovery Key, which can restore old messages and keep working even after the user rebuilds the account with the same phone number, so a reset can leave the attacker’s access intact. The FBI says RIS actors, including FSB-linked clusters, are using updated phishing messages that pose as support accounts to elicit the recovery key. The warning covers high-risk users such as government officials, military personnel, political figures, journalists, and Ukrainian officials, and says a captured key can expose historical, private, and group messages as well as future restores. The fix is to generate a new backup recovery key in Signal’s settings, but that only invalidates the old key for future downloads. If the backup was already taken, the data may already be out of the user’s control, and the persistence window remains open.

Part of the PlainSec briefing for 2026-06-29

Sources