Signal has introduced additional in-app confirmations and safety warnings after authorities warned of phishing campaigns that targeted the app’s linked-devices feature. Attackers posed as trusted contacts or support, requesting QR scans or verification codes to link devices and read messages; Signal now prompts users twice before linking, warns it will never request codes or PINs, and added expanded safety tips.
Part of the PlainSec briefing for 2026-05-13