The FBI warns that Russian intelligence actors are using a phishing scheme to compromise Signal accounts. According to reporting from multiple outlets, the approach targets users by abusing Signal’s support-related services and persuades victims to provide their Signal “backup recovery keys” (also described as backup keys). The FBI says the goal is to hijack Signal accounts by obtaining these recovery keys, which can be used to restore or access accounts tied to Signal’s backup and restore features.

The reports also indicate that the phishing campaign is directed toward high-value targets, including VIPs as well as government and military personnel. While the specific lure and delivery method can vary, the common thread is the social-engineering tactic: victims are tricked into sending or revealing recovery keys during the interaction.

In response to the warning, coverage emphasizes the importance of protecting Signal backup recovery keys and being cautious with messages or instructions that request sensitive account recovery information. The FBI’s alert focuses on preventing account takeover by keeping recovery keys from being shared with anyone.