Interestana
Home/News/FBI Warns Russian Hackers Target Signal Backup Recovery Keys
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

FBI Warns Russian Hackers Target Signal Backup Recovery Keys

The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have updated their March advisory concerning Russian intelligence operations targeting Signal users. The latest warning, issued this week, details an escalated phishing tactic where attackers are now actively soliciting Signal Backup Recovery Keys from their targets. Previously, the focus was on phishing Signal accounts directly.

This new method involves tricking users into revealing their unique 30-character backup recovery key. Once obtained, this key allows the attacker to restore the compromised Signal account's message backup. This restoration grants the attacker access to the entire private and group message history associated with the account. Furthermore, the attacker can then take over the account, effectively hijacking the user's communication channel. The FBI and CISA emphasize that the compromised recovery key remains functional, enabling persistent access for the threat actor.

The initial advisory from March highlighted phishing campaigns aimed at compromising Signal accounts, but the addition of the backup recovery key theft represents a significant escalation in the sophistication and potential impact of these attacks. The FBI and CISA urge Signal users to be vigilant against unsolicited requests for their recovery keys and to review their security settings. The agencies did not specify which Russian intelligence groups are behind these operations, but the targeting of encrypted communication platforms suggests a focus on intelligence gathering and disruption.

Signal, known for its end-to-end encryption, relies on these recovery keys to allow users to restore their message history on new devices or after reinstalling the app. The compromise of these keys bypasses the platform's core security features, making user data vulnerable. The agencies recommend users enable two-step verification and avoid sharing their recovery keys with anyone, even under duress. The ongoing nature of these threats underscores the importance of user awareness and adherence to security best practices when using encrypted messaging applications.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next