Russia’s security service, FSB, and Russian military-linked hacking groups have shifted from stealing one-time verification codes to stealing the recovery keys that unlock a victim's entire message history, and the theft works without breaking any encryption.

 

What happened

The US State Department's Rewards for Justice program is offering up to $10 million for information leading to the identification or location of members of UNC5792 and UNC4221, two Russian-linked hacking groups that have run sustained phishing campaigns against Signal and WhatsApp accounts. According to The Record, US authorities associate UNC5792 with Russia's Federal Security Service (FSB) Border Guards and UNC4221 with Russian military intelligence. The FBI confirmed in an updated advisory issued alongside the reward announcement that the group's primary goal has changed from stealing one-time verification codes to stealing Signal Backup Recovery Keys, the credential that decrypts a user's full message history. According to BleepingComputer, officials confirmed the campaign has already compromised thousands of individual messaging accounts and does not exploit any vulnerability in Signal or WhatsApp's encryption. The attacks rely entirely on tricking victims into voluntarily handing over their credentials.

 

Going deeper

The attackers abuse a legitimate feature in secure messaging apps called device linking, which allows a user to connect a new device, such as a second phone or a computer, to their existing account. Normally, this requires the user to scan a QR code or approve the connection directly. UNC5792 operators impersonate official Signal or WhatsApp support accounts, sending messages that walk victims through enabling backups and then ask them to share the resulting recovery key, claiming it is needed to verify their account or resolve a technical issue. In some documented cases, attackers modified legitimate Signal group invite pages so that clicking the invite link redirected victims to a page that linked an attacker-controlled device to their account instead. According to SecurityWeek, officials specifically warned that a stolen Backup Recovery Key remains valid even after a victim creates a new account using the same phone number, meaning the compromise can persist through what would normally be considered a clean account reset. Once inside an account, the attackers read private conversations and contact lists, then use the compromised account to send further phishing messages to the victim's contacts, extending the campaign through trusted relationships.

 

What was said

The Rewards for Justice program stated in its official announcement, "Using social engineering techniques, these malicious cyber actors exploit legitimate device-linking features in these secure messaging applications to gain unauthorized access to sensitive government communications, contact lists, and group conversations." US authorities specified that the campaign targets US government officials, diplomatic and foreign affairs personnel, defense and national security staff, NATO member-state officials, allied intelligence and defense partners, investigative journalists covering Russia and Ukraine, non-governmental organizations supporting Ukraine, and academic researchers focused on security studies and Russian affairs.

 

In the know

Ukraine's Security Service disclosed a related operation the week before the US reward announcement. According to The Record, Ukraine's SBU worked with the FBI to uncover a long-running Russian cyber-espionage campaign targeting government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States, using the same core technique of impersonating official messaging platform support to extract account credentials. The two-front disclosure, Ukrainian and American authorities publishing coordinated findings within days of each other, signals sustained intelligence-sharing between the two governments on this specific threat.

 

The big picture

While UNC5792 and UNC4221 currently target government, military, and journalism sectors specifically, the technique they use, impersonating trusted app support to extract backup credentials through social engineering rather than technical exploitation, is directly applicable to any organization relying on secure messaging apps for sensitive communications. Healthcare organizations that use Signal or WhatsApp for clinical coordination, incident response communications, or executive messaging face the same underlying vulnerability. A convincing fake support message asking a user to share a recovery key would succeed regardless of the victim's role or industry. According to Dark Reading's coverage of Verizon's 2026 Data Breach Investigations Report, social engineering returned as one of the top three breach patterns in healthcare this year, and pretexting, where an attacker builds a false but convincing backstory to gain a victim's trust, jumped to the second most common social engineering tactic used against the sector. Proofpoint threat researcher Sarah Sabotka noted that pretexting succeeds because it establishes legitimacy and builds trust rather than relying on urgency alone, the exact approach UNC5792 uses when impersonating official Signal and WhatsApp support.

 

FAQs

What is a Signal Backup Recovery Key, and why is stealing it more damaging than stealing a verification code?

A Backup Recovery Key decrypts a user's full message history stored in an encrypted backup. A stolen verification code typically only grants access to the account going forward from that point. A stolen recovery key can expose years of past conversations at once and, according to officials, can remain valid even after the victim resets their account using the same phone number.

 

How does device linking work, and why does it not require breaking encryption?

Device linking lets a user connect a second device to receive and send messages from the same account, a legitimate feature built into apps like Signal and WhatsApp. Attackers do not break the encryption protecting messages. Instead, they trick the victim into approving a device link or handing over the recovery key directly, gaining access the same way a legitimate second device would.

 

Why would attackers modify legitimate Signal group invite pages?

A modified group invite page that redirects to a malicious device-linking flow exploits the trust users place in an invitation coming from a group they recognize or expect to join. Because the initial link appears to come from a legitimate source, victims are less likely to scrutinize the destination before approving the device connection.

 

What should organizations using Signal or WhatsApp for sensitive communications do to reduce this risk?

Staff should be trained that official support teams for these platforms do not proactively message users asking for verification codes, PINs, or recovery keys, and any such request should be treated as fraudulent, regardless of how official it appears. Organizations should also enable two-factor authentication using a separate authenticator app rather than SMS, and establish a clear internal verification process for any request to link a new device to a shared or organizational account.

 

How does the Rewards for Justice program work, and what happens if someone provides useful information?

Rewards for Justice is a US State Department program that offers financial rewards for information leading to the arrest or conviction of individuals involved in terrorism or, in cases like this one, state-directed malicious cyber activity against US critical infrastructure. Tips can be submitted through secure channels, including the program's website, and the identity of informants is protected as part of the program's standard operating procedure.