{"id":11512,"date":"2026-03-21T10:03:50","date_gmt":"2026-03-21T10:03:50","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/21\/fbi-cisa-warn-russian-hackers-are-targeting-high-value-individuals-through-signal\/"},"modified":"2026-03-21T10:03:50","modified_gmt":"2026-03-21T10:03:50","slug":"fbi-cisa-warn-russian-hackers-are-targeting-high-value-individuals-through-signal","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/21\/fbi-cisa-warn-russian-hackers-are-targeting-high-value-individuals-through-signal\/","title":{"rendered":"FBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal"},"content":{"rendered":"<p>    FBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have recently released a joint cybersecurity advisory regarding a <a href=\"https:\/\/cybersecuritynews.com\/sharepoint-services-in-sophisticated-aitm-phishing-campaign\/\" type=\"post\" id=\"140573\" target=\"_blank\" rel=\"noreferrer noopener\">widespread phishing campaign<\/a>. <\/p>\n<p>The alert warns that Russian Intelligence Services are actively targeting users of encrypted messaging applications, primarily Signal. <\/p>\n<p>The attackers are bypassing the platform\u2019s robust end-to-end encryption by hijacking user accounts rather than compromising the underlying cryptographic protocols.<\/p>\n<h2 class=\"wp-block-heading\" id=\"target-demographics\"><strong>FBI, CISA Warn Russian Hackers <\/strong><\/h2>\n<p>This cyber espionage campaign is meticulously designed to compromise individuals who possess high intelligence value. <\/p>\n<p>The threat actors are specifically targeting current and former United States government officials, military personnel, influential political figures, and prominent journalists. <\/p>\n<p><a href=\"https:\/\/www.ic3.gov\/PSA\/2026\/PSA260320\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to the intelligence agencies<\/a>, the operation has already resulted in the unauthorised access of thousands of accounts on a global scale.<\/p>\n<p>Because Signal\u2019s core encryption remains secure, hackers rely entirely on deceptive social engineering techniques to trick victims into surrendering control of their profiles. <\/p>\n<p>The attackers initiate contact by sending in-app messages that impersonate official automated support channels. These fraudulent profiles often use authoritative names such as \u201cSignal Security Support ChatBot\u201d or \u201cSignal Security Team\u201d to appear legitimate.<\/p>\n<p>To manipulate the victims, the messages artificially manufacture a sense of urgency. They falsely claim that the user\u2019s account has <a href=\"https:\/\/cybersecuritynews.com\/volkswagen-data-breach\/\" type=\"post\" id=\"87275\" target=\"_blank\" rel=\"noreferrer noopener\">experienced a data leak<\/a>, or that suspicious login attempts were detected from foreign locations and unrecognized devices. <\/p>\n<p>The messages then instruct the target to complete a mandatory verification procedure to secure their account by handing over their SMS verification code or scanning a malicious QR code.<\/p>\n<p>When a victim inadvertently shares their verification code, the attackers exploit the application\u2019s linked device feature. This allows the hackers to tether their own hardware to the compromised account without raising immediate alarms. <\/p>\n<p>Once inside, the threat actors gain the ability to silently monitor private conversations, read historical messages, and infiltrate private group chats. <\/p>\n<p>Furthermore, they can harvest contact lists and impersonate the victim to launch secondary phishing campaigns against trusted colleagues.<\/p>\n<h2 class=\"wp-block-heading\" id=\"recommended-mitigations\"><strong>Recommended Mitigations<\/strong><\/h2>\n<p>To defend against these<a href=\"https:\/\/cybersecuritynews.com\/best-account-takeover-protection-tools\/\" type=\"post\" id=\"127359\" target=\"_blank\" rel=\"noreferrer noopener\"> sophisticated account takeover <\/a>attempts, the FBI and CISA urge users to implement strict security hygiene and vigilance.<\/p>\n<ul class=\"wp-block-list\">\n<li>Protect your accounts by never sharing verification codes or personal PINs with anyone, since legitimate support staff will never request authentication codes through direct messages.<\/li>\n<li>Treat unexpected security alerts with extreme caution, and never scan unsolicited QR codes or click unverified links sent by unknown contacts.<\/li>\n<li>Frequently audit the linked devices menu within the application settings to immediately spot and disconnect any unauthorized hardware.<a href=\"https:\/\/aristeguinoticias.com\/2003\/mundo\/fbi-alerta-por-vulneracion-de-cuentas-de-signal-de-politicos-militares-y-periodistas\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\n<\/li>\n<li>Turn on the disappearing messages feature to automatically purge highly sensitive conversations after a specified time limit, minimizing the data available if an account is compromised.<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/fbi-cisa-warn-russian-hackers\/\">FBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/fbi-cisa-warn-russian-hackers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>FBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have recently released a joint cybersecurity advisory regarding a widespread phishing campaign. The alert warns that Russian Intelligence Services are actively targeting users of encrypted messaging applications, primarily Signal. The [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-11512","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11512"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11512"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11512\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}