{"id":13287,"date":"2026-06-01T10:03:47","date_gmt":"2026-06-01T10:03:47","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/01\/hackers-attacking-signal-users-to-steal-backups-in-new-wave-of-attacks\/"},"modified":"2026-06-01T10:03:47","modified_gmt":"2026-06-01T10:03:47","slug":"hackers-attacking-signal-users-to-steal-backups-in-new-wave-of-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/01\/hackers-attacking-signal-users-to-steal-backups-in-new-wave-of-attacks\/","title":{"rendered":"Hackers Attacking Signal Users to Steal Backups in New Wave of Attacks"},"content":{"rendered":"<p>    Hackers Attacking Signal Users to Steal Backups in New Wave of Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">A new wave of phishing attacks is targeting users of Signal, the encrypted messaging app trusted by journalists, activists, and privacy-conscious individuals worldwide. <\/p>\n<p class=\"wp-block-paragraph\">Hackers are impersonating Signal\u2019s support team and tricking users into handing over their backup recovery keys, which can unlock entire archives of private chat history. <a href=\"https:\/\/cybersecuritynews.com\/phishing-campaign-exploits-google-cloud\/\" id=\"144219\" target=\"_blank\" rel=\"noreferrer noopener\">The campaign has raised serious concern among cybersecurity researchers<\/a> and digital rights organizations.<\/p>\n<p class=\"wp-block-paragraph\">The attack begins with a text message sent directly inside Signal. The message claims to be from \u201cSignal Support\u201d and warns the recipient that their chats and media are \u201cat risk of permanent loss due to a sync issue\u201d. <\/p>\n<p class=\"wp-block-paragraph\">Victims are then told to share their 64-character recovery key to fix the problem. That key, once handed over, can give attackers full access to years of stored messages, photos, and documents.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/techcrunch.com\/2026\/05\/28\/hackers-are-trying-to-steal-signal-users-backups-in-new-wave-of-phishing-attacks\/\" id=\"https:\/\/techcrunch.com\/2026\/05\/28\/hackers-are-trying-to-steal-signal-users-backups-in-new-wave-of-phishing-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">TechCrunch\u00a0said in a report<\/a> shared with Cyber Security News (CSN) that the campaign was first <a href=\"https:\/\/x.com\/joshrogin\/status\/2059634806648930614\" id=\"https:\/\/x.com\/joshrogin\/status\/2059634806648930614\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">publicly flagged after Josh Rogin<\/a>, a Washington Post analyst, posted a screenshot of the fake message on May 27, 2026. <\/p>\n<p class=\"wp-block-paragraph\">Rogin warned his followers to ignore the message and noted that many anti-CCP activists had already received the same phishing attempt.<\/p>\n<figure class=\"wp-block-embed aligncenter is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-x\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">This is a phishing attempt. If you get this message on Signal, do not follow the instructions. Many anti-CCP activists have also received this phishing attempt. Beware and be aware. <a href=\"https:\/\/t.co\/8J1YDcpUAX\">pic.twitter.com\/8J1YDcpUAX<\/a><\/p>\n<p>\u2014 Josh Rogin (@joshrogin) <a href=\"https:\/\/x.com\/joshrogin\/status\/2059634806648930614?ref_src=twsrc%5Etfw\">May 27, 2026<\/a>\n<\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.x.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<\/div>\n<\/figure>\n<p class=\"wp-block-paragraph\">Access Now\u2019s Digital Security Helpline confirmed that journalists, dissidents, and activists are being targeted most heavily. <\/p>\n<p class=\"wp-block-paragraph\">Two separate victims submitted near-identical versions of the phishing message to investigators, confirming this is a coordinated operation rather than a random or opportunistic one.<a href=\"https:\/\/aiweekly.co\/alerts\/signal-backup-keys-stolen-in-coordinated-phishing-wave\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">What makes this campaign especially dangerous is what the recovery key unlocks. Signal\u2019s Secure Backups feature stores encrypted data on Signal\u2019s servers, protected by a key that never leaves the user\u2019s device. <\/p>\n<p class=\"wp-block-paragraph\">If an attacker gets that key and gains access to the account, they can download and decrypt the full message history, not just future conversations but everything stored in the backup.<\/p>\n<h2 id=\"h-hackers-attacking-signal-users\" class=\"wp-block-heading\"><strong>Hackers Attacking Signal Users<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/cybersecuritynews.com\/phishing-email-filter-breakthroughs\/\" id=\"76873\" target=\"_blank\" rel=\"noreferrer noopener\">phishing message is crafted to look completely believable<\/a>. It arrives inside Signal from an account calling itself \u201cSignal Support,\u201d giving it a false sense of legitimacy. <\/p>\n<p class=\"wp-block-paragraph\">The tone is urgent: act now or lose your data. Most users do not expect a scam to reach them through an app they consider private and secure.<\/p>\n<p class=\"wp-block-paragraph\">Security researchers at Malwarebytes noted that once the victim pastes the recovery key into the chat, the attacker still needs one more step to complete the takeover. <\/p>\n<p class=\"wp-block-paragraph\">They must gain access to the Signal account before using the key to download and decrypt the backup. However, that step does not make the threat any less serious, as stealing the key is a critical first move in a chain that can lead to total account compromise.<\/p>\n<p class=\"wp-block-paragraph\">The fact that victims across different networks received nearly identical messages points to a well-organized group. Researchers say the operation appears targeted rather than broad, with activists and journalists being singled out with clear purpose.<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/aiweekly.co\/alerts\/signal-backup-keys-stolen-in-coordinated-phishing-wave\"><\/a><\/p>\n<h2 id=\"h-protecting-your-signal-account-from-phishing\" class=\"wp-block-heading\"><strong>Protecting Your Signal Account from Phishing<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Signal has made it very clear that it will never reach out to users first. The app also does not ask for registration codes, PINs, or recovery keys under any circumstances. That means any message claiming to be from Signal Support and requesting this kind of information is a scam.<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/mezha.net\/eng\/bukvy\/a1aa92eb_hackers_target_signal\/\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">Users should treat any unsolicited message warning of account issues as suspicious, regardless of where it arrives. Clicking links in account-warning messages should be avoided entirely. <\/p>\n<p class=\"wp-block-paragraph\">Sharing verification codes, recovery keys, or authentication secrets with any contact, even a seemingly official one, should never happen.<\/p>\n<p class=\"wp-block-paragraph\">Experts <a href=\"https:\/\/cybersecuritynews.com\/signal-app-vulnerability\/\" id=\"271\" target=\"_blank\" rel=\"noreferrer noopener\">recommend enabling the Registration Lock feature in Signal<\/a>, which requires a PIN before your number can be registered on a new device. <\/p>\n<p class=\"wp-block-paragraph\">Turning on PIN protection and device-change alerts adds another layer of defense. Using disappearing messages can also help limit damage if an account is ever compromised.<\/p>\n<p class=\"wp-block-paragraph\">This campaign is a reminder that even the most secure tools can be exploited through human trust. Staying informed and skeptical about unexpected messages remains the first and most effective line of defense.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong> <strong><strong><a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a><\/strong><\/strong>.<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-attacking-signal-users\/\">Hackers Attacking Signal Users to Steal Backups in New Wave of Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-attacking-signal-users\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Attacking Signal Users to Steal Backups in New Wave of Attacks A new wave of phishing attacks is targeting users of Signal, the encrypted messaging app trusted by journalists, activists, and privacy-conscious individuals worldwide. Hackers are impersonating Signal\u2019s support team and tricking users into handing over their backup recovery keys, which can unlock entire [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-13287","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13287"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13287"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13287\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13287"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}