Russian hackers target Signal in FBI-warned phishing campaign

Craig Nash
By
Craig Nash
Tech writer at All Things Geek. Covers artificial intelligence, semiconductors, and computing hardware.
10 Min Read
Russian hackers target Signal in FBI-warned phishing campaign

The Signal phishing campaign launched by Russian Intelligence Services (RIS) actors represents one of the most brazen state-sponsored attacks on encrypted messaging in recent memory. On Friday, March 21, 2026, the FBI and CISA issued a joint public service announcement confirming that Russian operatives have already compromised thousands of individual accounts across Signal and other commercial messaging apps. The attack does not exploit encryption flaws—it exploits human behavior, making it devastatingly effective against even security-conscious users.

Key Takeaways

  • Russian Intelligence Services have compromised thousands of Signal accounts through social engineering, not technical exploits.
  • Targets include current and former US government officials, military personnel, political figures, and journalists.
  • Attackers impersonate trusted contacts or fake “Signal Support Bot” to steal login credentials or verification codes.
  • The attack enables full account takeover, message access, contact list theft, and secondary phishing campaigns.
  • Signal’s encryption remains unbroken; phishing bypasses it entirely by compromising accounts at the authentication layer.

How the Signal Phishing Campaign Works

The Signal phishing campaign employs two primary attack vectors, both relying on deception rather than technical vulnerability. In the first method, attackers abuse Signal’s linked device feature—a legitimate function that lets users access their account from multiple devices. Attackers impersonate a trusted contact or pose as a “Signal Security Support ChatBot,” sending a malicious link or QR code. When victims interact with it, the attacker’s device becomes linked to the victim’s account, granting persistent access without triggering account lockout. The victim remains unaware the compromise has occurred.

The second vector is direct account takeover. Attackers, posing as automated support services, pressure victims to provide their PIN, SMS verification code, or click a malicious link. A sample phishing message circulating in the campaign reads: “Dear user, this is a Signal Security Support ChatBot. We have noticed suspicious activity in your device, which could have led to data leak. To prevent this, you have to pass verification procedure, entering the verification code to Signal Security Support ChatBot. DON’T TELL ANYONE THE CODE, NOT EVEN SIGNAL EMPLOYEES.” This psychological manipulation—creating urgency around fake security threats—is remarkably effective. Once credentials are obtained, attackers gain complete control of the account.

What makes this campaign particularly dangerous is what happens after compromise. According to the FBI and CISA, “After compromising an account, malicious actors can view the victims’ messages and contact lists, send messages, and conduct additional phishing against other CMA accounts”. A single compromised account becomes a springboard for lateral attacks against the victim’s entire network of contacts.

Why Encryption Cannot Stop This Attack

Signal’s end-to-end encryption is mathematically sound and remains unbroken. Yet the Signal phishing campaign renders encryption irrelevant. The FBI and CISA emphasized this critical point: “Phishing remains one of the most unsophisticated, yet effective means of cyber compromise, often rendering other protections irrelevant, including end-to-end encryption”. Encryption protects messages in transit—it does nothing to protect credentials at the moment of authentication.

This distinction matters enormously. A user who believes their Signal account is secure because of encryption may be far less cautious when receiving what appears to be a support request. They may click a link or share a code without the paranoia they would apply to a banking website. The attacker does not need to break encryption; they simply need the user to voluntarily hand over the keys. Signal acknowledged this in a statement on X: “These attacks, like all phishing, rely on social engineering. Attackers impersonate trusted contacts or services (such as the non-existent ‘Signal Support Bot’) to trick victims into handing over their login credentials or other information”.

Who Is Being Targeted and Why

The Signal phishing campaign is not indiscriminate. Russian intelligence actors are specifically targeting individuals of what the FBI describes as “high intelligence value”: current and former US government officials, military personnel, political figures, and journalists. These are precisely the people whose communications would be most valuable to a foreign intelligence service. Compromising their Signal accounts provides access to sensitive conversations, sources, and operational details.

The campaign is global in scope but has a specific US focus. However, it follows earlier warnings from Germany (February 2026) and the Netherlands (the week prior to the US alert), suggesting Russian actors have been testing and refining these tactics across multiple regions before scaling up. FBI Director Kash Patel publicly highlighted the threat, noting the vulnerability in user responses to phishing despite widespread awareness of the tactic.

How This Differs From Previous Threats

The Signal phishing campaign is not the first time Russian actors have targeted encrypted messaging apps. Google Threat Intelligence documented similar attempts against Signal users in Ukraine last year, and the Dutch and German governments previously warned of WhatsApp and Signal account takeovers. What distinguishes this current campaign is its scale—thousands of accounts compromised—and its focus on high-value US targets. It also contrasts sharply with spyware-based attacks, such as the malware threats CISA warned about in November. Phishing is lower-tech but, paradoxically, far more effective because it exploits human psychology rather than software flaws.

What Users Should Do Right Now

The FBI and CISA have issued concrete protection steps. Never share your SMS code or verification PIN with anyone, even if they claim to be Signal support. Exercise extreme caution with unexpected messages from unknown contacts, and always verify requests through a separate communication channel—call a colleague directly rather than replying to a message. Before clicking any link, hover over it or examine it closely; phishing links often contain subtle misspellings of legitimate domains.

Periodically review your linked devices in Signal’s settings and remove any you do not recognize. If you see a device linked to your account that you did not authorize, that is a sign of compromise. Scrutinize unexpected messages carefully—real Signal support will not ask for your PIN or verification code. Review your account settings, enable available security features, and report suspicious activity to Signal. For government officials and journalists, the stakes are higher; consider whether a burner device or additional authentication steps are warranted.

Will Signal Fix This?

Signal cannot patch human behavior. The company could theoretically add additional friction to the linked device feature or implement stronger verification requirements, but such changes would frustrate legitimate users. The real solution lies in user awareness—understanding that any message requesting credentials or verification codes, no matter how official it appears, should trigger skepticism. Signal has already made its position clear: the vulnerability is not in the app’s code but in how users respond to social engineering.

Why is the Signal phishing campaign happening now?

Russian intelligence services are conducting this campaign as part of broader espionage operations targeting US government and military leadership. The timing coincides with geopolitical tensions and the high intelligence value of US officials’ communications. Phishing is cost-effective and highly successful against even security-aware targets.

Can Signal’s encryption be broken to read compromised messages?

No. Even if an attacker gains full account access through phishing, they cannot retroactively decrypt messages encrypted with Signal’s protocol. However, they can read new messages sent to the compromised account going forward, making account recovery urgent.

Should I stop using Signal?

Signal remains one of the most secure messaging apps available. The vulnerability here is not Signal’s encryption or design—it is the universal human susceptibility to social engineering. Switching to another app solves nothing if you fall for the same phishing tactics. The smarter move is to stay on Signal, use it correctly, and remain vigilant against any message requesting credentials or verification codes, regardless of the sender’s claimed identity.

Edited by the All Things Geek team.

Source: TechRadar

Share This Article
Tech writer at All Things Geek. Covers artificial intelligence, semiconductors, and computing hardware.