Save 20% on your first hosting bill — use code HOSTING20 Claim now →
Live Bulletproof domains & hosting · Pay with crypto or card Bulletproof domains & hosting
FBI: Russian Hackers Now Target Signal Backup Recovery Keys
FBI: Russian Hackers Now Target Signal Backup Recovery Keys — Security guide on LaunchPad Host

FBI: Russian Hackers Now Target Signal Backup Recovery Keys

LH
By LaunchPad Host Team · Hosting & Infrastructure
Published · 6 min read

Key Takeaways

  • The FBI and CISA say Russian intelligence groups are phishing Signal users to steal their Backup Recovery Key, which unlocks full message history.
  • Legitimate Signal support never asks for verification codes inside the app or sends links to 'restore' your account.
  • If your key may be exposed, generate a new Backup Recovery Key in Signal settings — a new account on the same number does not invalidate a stolen key.
  • The same recovery-key theft pattern hits hosting panels, domain registrars, and email — protect those secrets with the same discipline.
  • Defense in depth (phishing-resistant 2FA, offline backup codes, separate recovery email) limits damage when one credential leaks.

What is the FBI warning about Signal backup recovery keys?

The FBI and CISA warn that Russian intelligence hackers are running phishing campaigns to steal Signal users' Backup Recovery Key — the secret that restores an account's encrypted backup. Hand it over once and an attacker can read your full private and group message history and take over the account. The encryption itself is not broken; the human is tricked.

This is an update to a March 2026 advisory. Back then the same Russia-linked groups were hijacking Signal accounts by abusing the app's linked-devices feature. The tactics have evolved: now they go after the recovery key directly, which gives them historical messages rather than just future ones. The threat actors are tracked as UNC5792 and UNC4221 and tied to multiple Russian Intelligence Services, including FSB officers embedded with the FSB Border Guards.

The targets are people of high intelligence value — current and former government officials, military personnel, political figures, journalists, and key officials in Ukraine. But the technique is generic, cheap, and copied fast. Anyone who runs a website, manages client data, or holds accounts worth taking should understand exactly how it works, because the same playbook is already pointed at hosting panels and domain registrars.

How the Signal recovery key phishing attack works

The attack never touches Signal's cryptography. It targets the one secret that sits outside it. Here is the chain the FBI describes.

  1. The bait. A message arrives that looks like it is from 'Signal support'. It claims Signal is rolling out mandatory two-factor verification after an alleged wave of attacks, and that you must act to keep your account.
  2. The urgency. The message manufactures pressure — your account will be locked, you must verify now, follow this link. Urgency short-circuits the part of your brain that checks details.
  3. The ask. The attacker requests your Backup Recovery Key, or walks you through 'verifying' in a way that hands it over. Some variants phish the in-app verification code instead.
  4. The takeover. With the key, the attacker restores your backup on their own device, reads everything, and controls the account.

The cruel part is the persistence. According to the advisory, creating a new Signal account with the same phone number does not invalidate a stolen key. And generating a new key won't claw back any backup the attacker already downloaded. The damage from a single leaked secret outlives the moment you realize you were phished — which is exactly why this pattern is so dangerous when applied to infrastructure accounts.

The one rule that defeats it

Real Signal support communicates only through official company email addresses. It never requests verification codes inside the app and never sends links asking you to verify or restore your account. Any message that does either of those things is hostile, full stop. That single heuristic neutralizes the entire campaign.

Tired of slow, overcrowded web hosting?

LaunchPad Host runs on NVMe SSDs + LiteSpeed with free migration, free SSL, daily backups, and crypto payments. 30-day money-back guarantee.

See Hosting Plans

What to do if your Signal recovery key may be stolen

If you suspect you handed over your key — or just want to be safe — move fast and in this order:

That last point about exposed history is the bridge to the real lesson. Most people store more than chit-chat in their messages: a server root password sent 'just this once', a registrar login, a recovery email address. When a message archive leaks, every secret inside it leaks too.

Why this matters for your website, hosting, and domain accounts

Strip away the Signal branding and this is a recovery-credential attack: trick the human into surrendering the one secret that bypasses every other protection. That pattern is not specific to messaging apps. It is the most common way websites, hosting accounts, and domains get stolen.

Think about every 'break glass' secret you hold. Your hosting control panel has a password reset and often backup codes. Your domain registrar holds the keys to your entire web presence — lose that and an attacker can point your site and email wherever they like. Your two-factor app has recovery codes. Each of these is a Backup Recovery Key by another name, and each is phishable in exactly the way the FBI describes.

Recovery secretWhat it unlocksHow to protect it
Signal Backup Recovery KeyFull encrypted message historyNever share; enable PIN + Registration Lock; rotate if exposed
2FA backup codesBypass of your second factorStore offline (paper or password manager), never paste into chat
Hosting panel login + reset emailFiles, databases, site backupsUnique password, phishing-resistant 2FA, locked-down recovery email
Domain registrar accountDNS, the whole domain, email routingRegistrar lock, 2FA, separate email not tied to the domain
SSH / API keysDirect server and service accessKey files only, passphrase-protected, rotate on any suspicion

The hosting angle most providers stay quiet about: your recovery email is the master key to everything. If your registrar and host both reset to an inbox hosted on the same domain you are trying to protect, one breach cascades into all of them. Keep recovery contacts on an independent, well-secured account. This is also where a privacy-forward host helps — at LaunchPad Host we keep account recovery off public WHOIS, support strong authentication, and never ask for your password or codes over chat or email, so a 'support' message that does is an instant red flag you can trust.

Building a recovery-key defense that actually holds

The goal is not to never get phished — skilled attackers are convincing. The goal is that when one secret leaks, it does not unlock everything else. That is defense in depth, and it is built from a few unglamorous habits.

Before you act on any 'urgent security' message, stop and ask one question: does the real company actually contact people this way? Legitimate support does not DM you for codes or recovery keys. If the channel is wrong, the message is an attack — no matter how official it looks.

Practical steps that scale from Signal to your servers

None of this is exotic. It is the same discipline the FBI is urging on Signal users, applied to the accounts that actually run your business online. The attackers reuse one technique against many targets; you defend with one set of habits across all of them.

Frequently Asked Questions

No. Signal's end-to-end encryption is intact. The attack is social engineering — it tricks users into handing over their Backup Recovery Key or in-app verification codes, which lets attackers restore the backup and take over the account without ever defeating the cryptography.

Legitimate Signal support only communicates through official company email addresses. It never requests verification codes inside the app and never sends links asking you to verify or restore your account. Any message that does either is a phishing attempt, regardless of how convincing it looks.

No. Creating a new account on the same phone number does not invalidate a stolen key. You must generate a new Backup Recovery Key in Signal's backup settings, which blocks future backup downloads. It cannot undo access to a backup the attacker already downloaded, so rotate any secrets that were in your message history.

It is the same pattern: phish the human for the one recovery secret that bypasses every other protection. Hosting panels, domain registrars, and recovery emails all have equivalents of a Backup Recovery Key. Protect them with phishing-resistant 2FA, offline backup codes, a separate recovery email, and a host that never asks for your credentials over chat or email.

Tags: signal security phishing account takeover backup recovery key two-factor authentication privacy russian hackers

Related tools, articles & authoritative sources

Hand-picked internal pages and external references from sources Google itself considers authoritative on this topic.

Related free tools

Offshore & privacy hosting