They Didn't Break Signal. They Broke the Person Holding the Phone.
By: Casey Cannady : nomad, cybersecurity veteran & Chapter 7 survivor
TL;DR
Last in this series, and the purest version of the pattern. I showed you the con dressed as politics, then dressed as AI tooling. Here it is with the costume off entirely. The State Department has put a $10 million bounty on two Russia-linked crews who spent months tricking Signal and WhatsApp users into handing over their backup recovery key, no exploit required, just a fake support agent and a sense of urgency. The encryption held. The humans didn't. And the stolen key keeps working even after you switch phones. That gap is the whole job I've worked for nearly 30 years, and it's not closing anytime soon.
Same con. New disguise. Same mark.
I showed you the con running as politics, a friendlier word bolted over the same concentration of power so nobody checks the access list. Then I showed you it running inside AI tooling, a borrowed star count and a clean scan standing in for trust until someone swapped the page. This is the one with nothing dressed up at all. No metaphor to unpack, no relabel to catch. Just a fake badge, a real target, and a nation-state on the other end.
Nearly 30 years in this industry and the headline never changes, only the dollar figure attached to it.
This time it's $10 million. In late June the FBI and CISA updated their advisory, and the State Department's Rewards for Justice program put up that bounty for information on UNC5792 and UNC4221, two hacking outfits tied to Russia's FSB Border Guards and military intelligence respectively. Their target list reads like a who's-who of people doing dangerous, necessary work: U.S. and NATO officials, diplomats, journalists covering the Russia-Ukraine war, NGOs supporting Ukraine, researchers who study this stuff for a living.
Their method is the part that should actually worry you, because it has nothing to do with breaking math.
The Trick, Stripped Down
Signal and WhatsApp encryption is fine. Nobody cracked it. What these groups did instead was simpler and uglier: they messaged people pretending to be Signal support, claimed a “mandatory two-factor verification” was required, and walked the target through handing over their backup recovery key.
That key is the master copy of someone's entire message history. Here's the detail that makes it worse than a normal account takeover: Signal's Secure Backups are zero-knowledge, so the 64-character key is generated on your device, never shared with Signal's servers, and Signal itself cannot recover, reset, or bypass it. That's a good design decision that becomes the single point of failure the moment someone talks you out of the key. Hand it over, and a stranger in another country can read every conversation you've ever had on the platform. Worse, the stolen key keeps working even if you switch phones, and even if you spin up a brand-new account on the same phone number. No malware. No zero-day. Just a well-written message and a target who trusted the badge.
Thousands of accounts went this way. The advisory is unusually blunt about why. Quoting it directly: “RIS cyber threat actors have compromised individual CMA accounts, but not the CMA's encryption or the application itself.” Not because the technology failed, but because the technology was never the weak point to begin with.
The Part Nobody Wants to Hear
I've spent my career on the defensive side of this exact problem. Endpoint hardening, vulnerability management, security awareness programs, the whole stack. And the uncomfortable truth I keep relearning is that you can build a fortress and someone will still hold the door open for a stranger in a uniform, because the uniform looked right and the moment felt official.
There's a bitter irony the advisory dances around: Signal's reputation for being unbreakable is now part of the attack surface. People scrutinize a fake in-app “support” message less, not more, precisely because the app feels safe. The trust the encryption earned is the exact thing being borrowed to get around it. That is the same move from my last two posts, run against the one product whose whole brand is that it can't be moved.
Real support teams do not DM you. They do not ask for verification codes inside the app. They do not create urgency around a “mandatory” step that conveniently requires you to hand over the one thing that unlocks everything. If a message asks you to prove who you are by giving up the keys to your own house, that's not verification. That's the heist.
This isn't a Signal problem or a WhatsApp problem. It's the oldest attack in the book wearing a new uniform, and it works because it's aimed at the one system every piece of software has to trust by design: the person using it.
Why the Target List Should Bother You More Than the Method
Diplomats and military leadership have institutional security teams. Journalists covering Russia and Ukraine, NGOs supporting Ukraine, independent researchers tracking this stuff? Most of them don't. They're running on a personal phone and whatever vigilance they can muster between everything else they're doing.
A state actor with a $10 million bounty on its own head isn't spending that effort on random people. It's spending it on people whose communications are inconvenient to a government. Reporters. Aid workers. Researchers asking the wrong questions. That's not abstract cybersecurity news, that's a government using a phishing template to go after the people documenting what it's doing.
I've made a career out of protecting infrastructure. This is infrastructure too, just the human kind, and it's getting the same treatment as everything else worth attacking: probed, mapped, and exploited at scale.
What Actually Protects You
Three things, none of them complicated:
- Treat your backup recovery key like a house key you never hand to anyone, ever, under any circumstance, including anyone claiming to be support. No legitimate support process needs it from you in a chat window. And know the difference between your key and your Signal PIN, because the attackers are counting on you not knowing. Signal says it plainly: the PIN is “different from the recovery key used to restore a Secure Backup.” A PIN protects your profile and contacts if you switch phones. It does not protect your backup, and setting one does nothing to stop the attack in this post. Set one anyway, alongside a registration lock. Just don't mistake it for armor it isn't.
- Support does not initiate contact. Any unsolicited message claiming to be Signal, WhatsApp, or platform support asking you to “verify” anything is the attack, not the fix.
- Urgency is the tell. Real account security processes do not require you to act in the next ten minutes. If a message is built to make you rush, that's the design, not an accident. And if you think you already handed over a recovery key, generate a new one now and assume any backup made before that is already in someone else's hands.
The fortress was never going to be the thing that failed here. Politics, AI tooling, or a Russian intelligence op, the shape is identical every time: the lock holds, and someone talks the keyholder into opening it. You were always the perimeter. Act like it.
Sources & Further Reading
- FBI / IC3 & CISA: Russian Intelligence Services Continue to Target Commercial Messaging Applications (June 2026 update). The primary advisory, including the recovery-key tactic and sample phishing messages. Read the samples. They are better written than you expect.
- FBI / IC3: the original March 2026 PSA that June's update builds on. This is where the “thousands of individual CMA accounts” figure comes from. CISA mirrors both advisories on its own site if you prefer that source.
- U.S. Department of State, Rewards for Justice: the $10 million reward notice for UNC5792, which also covers UNC4221.
- Signal: Introducing Signal Secure Backups, the source for how the 64-character recovery key works and why Signal cannot recover it for you. Also: how to set a Signal PIN.
- BleepingComputer: US offers $10 million for hackers targeting WhatsApp, Signal users, and The Record for independent coverage of the bounty and the device-linking abuse that preceded the recovery-key push.
Sourcing note: everything load-bearing here comes from the FBI, CISA, the State Department, or Signal's own documentation. I have not embellished the numbers. I did not need to.
Connect with Casey
If this resonated, or if there's a topic you want me to take on next, reach out. I read everything.
| Websites | |
| @cmcannady | |
| facebook.com/cmcannady | |
| Threads | @cmcannady |
| Bluesky | @cmcannady.bsky.social |
| linkedin.com/in/caseycannady | |
| X / Twitter | @casey_cannady |
| YouTube | @CaseyCannady |
Casey writes about economic policy, nomadic life, cybersecurity, and navigating the world as a late-diagnosed AuDHD adult. New posts drop on my professional website.