Back to Blog

They Didn't Break Signal. They Broke the Person Holding the Phone.

By: Casey Cannady : nomad, cybersecurity veteran & Chapter 7 survivor

July 27, 2026
6 min read
Casey Michael Cannady
CybersecuritySocial EngineeringPrivacy

TL;DR

Last in this series, and the purest version of the pattern. I showed you the con dressed as politics, then dressed as AI tooling. Here it is with the costume off entirely. The State Department has put a $10 million bounty on two Russia-linked crews who spent months tricking Signal and WhatsApp users into handing over their backup recovery key, no exploit required, just a fake support agent and a sense of urgency. The encryption held. The humans didn't. And the stolen key keeps working even after you switch phones. That gap is the whole job I've worked for nearly 30 years, and it's not closing anytime soon.

Same con. New disguise. Same mark.


I showed you the con running as politics, a friendlier word bolted over the same concentration of power so nobody checks the access list. Then I showed you it running inside AI tooling, a borrowed star count and a clean scan standing in for trust until someone swapped the page. This is the one with nothing dressed up at all. No metaphor to unpack, no relabel to catch. Just a fake badge, a real target, and a nation-state on the other end.

Nearly 30 years in this industry and the headline never changes, only the dollar figure attached to it.

This time it's $10 million. In late June the FBI and CISA updated their advisory, and the State Department's Rewards for Justice program put up that bounty for information on UNC5792 and UNC4221, two hacking outfits tied to Russia's FSB Border Guards and military intelligence respectively. Their target list reads like a who's-who of people doing dangerous, necessary work: U.S. and NATO officials, diplomats, journalists covering the Russia-Ukraine war, NGOs supporting Ukraine, researchers who study this stuff for a living.

Their method is the part that should actually worry you, because it has nothing to do with breaking math.


The Trick, Stripped Down

Signal and WhatsApp encryption is fine. Nobody cracked it. What these groups did instead was simpler and uglier: they messaged people pretending to be Signal support, claimed a “mandatory two-factor verification” was required, and walked the target through handing over their backup recovery key.

That key is the master copy of someone's entire message history. Here's the detail that makes it worse than a normal account takeover: Signal's Secure Backups are zero-knowledge, so the 64-character key is generated on your device, never shared with Signal's servers, and Signal itself cannot recover, reset, or bypass it. That's a good design decision that becomes the single point of failure the moment someone talks you out of the key. Hand it over, and a stranger in another country can read every conversation you've ever had on the platform. Worse, the stolen key keeps working even if you switch phones, and even if you spin up a brand-new account on the same phone number. No malware. No zero-day. Just a well-written message and a target who trusted the badge.

Thousands of accounts went this way. The advisory is unusually blunt about why. Quoting it directly: “RIS cyber threat actors have compromised individual CMA accounts, but not the CMA's encryption or the application itself.” Not because the technology failed, but because the technology was never the weak point to begin with.

The Part Nobody Wants to Hear

I've spent my career on the defensive side of this exact problem. Endpoint hardening, vulnerability management, security awareness programs, the whole stack. And the uncomfortable truth I keep relearning is that you can build a fortress and someone will still hold the door open for a stranger in a uniform, because the uniform looked right and the moment felt official.

There's a bitter irony the advisory dances around: Signal's reputation for being unbreakable is now part of the attack surface. People scrutinize a fake in-app “support” message less, not more, precisely because the app feels safe. The trust the encryption earned is the exact thing being borrowed to get around it. That is the same move from my last two posts, run against the one product whose whole brand is that it can't be moved.

Real support teams do not DM you. They do not ask for verification codes inside the app. They do not create urgency around a “mandatory” step that conveniently requires you to hand over the one thing that unlocks everything. If a message asks you to prove who you are by giving up the keys to your own house, that's not verification. That's the heist.

This isn't a Signal problem or a WhatsApp problem. It's the oldest attack in the book wearing a new uniform, and it works because it's aimed at the one system every piece of software has to trust by design: the person using it.

Why the Target List Should Bother You More Than the Method

Diplomats and military leadership have institutional security teams. Journalists covering Russia and Ukraine, NGOs supporting Ukraine, independent researchers tracking this stuff? Most of them don't. They're running on a personal phone and whatever vigilance they can muster between everything else they're doing.

A state actor with a $10 million bounty on its own head isn't spending that effort on random people. It's spending it on people whose communications are inconvenient to a government. Reporters. Aid workers. Researchers asking the wrong questions. That's not abstract cybersecurity news, that's a government using a phishing template to go after the people documenting what it's doing.

I've made a career out of protecting infrastructure. This is infrastructure too, just the human kind, and it's getting the same treatment as everything else worth attacking: probed, mapped, and exploited at scale.

What Actually Protects You

Three things, none of them complicated:

  • Treat your backup recovery key like a house key you never hand to anyone, ever, under any circumstance, including anyone claiming to be support. No legitimate support process needs it from you in a chat window. And know the difference between your key and your Signal PIN, because the attackers are counting on you not knowing. Signal says it plainly: the PIN is “different from the recovery key used to restore a Secure Backup.” A PIN protects your profile and contacts if you switch phones. It does not protect your backup, and setting one does nothing to stop the attack in this post. Set one anyway, alongside a registration lock. Just don't mistake it for armor it isn't.
  • Support does not initiate contact. Any unsolicited message claiming to be Signal, WhatsApp, or platform support asking you to “verify” anything is the attack, not the fix.
  • Urgency is the tell. Real account security processes do not require you to act in the next ten minutes. If a message is built to make you rush, that's the design, not an accident. And if you think you already handed over a recovery key, generate a new one now and assume any backup made before that is already in someone else's hands.

The fortress was never going to be the thing that failed here. Politics, AI tooling, or a Russian intelligence op, the shape is identical every time: the lock holds, and someone talks the keyholder into opening it. You were always the perimeter. Act like it.


Sources & Further Reading

Sourcing note: everything load-bearing here comes from the FBI, CISA, the State Department, or Signal's own documentation. I have not embellished the numbers. I did not need to.


Connect with Casey

If this resonated, or if there's a topic you want me to take on next, reach out. I read everything.

Casey writes about economic policy, nomadic life, cybersecurity, and navigating the world as a late-diagnosed AuDHD adult. New posts drop on my professional website.