The Lock Held. They Asked You for the Key.

 On June 26, 2026, the FBI and CISA updated a warning they first issued in March: Russian intelligence is hunting Signal users. The detail most headlines skip is the one that matters — they are not breaking Signal's encryption. They can't, and they know it. So they fall back on the oldest move in this field. They ask you for the key. Politely. Wearing a badge you already trust.


Here is the play, taken straight from the FBI's public service announcement (published June 26; reported the same day by Lawrence Abrams at BleepingComputer). A message arrives that looks like it's from Signal support. It claims that, following "a wave of attacks by hackers from Iran and post-Soviet countries," Signal is rolling out mandatory two-factor verification — and that to avoid losing your messages, you need to set up a backup. It walks you through the exact taps: Settings → Backups → Enable backups → View recovery key → Copy to clipboard. Then a second message, still posing as support, warns that your data is "at risk of permanent loss due to a sync issue" and asks you to paste that recovery key into the chat to save it.


That's the entire attack. No exploit. No malware. No zero-day. The instant you paste that key, the attacker restores your encrypted backup onto their phone and reads everything you've ever backed up — private messages, group chats, all of it.


Understand what the Backup Recovery Key actually is, because Signal does not hide it from you. When you turn on Secure Backups, your message history is stored encrypted on Signal's servers, and that key is the only thing that decrypts it. It is not a password you can reset. It is the master key to the vault. Signal tells you, in plain language, never to share it with anyone. The attacker's whole job — the FBI's entire warning — is to get you to ignore that one sentence for thirty seconds.


The campaign is tracked as UNC5792 and UNC4221, attributed to Russian Intelligence Services, including officers tied to the FSB Border Guards and actors working for the Russian military. The named targets are people of "high intelligence value" — current and former government and military officials, political figures, journalists, and officials in Ukraine. If you're reading this, you are almost certainly not on that list, and I'm not going to tell you Moscow is coming for your group chat. That would be the same fear-for-clicks I give other people grief for.


But the lesson generalizes, and that is the part worth your time. Signal built the lock correctly. End-to-end encryption did its job here; it has not been broken. The failure is the one this industry refuses to learn — mistaking a tool for safety. "I use Signal" is not a security posture. It's one good decision that one confident lie erases. The same trick — impersonate support, manufacture urgency, get you to read back a code or a key — empties bank accounts, hijacks email, and drains crypto wallets every single day. The brand on the screen changes. The con does not.


And notice the tell the FBI hands you for free: legitimate support — Signal's, your bank's, anyone's — never asks you to read a verification code or a recovery key back to them. Never. The request itself is the attack. If a "support" account asks for the key, the account is the threat.


If you use Signal with backups enabled, here's the unglamorous part. Treat your Backup Recovery Key like the deed to your house — write it down, store it offline, and never type it into a conversation. And know this one detail, because people miss it: if your key was already stolen, making a new Signal account on the same phone number does NOT invalidate the old key. You have to generate a new Backup Recovery Key in your backup settings to cut off future downloads — and even that won't claw back a backup they've already pulled. Once it's out, it's out. Which is exactly why the only winning move is to never hand it over in the first place.


So here's where it lands. Encryption is the strongest part of the system. You are the weakest. That isn't an insult — it's the architecture. The math is doing precisely what it promised; the attack simply walks around it and knocks on the one door math can't lock: your willingness to trust a stranger who says "support." Every vendor selling you a tool as if it were a guarantee is selling the same false comfort. The tool is real. The guarantee is the lie.


Read the FBI's PSA yourself — it's public, it's plain, and it quotes the exact phishing scripts: ic3.gov, published June 26, 2026.


Sources: FBI/CISA Public Service Announcement, June 26, 2026 (ic3.gov/PSA/2026/PSA260626); BleepingComputer, Lawrence Abrams, June 26, 2026; The Hacker News, June 26, 2026.