Russia's Signal Phishing Now Targets the Backup Recovery Key — and the Key Doesn't Expire

An FBI/CISA update says GRU-linked operators are coaxing victims into surrendering their Signal Backup Recovery Key, which yields full message history and durable account access.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Russia's Signal Phishing Now Targets the Backup Recovery Key — and the Key Doesn't Expire
Share

Key points

  • The FBI and CISA have updated their March advisory on Russian intelligence services phishing Signal users.
  • Operators now target the Signal Backup Recovery Key, not just the linked-device feature.
  • The key decrypts a full local Signal backup and carries no built-in expiry.
  • Targets to date include Ukraine-adjacent military personnel, journalists and diplomats.
  • Signal's cryptography is not the failure point; the human handling of credentials is.

The FBI and CISA have refreshed their March advisory on Russian intelligence services phishing Signal users, and the new wrinkle is the one worth watching: operators are now after the Signal Backup Recovery Key.

That is a meaningful upgrade.

What changed from the earlier campaign?

The earlier campaigns leaned on Signal's linked-device feature. Trick a target into scanning a malicious QR code, attach an attacker-controlled device, mirror messages going forward from that point. Useful for intelligence collection, but noisy and revocable the moment the victim checks their linked devices.

The Backup Recovery Key is a different animal. It decrypts a user's local Signal backup. Hand it to an attacker once and they can restore that backup on hardware they control, read the full private and group history, and effectively take over the account. The advisory's most uncomfortable detail is that the key keeps working. There is no built-in expiry, no user-facing signal that someone else has used it, and rotating it is nothing like the one-tap fix of unlinking a rogue device.

In web-security terms it is closer to stealing a long-lived API key (a credential that grants persistent programmatic access) than stealing a session cookie. Session hijacks die when you log out. API keys die when you remember they exist.

We have tracked GRU-linked activity across four stories in the last 90 days, starting with our 28 May report on the Kali365 OAuth phishing kit. The credential-harvesting logic is consistent: find the authentication layer users treat as administrative but handle carelessly.

How does the phishing reach targets?

The delivery is the predictable part. Targets in and around Ukraine have been hit with lures impersonating trusted contacts, military coordination tools and NGO communications. The goal of the social engineering is the same in every variant: get the target to read the recovery key out of Signal's settings and paste it somewhere they should not.

Should you worry?

If you run communications security for at-risk users, treat the Backup Recovery Key as a root credential. It belongs in a password manager or written on paper in a safe, not in screenshots or cloud notes.

Audit Linked Devices in Signal settings regularly; any device you did not personally attach should be treated as hostile. If you suspect a key was disclosed, rotate it and re-enroll backups immediately, and assume any prior backup is already read.

Journalists, diplomats and Ukrainian military personnel are the named target set, but nothing about the technique limits it to them.

The broader point: Signal's cryptography is not what is breaking here. The protocol is doing its job. What is getting phished is the human convention wrapped around it, the assumption that a "recovery key" is something users will guard as carefully as a private key, when in practice most people barely remember they have one.

GRU operators apparently noticed.

© 2026 Threat Vectr