Russia's Signal Phishing Now Targets the Backup Recovery Key — and the Key Doesn't Expire
An FBI/CISA update says GRU-linked operators are coaxing victims into surrendering their Signal Backup Recovery Key, which yields full message history and durable account access.

The FBI and CISA have refreshed their March advisory on Russian intelligence services phishing Signal users, and the new wrinkle is the interesting one: operators are now after the Signal Backup Recovery Key.
That's a meaningful upgrade.
The earlier campaigns leaned on Signal's linked-device feature — trick a target into scanning a malicious QR code, attach an attacker-controlled device, mirror messages going forward. Useful for spies. Noisy, though, and revocable the moment the victim audits their linked devices.
The Backup Recovery Key is a different animal. It's the credential that decrypts a user's local Signal backup. Hand it to an attacker once and they can restore the backup on hardware they control, read the full private and group history, and effectively take over the account. The advisory's most uncomfortable line is that the key keeps working. There is no built-in expiry, no obvious user-facing tell that someone else has used it, and rotating it isn't a one-click affair the way unlinking a rogue device is.
If this sounds familiar, it should. In web-security terms it's closer to stealing a long-lived API key than stealing a session cookie. Session hijacks die when you log out. API keys die when you remember they exist.
The delivery is the boring part — the part defenders can actually do something about. Targets in and around Ukraine have been hit with lures impersonating trusted contacts, military or NGO coordination tools, and assorted "verify your account" pretexts. The end state of the social engineering is the same: get the mark to read the recovery key out of Signal's settings and paste it somewhere they shouldn't.
A few practical notes for anyone running comms hygiene for at-risk users:
- Treat the Backup Recovery Key like a root credential. It belongs in a password manager or written on paper in a safe, not in chats, screenshots, or cloud notes.
- Audit Linked Devices in Signal settings regularly, and assume any device you didn't personally attach is hostile.
- If you suspect a key was disclosed, rotate it and re-enroll backups. Assume prior backups are compromised.
- Journalists, diplomats, defense-adjacent NGOs, and Ukrainian military personnel remain the named target set, but the technique generalizes.
The broader point: Signal's cryptography is not what's breaking here. The protocol is doing its job. What's getting phished is the human convention wrapped around it — the idea that a "recovery key" is something users will guard as carefully as a private key, when in practice most people barely remember they have one.
GRU operators apparently noticed.



