Signal Rolls Out Automatic Key Verification to Blunt Interception Attempts

The messaging app adds a key transparency layer, audited by Cloudflare and Trail of Bits, following a year of targeted phishing linked to Russian state-aligned clusters tracked as UNC5792 and UNC4221.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A messaging application interface on a smartphone displaying key verification status, with cryptographic elements and security confirmations visible on the scre
Share

Key points

  • Signal has launched Automatic Key Verification, a background check that confirms the encryption key tied to a contact hasn't been quietly swapped.
  • The system relies on Cloudflare and Trail of Bits as independent auditors of Signal's key directory.
  • Users switch it on under Settings, Privacy, Advanced and can still fall back to the older manual safety-number check.
  • The feature follows May 2025 phishing warnings added in response to attacks by Russian state-aligned groups Google's Threat Intelligence Group tracks as UNC5792 and UNC4221.
  • In June the U.S. State Department offered up to $10 million for information identifying members of those two clusters.

Signal has turned on a new safety net called Automatic Key Verification. It quietly checks, in the background, that the person you think you're messaging really is that person, and that nobody has slipped a fake encryption key into the middle of your chat.

That kind of attack has a name: a man-in-the-middle, where an attacker sits between two people and reads or alters what they send. Signal already lets users check a "safety number" together in person to rule this out. Almost nobody does.

What actually changed?

Signal now runs the check for you. The app compares the encryption key of the person you're talking to against a shared record, and confirms that record looks the same to everyone else on Signal. If it matches, you see a green tick and an "Encryption verified" message.

The shared record is the interesting part. Signal calls it key transparency. Cloudflare and the security consultancy Trail of Bits act as independent auditors of that record, so a rogue insider at Signal can't silently attach a new key to your phone number without it being noticed.

"This protects against scenarios where a key is swapped out without the key owner's knowledge," Signal software engineer Katherine Yen wrote in the company's announcement, giving the example of "a malicious party" breaking into Signal itself.

How do I turn it on?

Open Signal, tap Settings, then Privacy and Advanced, and toggle Automatic Key Verification. You can also trigger a check for a specific contact by opening the safety number screen and tapping "Verify Automatically."

Users who'd rather not trust Signal or its auditors can leave the feature off and keep verifying safety numbers by hand, as before.

Why is Signal doing this now?

Because real attackers have been going after Signal accounts for at least a year. In May 2025, Signal added extra warning pop-ups when a user is asked to link a new device, after a wave of phishing attempts aimed at high-profile users, first reported by BleepingComputer.

The attackers sent fake "Signal Support" messages and abused the Linked Device feature, which lets a Signal account run on more than one device at once. Scan the attacker's QR code, and the attacker's device quietly joined the account and started receiving your messages.

The FBI, German authorities, and the Dutch government attributed the campaign to Russian state-aligned operators. Google's Threat Intelligence Group tracks the two main clusters as UNC5792 and UNC4221. Attribution is medium confidence; the clusters overlap in tradecraft but not cleanly in infrastructure. Our earlier report from 26 June found GRU-linked operators were coaxing victims into surrendering their Signal Backup Recovery Key, a tactic that yields full message history without any key swap at all.

In June 2025, the U.S. State Department's Rewards for Justice programme offered up to $10 million for information identifying members of either group.

Does key transparency stop those phishing attacks?

Not directly. Automatic Key Verification is aimed at a different threat: someone tampering with the keys themselves at Signal or on the network. Linked Device phishing tricked the victim into approving the attacker's access, so no key swap was needed.

The two defences are meant to stack. In-app warnings slow down social-engineering attempts. Key transparency closes off the quieter, more technical route an intelligence service might reach for once phishing stops working. For anyone whose threat model includes a capable state actor, that's not a hypothetical sequence.

Date Event
Feb 2025 Google TAG publishes report on UNC5792 and UNC4221 targeting Signal users
May 2025 Signal adds Linked Device phishing warnings
Jun 2025 U.S. State Department offers up to $10 million for information on the two clusters
Nov 2025 Signal enables Automatic Key Verification with Cloudflare and Trail of Bits as auditors
© 2026 Threat Vectr