Signal Rolls Out Automatic Key Verification to Blunt Interception Attempts

The messaging app adds a key transparency layer, audited by Cloudflare and Trail of Bits, following a year of targeted phishing linked to Russian state-aligned clusters tracked as UNC5792 and UNC4221.

ThreatVectr Newsdesk· 4 min read
A digital illustration showing a hacker targeting Microsoft 365 through OAuth
Share

Key points

  • Signal has launched Automatic Key Verification, a background check that confirms the encryption key tied to a contact has not been quietly swapped.
  • The system relies on Cloudflare and Trail of Bits as independent auditors of Signal's key directory.
  • Users switch it on under Settings, Privacy, Advanced, and can still fall back to the older manual safety-number check.
  • The feature follows May 2025 phishing warnings added in response to attacks by Russian state-aligned groups Google's Threat Intelligence Group tracks as UNC5792 and UNC4221.
  • In June the U.S. State Department offered up to $10 million for information identifying members of those two clusters.

Signal has turned on a new safety net called Automatic Key Verification. It quietly checks, in the background, that the person you think you are messaging really is that person, and that nobody has slipped a fake encryption key into the middle of your chat.

That kind of attack has a name: a man-in-the-middle, where an attacker sits between two people and reads or alters what they send. Signal already lets users check a "safety number" together in person to rule this out. Almost nobody does.

What actually changed?

Signal now runs the check for you. The app compares the encryption key of the person you are talking to against a shared record, and confirms that record looks the same to everyone else on Signal. If it matches, you see a green tick and an "Encryption verified" message.

The shared record is the interesting part. Signal calls it key transparency. Two outside firms, Cloudflare and the security consultancy Trail of Bits, act as independent auditors of that record, so a rogue insider at Signal cannot silently attach a new key to your phone number without it being noticed.

"This protects against scenarios where a key is swapped out without the key owner's knowledge," Signal software engineer Katherine Yen wrote in the company's announcement, giving the example of "a malicious party" breaking into Signal itself.

How do I turn it on?

Open Signal, tap Settings, then Privacy, then Advanced, and toggle Automatic Key Verification. You can also trigger a check for a specific contact by opening the safety number screen and tapping "Verify Automatically."

People who would rather not trust Signal or its auditors can leave the feature off and keep verifying safety numbers by hand, as before.

Why is Signal doing this now?

Because real attackers have been going after Signal accounts for at least a year. In May, Signal added extra warning pop-ups when a user is asked to link a new device, after a wave of phishing attempts aimed at high-profile users, first reported by BleepingComputer.

The attackers sent fake "Signal Support" messages and abused the Linked Device feature, which lets a Signal account run on more than one device at once. If a target scanned the attacker's QR code, the attacker's device quietly joined the account and started receiving the victim's messages.

The FBI, along with German and Dutch government agencies, attributed the campaign to Russian state-aligned operators. Google's Threat Intelligence Group tracks the two main clusters as UNC5792 and UNC4221. The "UNC" prefix means uncategorised: Google has grouped the activity but has not yet merged it into a named APT such as Sandworm or APT29. Attribution here is medium confidence, and the clusters overlap in tradecraft but not cleanly in infrastructure.

In June, the U.S. State Department's Rewards for Justice programme offered up to $10 million for information identifying members of either group.

Does key transparency stop those phishing attacks?

Not directly. Automatic Key Verification is aimed at a different threat: someone tampering with the keys themselves, either at Signal or on the network. The Linked Device phishing tricked the victim into approving the attacker's access, so no key swap was needed.

The two defences are meant to stack. In-app warnings slow down social-engineering attempts. Key transparency closes off the quieter, more technical route an intelligence service might reach for if phishing stops working.

Date Event
Feb 2025 Google TAG publishes report on UNC5792 and UNC4221 targeting Signal users
May 2025 Signal adds Linked Device phishing warnings
Jun 2025 U.S. State Department offers up to $10 million for information on the two clusters
Nov 2025 Signal enables Automatic Key Verification with Cloudflare and Trail of Bits as auditors
© 2026 Threat Vectr