SSU, FBI Detail Russian Phishing Op Targeting Signal and Telegram Accounts
Ukrainian counterintelligence says GRU and FSB-linked operators ran fake tech-support flows against officials' messengers across Ukraine, Europe, and the U.S.

Ukraine's Security Service (SSU) and the FBI say they've mapped a multi-year Russian intelligence operation aimed at hijacking the messaging accounts of officials, soldiers, politicians, and activists.
The targets sat in Ukraine, across Europe, and inside the U.S.
Per the SSU's public account, operators posed as messenger support staff or as acquaintances of the target, pushing victims through bogus account-verification flows. The payoff was access to Signal, Telegram, and WhatsApp sessions — and the contact graphs, group chats, and operational chatter inside them.
This is social engineering, not an exploit chain. No CVE here. The mechanism is the well-worn QR-code linked-device abuse and SMS one-time-code interception that has been kicking around GRU and FSB tradecraft for at least two years (Sandworm-adjacent clusters tracked as UAC-0195 and the Star Blizzard activity Microsoft and the UK NCSC have documented previously fit the same shape).
The SSU attributes the work to Russian special services without breaking out specific unit numbers in its public statement. Translation: expect the indictment-grade attribution, if it comes, to land via DOJ or a follow-up advisory rather than this press cycle.
Operationally, the interesting bit is reach. Hitting a Ukrainian battalion commander's Signal is one thing. Pivoting from that compromised account into the contacts of a U.S. congressional staffer or a European MoD adviser — using the trust of an already-authenticated sender — is the actual prize. Account takeover is the delivery system; the next-hop spear-phishing is the campaign.
What defenders should do, today:
- Audit linked devices on Signal (Settings → Linked Devices), Telegram (Settings → Devices), and WhatsApp (Settings → Linked Devices). Kill anything you don't recognize.
- Turn on Signal's registration lock and Telegram's two-step verification password. SMS codes alone are not enough against an attacker who can phish them in real time or, in some theaters, intercept SS7 traffic.
For higher-risk users, move sensitive conversations to disappearing messages and treat any inbound "support" contact — in-app, by SMS, or by phone — as hostile until proven otherwise. Real Signal support does not ring you up.
The SSU also flagged that compromised accounts were used to seed malware and to run influence prompts at follower networks, which tracks with how Star Blizzard and Coldriver clusters have been operating against NGOs and policy researchers.
No patched-version string fixes this one. The mitigation is hygiene: linked-device review, registration locks, and an organizational habit of verifying out-of-band before clicking anything a contact sends, even (especially) a familiar one.
The SSU statement is the primary source; expect a parallel FBI advisory or PIN to follow if the U.S.-side victim set is as broad as Kyiv suggests.



