SSU, FBI Detail Russian Phishing Op Targeting Signal and Telegram Accounts
Ukrainian counterintelligence says GRU and FSB-linked operators ran fake tech-support flows against officials' messengers across Ukraine, Europe, and the U.S.

Key points
- The SSU and FBI say Russian intelligence services ran a long-running campaign to seize messaging accounts belonging to government officials, military personnel, politicians, and activists.
- Operators posed as messenger support staff or as known contacts, walking victims through bogus account-verification flows on Signal, Telegram, and WhatsApp.
- The mechanism is QR-code linked-device abuse and SMS one-time-code interception, not a software vulnerability.
- Compromised accounts were then used to reach that account's contacts, pivot to spear-phishing, seed malware, and run influence operations.
- No patch fixes this. Linked-device audits, registration locks, and out-of-band verification are the mitigations.
What did the SSU and FBI actually find?
Ukraine's Security Service and the FBI say they've mapped a multi-year Russian intelligence operation aimed at hijacking messaging accounts of officials, soldiers, politicians, and activists across Ukraine, Europe, and the U.S. Operators posed as messenger support staff or as acquaintances, pushing victims through bogus account-verification flows to capture Signal, Telegram, and WhatsApp sessions, along with the contact graphs, group chats, and operational chatter inside them.
This is social engineering, not an exploit chain. No CVE here. The mechanism, QR-code linked-device abuse and SMS one-time-code interception, has been documented in GRU and FSB tradecraft for years. Our story on 26 June 2026, Russia's Signal Phishing Now Targets the Backup Recovery Key, covered an FBI/CISA update describing how GRU-linked operators coax victims into surrendering their Signal Backup Recovery Key, yielding full message history and durable account access; this advisory sits squarely in the same operational pattern.
The SSU attributes the work to Russian special services without breaking out specific unit numbers publicly. Indictment-grade attribution, if it comes, will likely arrive via DOJ or a follow-up advisory rather than this press cycle.
Why does account access lead to a broader network compromise?
Reaching a Ukrainian battalion commander's Signal is only the first step. Pivoting from that compromised account into the contacts of a U.S. Congressional staffer or a European defence ministry adviser, using the trust of an already-authenticated sender, is the actual prize. Account takeover is the delivery system; the next-hop spear-phishing is the campaign. The SSU also flagged that compromised accounts were used to seed malware and to push influence prompts at follower networks, consistent with how Star Blizzard and Coldriver clusters have operated against NGOs and policy researchers.
Should you worry if you're not a government official?
If you're in the contact list of anyone who is a government official, an activist, or a defence-sector employee, yes. The attack moves laterally through trusted relationships, so proximity to a high-value target matters.
What should defenders do right now?
Audit linked devices on Signal (Settings, Linked Devices), Telegram (Settings, Devices), and WhatsApp (Settings, Linked Devices). Kill anything unrecognised. Turn on Signal's registration lock and Telegram's two-step verification password. SMS codes alone are not enough against an attacker who can phish them in real time or, in some theaters, intercept SS7 signalling traffic.
For higher-risk users: move sensitive conversations to disappearing messages and treat any inbound support contact, whether in-app, by SMS, or by phone, as hostile until proven otherwise. Real Signal support does not call you.
No patched-version string fixes this. Hygiene is the mitigation: linked-device review, registration locks, and an organisational habit of verifying out-of-band before acting on anything a contact sends, especially a familiar one.
The SSU statement is the primary source here. A parallel FBI advisory or PIN covering the U.S. Victim set would be worth watching for if Kyiv's characterisation of scope holds up.



