US warns Russian spies are still hunting your WhatsApp and Signal accounts
CISA and the FBI say Russian intelligence officers are running fresh phishing campaigns to hijack accounts on messaging apps used by journalists, officials and activists.

Key points
- CISA and the FBI updated a public warning that Russian intelligence services are targeting commercial messaging apps through phishing campaigns.
- The advisory updates guidance first published in March 2026 about the same Russian operation.
- Fresh examples of fake messages sent to victims are included in the update.
- Targets include government officials, military personnel, journalists and activists.
- CISA urges users to audit linked devices and treat unexpected login requests as suspicious.
Russian spies are still going after your messaging apps. CISA, the US government's civilian cyber defence agency, and the FBI updated their public warning this week about an ongoing campaign by Russian intelligence services. The March 2026 original alert is now supplemented with fresh tactics and sample phishing messages the agencies have collected.
We covered two related developments on 26 and 27 June: GRU-linked operators coaxing victims into surrendering their Signal Backup Recovery Key, and Ukrainian counterintelligence detailing FSB and GRU-linked phishing flows against officials' messengers across Ukraine, Europe and the US. This latest advisory confirms those operators haven't stepped back.
The target is accounts on commercial messaging apps, WhatsApp and Signal chief among them. The method is phishing: fake messages crafted to trick a target into linking their account to a device the attacker controls, or surrendering the one-time code that protects it.
Why would Russian spies want your chat app?
Messaging apps are where sensitive conversations happen. The people in the crosshairs tend to be government officials, military personnel, defence contractors and journalists covering Russia or Ukraine, along with human rights workers and activists inside and outside Russia.
Once inside an account, an attacker can read past conversations, watch new ones arrive in real time, impersonate the victim to trick their contacts, and harvest sensitive information for months. Some campaigns have used fake QR codes that, when scanned, silently link the victim's account to a device the attacker controls. The agencies didn't name a specific Russian unit in the public update, but earlier reporting has tied similar campaigns to groups linked to Russia's Federal Security Service and its military intelligence arm.
What should ordinary users do?
Treat any unexpected login request, verification code, or "link a new device" prompt as suspicious until you can prove otherwise.
The CISA guidance calls for four concrete steps:
- Open your messaging app and check the list of linked devices. Remove anything you don't recognise.
- Turn on two-step verification, sometimes called a PIN or passcode, inside the app itself. This is separate from your phone's lock screen.
- Never share a login code that arrives by SMS or in-app message. No legitimate party needs it.
- Be wary of QR codes sent in a chat, even from a known contact. A hijacked contact is still a hijacked contact.
Journalists, aid workers and government staff should assume they're of interest. Slow down before tapping a link; confirm odd requests through a second channel like a phone call.
What is new in this update?
CISA says the update reflects tactics observed since March 2026, including fresh phishing lures and social-engineering scripts. Publishing sample messages gives defenders and everyday users something concrete to recognise.
The campaign hasn't stopped. It's adapted. That's the part worth sitting with: the advisory isn't announcing a new threat, it's confirming a patient, ongoing one that has already evolved past what the March warning described.



