FBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal
## Joint Advisory on Phishing Campaign Targeting Encrypted Messaging Applications
Joint Advisory on Phishing Campaign Targeting Encrypted Messaging Applications
The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued a joint cybersecurity advisory concerning a widespread phishing campaign. The alert highlights that Russian Intelligence Services are actively targeting users of encrypted messaging applications, including Signal.
The attackers are bypassing the platform's end-to-end encryption by hijacking user accounts instead of compromising the cryptographic protocols.
This cyber espionage campaign is designed to compromise individuals with high intelligence value. The targets include current and former United States government officials, military personnel, influential political figures, and prominent journalists. The operation has resulted in unauthorized access to thousands of accounts globally.
As Signal's core encryption remains secure, attackers use social engineering techniques to deceive victims into relinquishing control of their profiles. They impersonate official support channels, creating fraudulent profiles with names like "Signal Security Support ChatBot" to appear legitimate.
The alert highlights that Russian Intelligence Services are actively targeting users of encrypted messaging applications, including Signal.
The messages create urgency by falsely claiming data leaks or suspicious login attempts from foreign locations. Victims are then instructed to complete a verification procedure by providing their SMS verification code or scanning a malicious QR code. This allows attackers to tether their hardware to compromised accounts without detection, enabling them to monitor conversations and impersonate victims.
The FBI and CISA recommend the following measures to defend against account takeover attempts:
Never share verification codes or personal PINs, as legitimate support staff will not request authentication codes through direct messages. Treat unexpected security alerts with caution and avoid scanning unsolicited QR codes or clicking unverified links. Regularly audit the linked devices menu within application settings to disconnect unauthorized hardware. Enable disappearing messages to automatically delete sensitive conversations, minimizing available data if an account is compromised.
Based on reporting by Cyber Security News.
