FBI, CISA Say Russia-Linked Hackers Are Phishing Signal and WhatsApp Accounts of High-Value Targets
U.S. cybersecurity authorities are alerting the public that actors tied to Russian intelligence services have been mounting large-scale phishing operations aimed at commercial messaging apps such as Signal and WhatsApp. According to notices from the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI), the intrusions focus on accounts belonging to people of significant intelligence interest.
FBI Director Kash Patel said on X that the campaign concentrates on individuals with high intelligence value - a group that includes current and former U.S. government personnel, members of the military, political figures and members of the press. The agencies report that the activity has led to unauthorized entry into thousands of personal messaging accounts worldwide. Once inside, operators can read messages and contact lists, send communications while posing as the victim, and use the compromised identity to phish others.
CISA and the FBI emphasized that these breaches result from social engineering and account takeover techniques, not from breaking the apps’ encryption mechanisms. While the agencies did not assign the activity to a single named group in their alert, previous analyses by Microsoft and the Google Threat Intelligence Team have connected similar operations to multiple Russia-aligned clusters tracked under names such as Star Blizzard, UNC5792 (also called UAC-0195), and UNC4221 (also known as UAC-0185).
European authorities have issued parallel warnings. France’s National Cybersecurity Agency (ANSSI) - through its Cyber Crisis Coordination Center (C4) - reported a rise in campaigns that target instant-messaging accounts belonging to government actors, journalists and corporate leaders. C4 noted that successful attacks can expose chat histories or allow attackers to fully control accounts and send messages impersonating victims.
The purpose of these operations is to obtain unauthorized account access so adversaries can read messages and contacts, send messages as the victim, and leverage trust relationships to carry out follow-on phishing against new targets.
Security agencies in Germany and the Netherlands have described the typical approach: attackers pose as “Signal Support” and prompt targets to either click a link (or scan a QR code) or to disclose a PIN or verification code. Both tactics rely on social engineering to capture account access, but they produce different outcomes for the victim.
If a target hands over a PIN or SMS verification code, the attacker can use that information to recover the account on their own device. In that scenario the intruder cannot retroactively read older messages, but they can monitor new incoming messages and send communications while impersonating the account owner - effectively locking the victim out of future control.
By contrast, when a target clicks a malicious link or scans a QR code supplied by the adversary, the attacker’s device becomes linked to the victim’s account. That linkage permits the attacker to access all messages, including historical conversations. The victim typically retains access unless the attacker explicitly removes their device from the app’s linked-device settings.
To reduce risk, authorities recommend never sharing SMS codes or verification PINs with anyone, treating unexpected messages from unknown senders with suspicion, examining links before clicking them, and regularly auditing linked devices in your messaging app and removing any entries you don’t recognize.
Signal itself has warned that these schemes are classic phishing built on social engineering. The company reminded users that an SMS verification code is needed only when first registering the app, and that Signal Support will never initiate contact via in-app messages, SMS or social media to request a verification code or PIN. Any solicitation for those codes should be treated as a scam.