Hackers hunt Signal recovery keys to steal chat backups – Claril Noticias

Hackers are actively targeting Signal users in a widespread phishing campaign designed to steal private chat backups by impersonating the platform’s official support team.

The Anatomy of the Support Phishing Scam

The alarm was raised when Washington Post analyst Josh Rogin posted a screenshot detailing a highly deceptive social engineering tactic. In this campaign, malicious actors pose as Signal’s customer support team, sending messages that falsely warn users of an imminent threat. The fraudulent alerts claim that backed-up chats and media are “at risk of permanent loss due to a sync issue.”

To resolve this fabricated issue, targets are instructed to share their unique recovery key directly within the chat. “This links your existing backup to your account. Failure to do this may result in losing access to your account and all stored data,” warns the message, which is sent from an account deceptively named “Signal Support.”

This is a phishing attempt. If you get this message on Signal, do not follow the instructions. Many anti-CCP activists have also received this phishing attempt. Beware and be aware. pic.twitter.com/8J1YDcpUAX

— Josh Rogin (@joshrogin) May 27, 2026

Who is Being Targeted by the Campaign?

According to Rogin, several prominent anti-Chinese Communist Party (CCP) activists have already been targeted by this malicious wave. However, the scope of the operation appears to extend far beyond this specific group.

Mohammed Al-Maskati, Director of Access Now’s Digital Security Helpline—which investigates cyberattacks against journalists, dissidents, and human rights defenders—confirmed that at least two other individuals have reported identical phishing attempts. Crucially, these victims are not linked to Chinese activism, indicating that the cyber-campaign is either more widespread or is being executed by multiple independent hacking groups using identical playbooks.

While the exact success rate of the campaign remains unclear, Al-Maskati pointed out that obtaining the recovery key is merely the first step. To fully compromise the data, the attackers must still successfully hijack the victim’s Signal account. In response to the threat, Signal President Meredith Whittaker stated: “We’re working on mitigations here, and monitoring.”

Why This Attack is Different: The Threat to Historical Backups

This campaign represents a tactical shift. Traditional attacks on Signal users typically focus on account hijacking—often by stealing the victim’s phone number—to impersonate them, harvest contacts, or initiate new conversations. However, because of Signal’s privacy-focused architecture, re-registering an account on a new device does not transfer historical message logs. The attackers are left with an empty chat history.

By targeting recovery keys, hackers are attempting to bypass this limitation. Access to the recovery key combined with an account takeover would allow them to download and decrypt the victim’s entire historical archive, including past messages, photographs, and shared documents.

How Signal’s Secure Backups Work

Last year, Signal launched Secure Backups, an opt-in feature designed to let users store their chat history on Signal’s servers. This data is fully encrypted using a unique recovery key. Signal says this key remains strictly on the user’s device and is never shared with the organisation’s servers.

“Without your unique recovery key, no one (including Signal) can read, decrypt, or restore any of the data in your Secure Backup Archive,” the organisation previously stated. Consequently, the only way for an attacker to read these archives is to trick the user into handing over the key.

How to Protect Your Signal Account

The primary defence against this attack is awareness of Signal’s official communication policies. Signal explicitly says that it “will never reach out” to users unsolicited, and will never ask for registration codes, PINs, or recovery keys under any circumstances. Any unsolicited message claiming to be from “Signal Support” is a scam. The company publicly warned about this specific attack vector last month.

To safeguard your account from being hijacked, users are strongly encouraged to enable Registration Lock. This security feature prevents attackers from registering your phone number on a new device unless they also possess your custom Signal PIN.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *