GoFirm
Back to Blog
Case Studies·4 min read

The fake Signal Support message that opened Bill Browder's encrypted backup to Russian Intelligence

By GoFirm

On 26 June 2026, the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) published an updated Public Service Announcement confirming that a phishing campaign run by Russian Intelligence Services (RIS) had evolved to target Signal's Backup Recovery Keys. The update built on a March 2026 advisory that first linked the campaign to Moscow. It began, as it had for months, with a single message arriving from an account calling itself Signal Support.

The message opened with an urgent warning: hackers from Iran and post-Soviet countries had been attacking Signal accounts, and the app was introducing mandatory two-factor verification in response. To comply, the target was walked through a precise sequence: open Settings, go to Backups, enable backups, view the recovery key, copy it to the clipboard, and paste it into the chat with "Support". A second message followed days later, warning that the account's data was at risk of permanent loss due to a synchronisation issue, pressing anyone who had hesitated to send the key after all.

The recovery key is a 64-character string that decrypts a user's Signal Secure Backup: every message and every piece of media stored across every conversation. Handing it to the attacker is functionally identical to handing over the phone. Among those who reportedly did were Bill Browder, the financier and Kremlin critic behind the Magnitsky Act; Arndt Freytag von Loringhoven, a former vice president of Germany's Bundesnachrichtendienst (BND); and Julia Klöckner, President of the German Bundestag, whose account was reportedly compromised through a phishing message embedded in what looked like a legitimate party group chat. German Chancellor Friedrich Merz was also targeted, though no compromise has been confirmed in his case. The FBI says the wider campaign has hit thousands of accounts belonging to current and former US and international officials, military personnel, journalists, and NGOs supporting Ukraine.

The financial response has been unusually direct. On 30 June 2026, the US Department of State's Rewards for Justice programme announced a reward of up to $10 million for information leading to the identification or location of the individuals behind UNC5792 and UNC4221. No dollar figure has been placed on what was actually taken. What was taken was years of private and group correspondence belonging to some of the most closely watched people in the world, now sitting outside their control and within reach of a hostile intelligence service.

The defences that failed here were not weak by conventional standards. Signal's end-to-end encryption held throughout: officials confirmed the app itself was never compromised, and the backup key remains one of the strongest credential designs available on a consumer messaging platform. Signal has published in-app warnings about social engineering. None of it mattered, because the entire architecture assumes the key stays with the person who generated it. The vulnerability was not in the cryptography. It was in the moment it takes a busy, concerned person to copy a string of characters and paste it into a chat with someone who sounds official.

Copying a Backup Recovery Key out of a messaging app and sending it to an external party is a high-consequence execution event, whatever the platform and whatever the pretext used to request it. For an embassy, a ministry, an NGO, or a corporate security team responsible for protecting officials, diplomats, and executives who rely on encrypted messaging for sensitive work, that transmission is precisely the kind of action GoFirm sits in front of. Before the key can be copied and sent anywhere, a confirmation request goes to the named individual on their own registered device, on a channel entirely separate from the one carrying the instruction, requiring biometric confirmation before the action can complete.

A phishing message impersonating Signal Support, however convincing, cannot produce that confirmation. The execution boundary holds regardless of how credible the impersonation appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Internet Crime Complaint Center (IC3), "Russian Intelligence Services Continue to Target Commercial Messaging Applications" (PSA260626), 26 June 2026

2. BleepingComputer, "FBI: Russian hackers now target Signal backup recovery keys", 26 June 2026

3. BleepingComputer, "U.S. offers $10 million for hackers targeting WhatsApp, Signal users", 30 June 2026

4. TechRadar, "FBI warns of Russian Intelligence phishing campaign abusing Signal support services to target VIPs and high-value government and military targets", June 2026

5. Security Affairs, "New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages", June 2026

Share this article