US offers $10 million for info on group behind Signal and WhatsApp hacking spree

by | Jul 27, 2026 | Technology

US offers $10 million for info on group behind Signal and WhatsApp hacking spree

The US State Department announced a reward of up to $10 million for information identifying or locating members of two Russian state-affiliated cyber groups engaged in a widespread campaign targeting encrypted messaging accounts. The operation has been active since at least March, according to an FBI advisory released earlier in the year.

The attackers have employed multiple phishing tactics to compromise thousands of accounts belonging to high-value targets including current and former US government officials, military personnel, political figures, and investigative journalists. Initial messages impersonate automated support communications from Signal or WhatsApp, requesting that users click links or provide verification codes. If users comply, the attackers can either link their own devices to the victim’s account or take complete control, allowing them to read incoming messages. A Signal security feature prevents attackers from accessing previous conversations using this method.

In a recent update, the campaign evolved to include requests for backup recovery keys. Users receive messages instructing them to create account backups and provide the encryption passcodes used to secure those backups on Signal’s servers. By obtaining these keys, attackers gain access to historical conversations and stored data. The phishing messages were designed to appear legitimate, sometimes even exploiting Signal’s group invitation feature by redirecting users to malicious URLs that link attacker-controlled devices to victim accounts.

The State Department identified the two groups responsible as UNC5792, associated with the Russian Federal Security Service Border Guards, and UNC4221, working on behalf of Russian military services. The campaign has not exploited any encryption vulnerabilities in the platforms themselves but has relied on social engineering to deceive users into voluntarily providing access credentials.

Security experts note that phishing remains highly effective despite its relatively unsophisticated technical requirements, particularly against fatigued or inattentive targets. The State Department and FBI have advised users to resist the urgency conveyed in such messages and, if credentials have been compromised, to generate new backup recovery keys to prevent further unauthorized access to previously downloaded account data.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI