US offers $10 million for info on group behind Signal and WhatsApp hacking spree

by | Jul 24, 2026 | Technology

US offers $10 million for info on group behind Signal and WhatsApp hacking spree

Federal authorities have announced a substantial financial reward for intelligence regarding a Russian state-sponsored cyber operation targeting secure messaging platforms. The State Department disclosed on Monday that it is offering up to $10 million for information identifying or locating members of two Russian government-affiliated groups conducting the campaign.

The phishing operation has been active since at least March, when the FBI first warned of attacks against high-value targets. The campaign employs deceptive messages designed to masquerade as legitimate support communications from Signal or WhatsApp. These fraudulent messages typically request users to click links, provide verification codes, or share account credentials. If victims comply, attackers can gain access to their accounts or link attacker-controlled devices to the compromised accounts, allowing unauthorized message viewing.

According to authorities, the operation has compromised thousands of messaging accounts belonging to US government employees, military personnel, political figures, and investigative journalists. The tactics have evolved since March, initially focusing on account linking through false support messages but more recently incorporating requests for backup recovery keys. When users provide these encryption keys, attackers can access past conversations stored on Signal servers. While Signal’s security features prevent attackers from viewing older messages in some cases, the compromise of backup keys circumvents this protection.

The State Department identified the responsible groups as UNC5792, associated with the Russian Federal Security Service Border Guards, and UNC4221, working for Russian military services. The reward is being offered through the State Department’s Reward for Justice program. In some instances, attackers manipulated legitimate Signal group invite pages to redirect users to malicious URLs that facilitated account compromise. Security experts note that phishing remains an effective attack method despite its technical simplicity, as individuals experiencing fatigue or distraction may inadvertently comply with fraudulent requests.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI