US Offers $10 Million for Russian Group’s Signal and WhatsApp Hacks

The U.S. offers a $10 million reward for information on a Russian cyber group targeting Signal and WhatsApp accounts of high-value individuals.

By Central
Reward targets Russian state cyber group hacking Signal and WhatsApp accounts of journalists and government employees.
Highlights
  • The phishing campaign has been active since at least March 2025, evolving to steal backup passcodes.
  • Two Russian intelligence-linked groups, UNC5792 and UNC4221, are responsible for the attacks.
  • Signal’s safety feature prevents attackers from reading previous conversations, but new ones are compromised.

Federal authorities are offering a reward of up to $10 million for information leading to the identification or location of a Russian state cyber group that has compromised thousands of Signal and WhatsApp accounts belonging to investigative reporters and US government employees. The bounty, announced by the US Department of State, targets the threat actors behind an ongoing and evolving phishing campaign that has demonstrated a sophisticated understanding of secure messaging platforms, targeting high-value individuals with tailored social engineering tactics.

Evolving Phishing Tactics Target Encrypted Messaging

The operation has been active since at least March, when the FBI published an advisory warning of ongoing phishing campaigns targeting high-value targets by attackers associated with Russian intelligence services. Messages masquerading as automated support communications ask that users click a link or provide verification codes or account passcodes. In the event the user complies, they unknowingly link the attacker’s device to their account or have their account completely taken over and are locked out. With that, the attackers can read any new messages sent to the compromised account. A safety feature built into Signal, however, prevents the attackers from reading any previous conversations. The messages are sent to “individuals of high intelligence value, such as current and former US government officials, military personnel, political figures, and journalists.”

Last week, the FBI published an update confirming the campaign had evolved. In addition to trying to pose as support bots tricking recipients into linking their account to an attacker device, the messages also urge users to create a backup of all previous communications by following specific directions. A follow-up message then instructs the targets to send the long passcode used to encrypt backups stored on Signal servers. With that, the attackers gain access to past Signal conversations. The update identified two Russian government groups responsible, tracked as UNC5792 and UNC4221.

How the Signal and WhatsApp Phishing Attacks Work

The attack chain relies on a multi-step social engineering process, not a technical exploit of the messaging apps themselves. The initial message appears to come from Signal’s support team, warning of hacking attempts and an updated terms of service. One known message text reads: “Recently, attempts to hack users of our messenger with the connection of third-party devices to the account have become more frequent. An investigation conducted jointly with the US government and European partners revealed that the attacks on accounts were carried out by hackers from Iran and post-Soviet countries. In this regard, Signal updates Terms of Service & Privacy Policy, and introduces Mandatory Two-factor Verification for users.”

The message then provides step-by-step instructions for the victim to navigate to their backup settings, view their recovery key, and send it to the attackers. A second message then instructs the target to send the long passcode used to encrypt backups stored on Signal servers. This two-step process allows the attackers to bypass the platform’s built-in protections against reading past conversations, effectively giving them a complete archive of the victim’s communications.

What Makes This Campaign Particularly Dangerous

For English-speaking users in the US, UK, Australia, and Canada, this campaign represents a significant escalation in state-sponsored targeting of personal communications. The attackers are not breaking Signal or WhatsApp’s encryption; they are exploiting the human element. By convincing a target to willingly provide their backup passcode, the attackers gain access to a complete history of encrypted messages. This method is particularly pernicious because it subverts the very security features users rely on for private communication. The reward of $10 million underscores the severity of the threat and the US government’s determination to disrupt the operations of the Russian groups, identified as UNC5792 and UNC4221, behind this campaign.

What Affected Users Should Do Now

If you suspect your Signal or WhatsApp account may have been compromised, take immediate action. Begin by revoking access to any linked devices. For Signal, navigate to Settings > Linked Devices and remove any unrecognized connections. For WhatsApp, go to Settings > Linked Devices and do the same. Next, change your account passcode and enable two-factor authentication (2FA) using a separate authenticator app, not SMS-based codes, to protect against future unauthorized linking. It is also critical to rotate the backup passcode for your Signal account by disabling and re-enabling backups, which will generate a new key.

To reduce the risk of falling victim to such campaigns in the future, treat any unsolicited message requesting verification codes, account passcodes, or urging you to click a link as an immediate red flag. Legitimate service providers, including Signal and WhatsApp, never ask for your backup passcode or request that you link a device via an unsolicited message. Using a reputable no-log VPN service can help obscure your IP address and make it more difficult for attackers to pinpoint your location during targeted campaigns. Additionally, deploying a multi-layer endpoint protection solution on your devices can provide an extra layer of defense against malware that may be delivered through phishing links. Always independently verify any support communication by contacting the service provider directly through their official website or app, not through the message itself.

Share This Article