Signal Users Targeted in Phishing Campaign Designed to Steal Chat Backup Keys

A phishing campaign is targeting Signal users by impersonating the app’s support team in an attempt to steal recovery keys that unlock encrypted chat backups, TechCrunch reported on May 28, 2026.

The attack works by sending victims a message from an account called “Signal Support,” warning that their backed-up chats and media are “at risk of permanent loss due to a sync issue.” The message instructs users to share their recovery key — the credential required to decrypt Signal’s Secure Backup archives — directly with the attackers. “Failure to do this may result in losing access to your account and all stored data,” the fraudulent message reads.

Washington Post analyst Josh Rogin first surfaced the attack on May 27, 2026, posting a screenshot on social media and noting that several anti-Chinese Communist Party activists had received the message. Mohammed Al-Maskati, director at Access Now’s Digital Security Helpline — which investigates cyberattacks against journalists, dissidents, and human rights activists — told TechCrunch that two additional individuals, who are not Chinese activists, reported receiving similar messages. This suggests the campaign may be broader than initially observed, or that multiple hacker groups are using the same method.

Signal launched its Secure Backups feature last year, allowing users to upload encrypted account contents to Signal’s servers. The recovery key never leaves the user’s device and is never shared with Signal itself, meaning anyone who obtains it could potentially decrypt a victim’s full archive of past messages, photos, and documents.

Signal has publicly stated it will never contact users first and will never ask for a registration code, PIN, or recovery key. The organization warned about this type of attack last month. Any message claiming to be from “Signal Support” should be treated as malicious.

Al-Maskati noted that obtaining the recovery key is only one step in the attack — hackers would still need to take over the victim’s account to make full use of the stolen credential. It is not yet clear how many users have been affected or how successful the campaign has been.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top