Observed Signal · Jun 2, 2026 · Phishing Campaign · Source: t3n · Impact: 2/5 · Sentiment: Negative

Hackers Target Signal Chat Backups via Phishing

Executive Signal Summary

Signal users are being targeted in a new wave of phishing attacks that attempt to steal chat backups by impersonating “Signal Support.” Attackers send messages warning users their backups will be lost unless they provide the recovery key, and include instructions to obtain that key. TechCrunch reported the campaign and Washington Post analyst Josh Rogin posted a screenshot of a sample message on X. Signal warns it will never contact users directly for recovery keys and recommends blocking and reporting fake accounts and contacting Signal via official support pages. Attackers would still need access to the victim’s Signal account to download and decrypt any backups stored on Signal’s servers. The piece cites prior phishing-based account takeovers, reportedly linked to actors operating from Russia.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Security-focused phishing against a major consumer messaging app risks account takeover and data exposure for high-value users, but it is not a platform-level policy or technical change affecting the wider AdTech ecosystem.

SIGNAL RADAR

Track TargetVideo Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Cybercriminals are using phishing messages that impersonate 'Signal Support' to request users' chat backup recovery keys.
  • TechCrunch reported the campaign and Washington Post analyst Josh Rogin posted a screenshot of the phishing message on X.
  • Signal states it will never contact users directly to request recovery keys and advises users to block, report fake accounts, and contact Signal via official support channels.
  • To access and decrypt chat backups attackers need both the recovery key and access to the victim's Signal account to download the encrypted backup.

Ontology Mapping & Concepts

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: Jun 2, 2026
Original Coverage Title: “Signal: Wie sich Cyberkriminelle Zugang zu deinen Daten erschleichen – und wie du dich schützt”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

PrivacyMay 28, 2026

Phishing Campaign Targets Signal Secure Backups

Hackers are running a phishing campaign targeting Signal users by impersonating a "Signal Support" account and asking victims to share their recovery key to access encrypted online backups. Washington Post analyst Josh Rogin posted a screenshot of the attack; Access Now’s Mohammed Al‑Maskati told TechCrunch that multiple people received similar messages, including some victims who are not Chinese activists, suggesting the campaign may be broader. Stealing a recovery key would let attackers decrypt a user’s Secure Backup archive, but attackers still must fully take over the account to exploit older messages. Signal warns it will never contact users first or ask for registration codes, PINs, or recovery keys. Signal launched its opt‑in Secure Backups feature last year, which encrypts backups with a recovery key that is never shared with Signal’s servers.

Read assessment
Security / GovernanceMar 9, 2026

Russian Hackers Target Signal and WhatsApp Users, Warns Dutch Intel

Dutch intelligence agencies MIVD and AIVD warned of a large-scale global hacking campaign by alleged Russian state actors targeting Signal and WhatsApp users — especially government and military officials and journalists. The attackers are reported to use phishing and social‑engineering techniques rather than malware, including impersonating Signal support to request SMS verification codes and PINs, tricking users into scanning malicious QR codes or clicking links, and abusing WhatsApp’s Linked Devices feature to link attacker devices and, in some cases, read past messages. Signal and Meta alerted users not to share verification codes; Meta pointed to Help Center guidance. Dutch spokespeople declined to provide additional operational details. Some techniques match methods previously observed in Russian operations related to the war in Ukraine.

Read assessment
IdentityJan 12, 2026

Instagram password-reset emails spark phishing fears

Over the weekend, millions of Instagram users received password-reset emails they did not initiate, prompting security experts to warn of potential phishing and fraud. Malwarebytes highlighted a purported dataset tied to around 17.5 million Instagram accounts that was offered for sale on the dark web, reporting that it could include usernames, email addresses, phone numbers, and some physical addresses. Instagram acknowledged the issue but denied a data breach or unauthorized access to accounts, saying users can ignore the emails and that passwords were not automatically changed. Security researchers caution that even without a breach, circulating data can fuel phishing attempts. Instagram advised a cautious approach and recommended steps to protect accounts: enable two-factor authentication, review logged-in devices in the Meta Accounts Center, consider changing passwords, and avoid clicking links in suspicious emails. Some observers noted the possibility that older datasets are resurfacing rather than a fresh incident.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.