Observed Signal · May 28, 2026 · Security Incident · Source: techcrunch · Impact: 2/5 · Sentiment: Negative
Phishing Campaign Targets Signal Secure Backups
Hackers are running a phishing campaign targeting Signal users by impersonating a "Signal Support" account and asking victims to share their recovery key to access encrypted online backups. Washington Post analyst Josh Rogin posted a screenshot of the attack; Access Now’s Mohammed Al‑Maskati told TechCrunch that multiple people received similar messages, including some victims who are not Chinese activists, suggesting the campaign may be broader. Stealing a recovery key would let attackers decrypt a user’s Secure Backup archive, but attackers still must fully take over the account to exploit older messages. Signal warns it will never contact users first or ask for registration codes, PINs, or recovery keys. Signal launched its opt‑in Secure Backups feature last year, which encrypts backups with a recovery key that is never shared with Signal’s servers.
A phishing campaign targeting encrypted backups undermines user privacy and trust; it highlights risks around account recovery and encrypted cloud backups, which are relevant to consumer app security and identity protection but is not industry‑shifting for AdTech.
Track Telegram Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Hackers impersonate "Signal Support" and ask users to share their recovery key to access encrypted backups.
- Washington Post analyst Josh Rogin posted a screenshot of the phishing message.
- Mohammed Al‑Maskati, director at Access Now’s Digital Security Helpline, said multiple people reported similar messages, some not tied to Chinese activism.
- Signal's Secure Backups encrypt backups with a recovery key that Signal says is never shared with its servers; Signal warns it will never contact users first or ask for recovery keys.
- Article publication date: 2026-05-28.
Connected Companies & Entities
1 Entity mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Hackers Target Signal Chat Backups via Phishing
Signal users are being targeted in a new wave of phishing attacks that attempt to steal chat backups by impersonating “Signal Support.” Attackers send messages warning users their backups will be lost unless they provide the recovery key, and include instructions to obtain that key. TechCrunch reported the campaign and Washington Post analyst Josh Rogin posted a screenshot of a sample message on X. Signal warns it will never contact users directly for recovery keys and recommends blocking and reporting fake accounts and contacting Signal via official support pages. Attackers would still need access to the victim’s Signal account to download and decrypt any backups stored on Signal’s servers. The piece cites prior phishing-based account takeovers, reportedly linked to actors operating from Russia.
Russian Hackers Target Signal and WhatsApp Users, Warns Dutch Intel
Dutch intelligence agencies MIVD and AIVD warned of a large-scale global hacking campaign by alleged Russian state actors targeting Signal and WhatsApp users — especially government and military officials and journalists. The attackers are reported to use phishing and social‑engineering techniques rather than malware, including impersonating Signal support to request SMS verification codes and PINs, tricking users into scanning malicious QR codes or clicking links, and abusing WhatsApp’s Linked Devices feature to link attacker devices and, in some cases, read past messages. Signal and Meta alerted users not to share verification codes; Meta pointed to Help Center guidance. Dutch spokespeople declined to provide additional operational details. Some techniques match methods previously observed in Russian operations related to the war in Ukraine.
Trezor warns of phishing after Brevo email provider breach
Hardware crypto wallet maker Trezor has warned customers of a second data breach affecting its ecosystem in as many months. A cyberattack on Brevo, a marketing technology company used by Trezor for email newsletters, allowed hackers to send approximately 347,000 phishing emails to Trezor customers. The phishing emails contained a malicious link that, when clicked, downloaded an app requesting the victim's wallet backup password, which could be used to steal cryptocurrency funds irreversibly. Brevo reported that hackers accessed 138 accounts due to improperly scoped permissions. Trezor emphasized that its own products and account systems were not compromised. This incident follows a previous breach at shipping partner ShipMonk that exposed personal data of over 81,000 customers, heightening risks of targeted physical attacks. Trezor is reevaluating vendor relationships and warns that email addresses may be used for future phishing attempts.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
