Russian Intelligence Is Impersonating Signal Support to Steal Your Backup Recovery Keys — The FBI Spent $10 Million in Bounties to Tell You That the Weakest Link in End-to-End Encryption Has Always Been the Person Holding the Phone

🤚 The Open-Palm Briefing

The FBI and CISA issued a joint advisory on June 26 warning that Russian intelligence operatives — tracked as UNC5792 and UNC4221 — are running an elaborate phishing campaign against Signal users. The targets: current and former US government officials, military personnel, Ukrainian officials, journalists, and policy analysts. The kind of people who use Signal specifically because they have something worth encrypting.

The attack is elegant in its simplicity:

  • Stage One: Operatives impersonate Signal support, claiming a mandatory two-factor verification is required following attacks from “Iran and post-Soviet countries.” They instruct victims to enable Signal Backups and create recovery keys.
  • Stage Two: A follow-up message warns of data loss from “synchronization issues” and asks victims to paste their recovery keys into the chat window.

That is the entire exploit. No zero-days. No sophisticated exploit chains. Just “please paste your password here” delivered with institutional confidence. The operation has successfully compromised thousands of accounts.

👐 The Two-Handed Dissection

UNC5792 has been linked to the Russian Federal Security Service (FSB) Border Guards — because apparently border security in Russia extends to your encrypted messages. UNC4221 operates on behalf of Russian military services. Together, they have compromised thousands of individual commercial messaging accounts belonging to the exact people you would expect Russian intelligence to be interested in.

The target list reads like a personnel directory of people Russia would very much like to eavesdrop on:

  • U.S. and NATO government and diplomatic officials
  • Defense and intelligence personnel
  • Policy analysts and journalists covering Russia-Ukraine
  • Ukraine-supporting NGOs
  • Researchers covering Russian security affairs

The Department of State was sufficiently impressed to offer a $10 million bounty through the Rewards for Justice program for information on either group. They want names, locations, biographies, affiliations, cryptocurrency wallets, and blockchain data. If you have ever wanted to make $10 million by providing information about Russian intelligence officers to the American government, the paperwork has never been simpler.

🌿 The Gentle Awakening

There is a cosmic irony in Signal — the messaging app chosen specifically because it promises end-to-end encryption so strong that not even Signal itself can read your messages — being compromised by someone simply asking for the backup key. The cryptography is flawless. The math is unbreakable. The humans using it will paste their recovery keys into a chat window because someone pretending to be support told them to.

Signal’s actual support documentation is clear: they never request verification codes in-app and never send account verification links. But clarity has never been a match for urgency, and UNC5792 has weaponized the exact panic that security tools create. “Your account may be compromised” is the oldest trick in the phishing playbook, and it works just as well against intelligence analysts as it does against your uncle.

The fundamental paradox of encrypted backups is this: the moment you create a recovery key, you have created a single point of failure that bypasses every layer of encryption your app provides. The backup is the backdoor. The recovery key is the key. And Russian intelligence services have figured out that the easiest way through the strongest door is to politely ask the person holding the key to slide it under.

👑 The Gold-Leaf Reckoning

The FBI advisory (PSA260626) notes that creating a new recovery key invalidates the previous one for future downloads — but does nothing about backups already downloaded with the compromised key. So if your recovery key was stolen last month, your historical messages are already on a server in a building you will never visit. Not theoretically. Actually.

The $10 million bounty is the US government’s way of admitting that the technical problem was never technical. UNC5792 and UNC4221 are not exploiting code. They are exploiting trust. And trust is not something you can patch on Tuesday.

This campaign is the clearest possible demonstration that the security industry’s obsession with cryptographic strength has always missed the point. You can build a door out of titanium and secure it with a lock that would take the sun’s remaining lifetime to brute-force. The FSB will simply knock, introduce themselves as maintenance, and ask you to hand over the key. And thousands of people did.

“The encryption was military-grade. The phishing was in fluent English. The recovery key was pasted voluntarily. This is what peak cybersecurity looks like — the door was impenetrable, so they knocked, and someone opened it.” — The Slap of Wisdom Incident Response Team, currently reviewing whether this advisory was itself a phishing test