Monday, August 3, 2026

Apps & Consumer

Signal warns of new phishing campaign targeting chat backups

Hackers are impersonating Signal support to steal user backup keys, in a campaign that could be more widespread than initially targeting specific activist groups.

Signal warns of new phishing campaign targeting chat backups

Hackers are currently running a hacking campaign that uses a malicious message to impersonate Signal support, attempting to trick users into surrendering their backup recovery keys. On Wednesday, Washington Post analyst Josh Rogin posted a screenshot of the attack, which showed a message from an impersonated account called Signal Support. The message warned the target of a sync issue, claiming that the step links the existing backup to the account and that failing to do so could result in losing access to the account and all stored data. Rogin noted that several anti-Chinese Communist Party activists received this malicious message.

While initial reports linked these phishing targets to Chinese activists, security researchers note the campaign could be more widespread. Mohammed Al-Maskati, the director at Access Now’s Digital Security Helpline—an organization investigating cyberattacks against journalists and activists—stated that two people outside of that group shared similar messages with him. Al-Maskati indicated that the hacking campaign could be more widespread and targeting other communities beyond anti-Chinese Communist Party activists, or there may be different groups of hackers using the same strategy.

The attack marks a shift from previous campaigns. Historically, attackers attempted to hijack accounts by re-registering a victim’s phone number on a new device. To prevent this, Signal offers Registration Lock, a security setting to prevent unauthorized device linking by requiring a PIN. However, hijacking an account does not grant access to past messages. To access older chats, hackers must target Secure Backups, an encrypted cloud storage feature launched last year that lets users upload account contents to Signal’s servers. Decrypting these backups requires a unique recovery key.

Signal, the encrypted messaging app, maintains that it will never reach out to users first, nor will it ask for registration codes, PINs, or recovery keys. Signal president Meredith Whittaker stated that the organization is working on mitigations and monitoring the situation. The organization publicly warned about this exact type of attack last month. Signal emphasizes that the recovery key is never shared with its servers and never leaves the user’s device. According to the organization, “Without your unique recovery key, no one (including Signal) can read, decrypt, or restore any of the data in your Secure Backup Archive.”

Why it matters

This campaign marks a tactical shift: attackers are moving beyond simple account hijacking to target encrypted backups, which contain sensitive historical data like older chats and photos.