Skip to content

Signal / CMA Account Takeover — Russian Intelligence Services

Signal / CMA Account Takeover — Russian Intelligence Services

Section titled “Signal / CMA Account Takeover — Russian Intelligence Services”

Source: FBI/CISA Public Service Announcement I-032026-PSA, 20 March 2026. Original advisory: ic3.gov/PSA/2026/PSA260320

FieldValue
Threat actorCyber actors associated with the Russian Intelligence Services (RIS)
Target populationCurrent/former U.S. government officials, military personnel, political figures, journalists, and anyone of “high intelligence value”
Primary platformSignal (confirmed). Same TTPs apply to WhatsApp, Telegram, and other commercial messaging applications (CMAs)
Scale”Thousands” of individual CMA accounts compromised globally
What is NOT compromisedThe messaging apps themselves, their infrastructure, or their end-to-end encryption — only individual user accounts. The phishing bypasses encryption by gaining account access in the first place.
First reportedMarch 2026
StatusOngoing

The campaign uses two related techniques. Both start with the actor identifying a high-value target, then impersonating either a known contact or “official support.” The phishing message is delivered through the CMA itself, which makes it feel native and trustworthy.

Signal — like Matrix, WhatsApp, and Telegram — supports linking additional devices to a single account via a QR code. Once a device is linked, it receives all messages, contacts, and group access silently and in parallel with the legitimate device.

flowchart TD
    A[Actors identify target] --> B[Impersonate a contact of the victim]
    B --> C[Send malicious link or QR code]
    C --> D[Victim clicks link / scans QR]
    D --> E[Actors' device is linked to victim's account]
    E --> F[Victim retains access<br/><strong>Actors ALSO have access</strong><br/>Read all messages, see contacts, join groups]
    style F fill:#fee,stroke:#900,stroke-width:2px

Why it works: QR-based device linking is the normal flow Signal uses for legitimate desktop pairing. The victim sees a familiar UI and believes they are pairing their own laptop. The attacker’s device is now a permanent linked client until manually revoked.

Detection lag: The victim sees no immediate symptom. The compromise can persist for weeks or months until the victim either notices the linked device in settings or a contact reports anomalous messages.

Scheme 2: Account Takeover via 2FA/PIN Phishing

Section titled “Scheme 2: Account Takeover via 2FA/PIN Phishing”
flowchart TD
    A[Actors identify target] --> B[Send phishing message<br/>posing as Signal Security/Support]
    B --> C[Request: verification code,<br/>PIN, or 2FA token]
    C --> D[Victim supplies the code]
    D --> E[Actors register victim's number<br/>on their own device]
    E --> F[<strong>Victim LOSES access</strong><br/>Actors have sole control of account]
    style F fill:#fee,stroke:#900,stroke-width:2px

Why it works: The lure arrives in-app from what appears to be a “Signal Security Support ChatBot.” Real Signal verification codes are arriving on the victim’s phone at the same moment — because the attacker is actively trying to register the victim’s number on a new device. The timing makes the lure feel timely and legitimate.

Detection lag: Near-zero. The victim usually notices within minutes (their Signal stops working). But by then, the attacker has full access and the victim has none.

The FBI/CISA PSA published five sample messages used in the campaign. The exact wording matters because these patterns can be used directly for awareness training:

“Dear user, this is Signal Security support ChatBot. We have noticed suspicious activity on your device, which could have led to data leak. We have also detected attempts to gain access to your private data on Signal. To prevent this, you have to pass verification procedure, entering the verification code to Signal Security Support Chatbot. Don’t tell anyone the code. Not even Signal employees.”

“Our system has detected a recent login attempt to your account from an unrecognized device or location. As a security measure, we have blocked this attempt and sent a verification code via SMS to your registered phone number. If this was NOT you: To secure your account and block this unauthorized access please reply to this message with the verification code you just received. If this WAS you: You can safely ignore this message.”

“Dear user, We noticed suspicious activity on your device, which have led to data leak. We have also detected attempts to gain access to your private data in Signal. To prevent this, we ask you to pass verification procedure, which will take less than a minute. Please let us know as soon as you are ready. Best regards, Signal support”

“Signal Security Team — Recently, attempts to hack users of our messenger with the connection of third-party devices to the account have become more frequent. In this regard, Signal updates Terms of Service & Privacy Policy and introduces Mandatory Two-factor Verification for users. Stay safe and thank you for using the most secure messenger with end-to-end encryption.”

“Dear user, this is Signal Security Support Chatbot. Another Samsung Galaxy S 10 device is connected to your account. Location: Drohobych, Lvivska oblast, Ukraine - IP: 178.212.97.211. If it were not you, send: /Cancel”

  • Pose as an official “Signal Security,” “Signal Support,” or “ChatBot”no such entity exists in-app. Signal does not message users.
  • Manufactured urgency: “suspicious activity,” “data leak,” “unauthorized access detected”
  • Request the user reply with a code or type a command (e.g., /Cancel)
  • Cite plausible-sounding geographic detail (Ukrainian city, IP address, device model) to feel evidentiary
  • Vague “data leak” framing that bypasses technical literacy
  • Mention of a “Mandatory Two-factor Verification” or “updated Terms of Service” that does not exist as Signal policy
  • Instruct the victim not to verify out-of-band (“don’t tell anyone, not even Signal employees”)

Check each of these. Any one is a strong signal; multiple is conclusive:

  • An unfamiliar device appears in Signal → Settings → Linked Devices
  • Messages you didn’t send appear in “Sent” or in your contacts’ replies
  • A contact reports receiving requests from “you” that you didn’t send
  • Login alerts or “linked device” notifications for sessions you didn’t initiate
  • Sudden loss of access to your own account (“registered on another device”)
  • A previously-trusted contact’s account begins exhibiting the above patterns — they may have been compromised and are now being used to phish you and others in their network
  • New participants in group chats that no admin added
  • Outbound DMs to your contacts containing the same lure messages above

See the Digital Force Protection Guide for the full prevention baseline. Threat-specific actions, in priority order:

  1. Set a Signal Registration Lock PIN. Settings → Account → Signal PIN → enable Registration Lock. This blocks Scheme 2 even if the attacker has the SMS verification code — the account cannot be re-registered without the PIN.
  2. Audit Linked Devices regularly. Settings → Linked Devices. Remove anything you don’t recognize. Especially after travel, after any QR scan, or whenever you receive a “linked device” notification.
  3. Verify safety numbers with key contacts in person or via a separate trusted channel. Signal will alert you if a contact’s safety number changes — investigate every change.
  4. Never type a verification code into a chat. Real Signal codes arrive via SMS or in-app prompt. They are never requested by another user, a “support account,” or any in-app bot.
  5. Treat “Signal Security,” “Signal Support,” “Verification Bot,” or any similar in-app account as automatic phishing. No such accounts exist. The only legitimate Signal support channel is support@signal.org (email only).
  6. Audit group chat participants periodically. Look for duplicates of known contacts (a common impersonation tactic) or unknown numbers added by no one.
  7. Apply mobile hardening. Mobile Hardening Guide; prefer GrapheneOS on supported devices.
  8. Compartmentalize. Separate Signal accounts (via Twilio/MySudo numbers) for distinct threat contexts — work, OSINT research, source-handling, personal.
  9. Enable message disappearing for sensitive conversations. Limits exposure window if you are compromised later.

Threat-specific steps in order:

  1. ImmediatelySignal → Settings → Linked Devices → remove every device you don’t actively use. The attacker’s session ends the moment you revoke it.
  2. Re-register your number if you’ve lost access. If you had Registration Lock enabled, the attacker is blocked. If you didn’t, use Signal’s account recovery process.
  3. Rotate your Signal PIN and enable Registration Lock if it wasn’t already on.
  4. Notify your contacts through a different channel (phone call, Matrix, in person, email) that your Signal may have been read or impersonated by a third party. Assume any conversation since the compromise window opened was visible to the attacker.
  5. Audit recent message history for content the attacker may have exfiltrated — credentials, addresses, source identities, sensitive plans. Treat that content as burned.
  6. Verify group chats — actors may have added themselves to groups via your compromised account. Scan participant lists for duplicates or unknown numbers; revoke their access and notify other admins.
  7. Check linked accounts and recovery paths — if your Signal-registered phone number is a recovery method for other accounts (email, banking), audit those too.
  8. Report:
    • IC3 (Internet Crime Complaint Center): ic3.gov
    • Your organization’s security team / IT
    • If USG/military: your local FBI Field Office
    • If financial or identity fraud is involved: also notify local authorities

Defenders supporting at-risk populations can validate the controls above:

  • Tabletop the linked-device flow — send a controlled QR-code lure to a consenting test user; confirm they catch it before scanning. Measure click-through rate as a baseline; train and re-test.
  • Audit linked-device hygiene at scale — for organizations managing journalist/NGO Signal accounts, build a quarterly checklist that walks each user through Settings → Linked Devices.
  • Phishing recognition training — the five sample messages above are real, attributed, and have distinctive linguistic patterns. Ideal as training material because the language patterns generalize to other CMA phishing campaigns.
  • Purple team validation — pair red-team attempts to send these lures with blue-team detection (do users report? Through what channel? How long until reporting?).
  • Authorized testing: see Cyber Red Teaming for principles. Never run these patterns against people who haven’t consented.
TechniqueDescriptionUsage in this campaign
T1566.002 Phishing: Spearphishing LinkTargeted link phishingThe QR-code / linked-device lure (Scheme 1)
T1566.003 Phishing: Spearphishing via ServicePhishing via third-party serviceLures delivered through Signal itself
T1656 ImpersonationPosing as trusted entity”Signal Security Support ChatBot”
T1078 Valid AccountsUse of compromised credentialsPost-takeover account access
T1556.006 Modify Authentication Process: Multi-Factor AuthenticationMFA bypass via interception2FA / verification code phishing (Scheme 2)
T1098.005 Account Manipulation: Device RegistrationAdding actor-controlled devicesLinked Device Feature Abuse (Scheme 1)