Signal / CMA Account Takeover — Russian Intelligence Services
Signal / CMA Account Takeover — Russian Intelligence Services
Section titled “Signal / CMA Account Takeover — Russian Intelligence Services”Source: FBI/CISA Public Service Announcement I-032026-PSA, 20 March 2026. Original advisory: ic3.gov/PSA/2026/PSA260320
At a glance
Section titled “At a glance”| Field | Value |
|---|---|
| Threat actor | Cyber actors associated with the Russian Intelligence Services (RIS) |
| Target population | Current/former U.S. government officials, military personnel, political figures, journalists, and anyone of “high intelligence value” |
| Primary platform | Signal (confirmed). Same TTPs apply to WhatsApp, Telegram, and other commercial messaging applications (CMAs) |
| Scale | ”Thousands” of individual CMA accounts compromised globally |
| What is NOT compromised | The messaging apps themselves, their infrastructure, or their end-to-end encryption — only individual user accounts. The phishing bypasses encryption by gaining account access in the first place. |
| First reported | March 2026 |
| Status | Ongoing |
How it works — two schemes
Section titled “How it works — two schemes”The campaign uses two related techniques. Both start with the actor identifying a high-value target, then impersonating either a known contact or “official support.” The phishing message is delivered through the CMA itself, which makes it feel native and trustworthy.
Scheme 1: Linked Device Feature Abuse
Section titled “Scheme 1: Linked Device Feature Abuse”Signal — like Matrix, WhatsApp, and Telegram — supports linking additional devices to a single account via a QR code. Once a device is linked, it receives all messages, contacts, and group access silently and in parallel with the legitimate device.
flowchart TD
A[Actors identify target] --> B[Impersonate a contact of the victim]
B --> C[Send malicious link or QR code]
C --> D[Victim clicks link / scans QR]
D --> E[Actors' device is linked to victim's account]
E --> F[Victim retains access<br/><strong>Actors ALSO have access</strong><br/>Read all messages, see contacts, join groups]
style F fill:#fee,stroke:#900,stroke-width:2px
Why it works: QR-based device linking is the normal flow Signal uses for legitimate desktop pairing. The victim sees a familiar UI and believes they are pairing their own laptop. The attacker’s device is now a permanent linked client until manually revoked.
Detection lag: The victim sees no immediate symptom. The compromise can persist for weeks or months until the victim either notices the linked device in settings or a contact reports anomalous messages.
Scheme 2: Account Takeover via 2FA/PIN Phishing
Section titled “Scheme 2: Account Takeover via 2FA/PIN Phishing”flowchart TD
A[Actors identify target] --> B[Send phishing message<br/>posing as Signal Security/Support]
B --> C[Request: verification code,<br/>PIN, or 2FA token]
C --> D[Victim supplies the code]
D --> E[Actors register victim's number<br/>on their own device]
E --> F[<strong>Victim LOSES access</strong><br/>Actors have sole control of account]
style F fill:#fee,stroke:#900,stroke-width:2px
Why it works: The lure arrives in-app from what appears to be a “Signal Security Support ChatBot.” Real Signal verification codes are arriving on the victim’s phone at the same moment — because the attacker is actively trying to register the victim’s number on a new device. The timing makes the lure feel timely and legitimate.
Detection lag: Near-zero. The victim usually notices within minutes (their Signal stops working). But by then, the attacker has full access and the victim has none.
Phishing lures observed
Section titled “Phishing lures observed”The FBI/CISA PSA published five sample messages used in the campaign. The exact wording matters because these patterns can be used directly for awareness training:
“Dear user, this is Signal Security support ChatBot. We have noticed suspicious activity on your device, which could have led to data leak. We have also detected attempts to gain access to your private data on Signal. To prevent this, you have to pass verification procedure, entering the verification code to Signal Security Support Chatbot. Don’t tell anyone the code. Not even Signal employees.”
“Our system has detected a recent login attempt to your account from an unrecognized device or location. As a security measure, we have blocked this attempt and sent a verification code via SMS to your registered phone number. If this was NOT you: To secure your account and block this unauthorized access please reply to this message with the verification code you just received. If this WAS you: You can safely ignore this message.”
“Dear user, We noticed suspicious activity on your device, which have led to data leak. We have also detected attempts to gain access to your private data in Signal. To prevent this, we ask you to pass verification procedure, which will take less than a minute. Please let us know as soon as you are ready. Best regards, Signal support”
“Signal Security Team — Recently, attempts to hack users of our messenger with the connection of third-party devices to the account have become more frequent. In this regard, Signal updates Terms of Service & Privacy Policy and introduces Mandatory Two-factor Verification for users. Stay safe and thank you for using the most secure messenger with end-to-end encryption.”
“Dear user, this is Signal Security Support Chatbot. Another Samsung Galaxy S 10 device is connected to your account. Location: Drohobych, Lvivska oblast, Ukraine - IP: 178.212.97.211. If it were not you, send: /Cancel”
Red flags common to all samples
Section titled “Red flags common to all samples”- Pose as an official “Signal Security,” “Signal Support,” or “ChatBot” — no such entity exists in-app. Signal does not message users.
- Manufactured urgency: “suspicious activity,” “data leak,” “unauthorized access detected”
- Request the user reply with a code or type a command (e.g.,
/Cancel) - Cite plausible-sounding geographic detail (Ukrainian city, IP address, device model) to feel evidentiary
- Vague “data leak” framing that bypasses technical literacy
- Mention of a “Mandatory Two-factor Verification” or “updated Terms of Service” that does not exist as Signal policy
- Instruct the victim not to verify out-of-band (“don’t tell anyone, not even Signal employees”)
Indicators of compromise
Section titled “Indicators of compromise”Check each of these. Any one is a strong signal; multiple is conclusive:
- An unfamiliar device appears in
Signal → Settings → Linked Devices - Messages you didn’t send appear in “Sent” or in your contacts’ replies
- A contact reports receiving requests from “you” that you didn’t send
- Login alerts or “linked device” notifications for sessions you didn’t initiate
- Sudden loss of access to your own account (“registered on another device”)
- A previously-trusted contact’s account begins exhibiting the above patterns — they may have been compromised and are now being used to phish you and others in their network
- New participants in group chats that no admin added
- Outbound DMs to your contacts containing the same lure messages above
Prevention
Section titled “Prevention”See the Digital Force Protection Guide for the full prevention baseline. Threat-specific actions, in priority order:
- Set a Signal Registration Lock PIN.
Settings → Account → Signal PIN → enable Registration Lock. This blocks Scheme 2 even if the attacker has the SMS verification code — the account cannot be re-registered without the PIN. - Audit Linked Devices regularly.
Settings → Linked Devices. Remove anything you don’t recognize. Especially after travel, after any QR scan, or whenever you receive a “linked device” notification. - Verify safety numbers with key contacts in person or via a separate trusted channel. Signal will alert you if a contact’s safety number changes — investigate every change.
- Never type a verification code into a chat. Real Signal codes arrive via SMS or in-app prompt. They are never requested by another user, a “support account,” or any in-app bot.
- Treat “Signal Security,” “Signal Support,” “Verification Bot,” or any similar in-app account as automatic phishing. No such accounts exist. The only legitimate Signal support channel is
support@signal.org(email only). - Audit group chat participants periodically. Look for duplicates of known contacts (a common impersonation tactic) or unknown numbers added by no one.
- Apply mobile hardening. Mobile Hardening Guide; prefer GrapheneOS on supported devices.
- Compartmentalize. Separate Signal accounts (via Twilio/MySudo numbers) for distinct threat contexts — work, OSINT research, source-handling, personal.
- Enable message disappearing for sensitive conversations. Limits exposure window if you are compromised later.
If you’re compromised
Section titled “If you’re compromised”Threat-specific steps in order:
- Immediately —
Signal → Settings → Linked Devices→ remove every device you don’t actively use. The attacker’s session ends the moment you revoke it. - Re-register your number if you’ve lost access. If you had Registration Lock enabled, the attacker is blocked. If you didn’t, use Signal’s account recovery process.
- Rotate your Signal PIN and enable Registration Lock if it wasn’t already on.
- Notify your contacts through a different channel (phone call, Matrix, in person, email) that your Signal may have been read or impersonated by a third party. Assume any conversation since the compromise window opened was visible to the attacker.
- Audit recent message history for content the attacker may have exfiltrated — credentials, addresses, source identities, sensitive plans. Treat that content as burned.
- Verify group chats — actors may have added themselves to groups via your compromised account. Scan participant lists for duplicates or unknown numbers; revoke their access and notify other admins.
- Check linked accounts and recovery paths — if your Signal-registered phone number is a recovery method for other accounts (email, banking), audit those too.
- Report:
- IC3 (Internet Crime Complaint Center): ic3.gov
- Your organization’s security team / IT
- If USG/military: your local FBI Field Office
- If financial or identity fraud is involved: also notify local authorities
Detection and purple team validation
Section titled “Detection and purple team validation”Defenders supporting at-risk populations can validate the controls above:
- Tabletop the linked-device flow — send a controlled QR-code lure to a consenting test user; confirm they catch it before scanning. Measure click-through rate as a baseline; train and re-test.
- Audit linked-device hygiene at scale — for organizations managing journalist/NGO Signal accounts, build a quarterly checklist that walks each user through
Settings → Linked Devices. - Phishing recognition training — the five sample messages above are real, attributed, and have distinctive linguistic patterns. Ideal as training material because the language patterns generalize to other CMA phishing campaigns.
- Purple team validation — pair red-team attempts to send these lures with blue-team detection (do users report? Through what channel? How long until reporting?).
- Authorized testing: see Cyber Red Teaming for principles. Never run these patterns against people who haven’t consented.
MITRE ATT&CK mapping
Section titled “MITRE ATT&CK mapping”| Technique | Description | Usage in this campaign |
|---|---|---|
T1566.002 Phishing: Spearphishing Link | Targeted link phishing | The QR-code / linked-device lure (Scheme 1) |
T1566.003 Phishing: Spearphishing via Service | Phishing via third-party service | Lures delivered through Signal itself |
T1656 Impersonation | Posing as trusted entity | ”Signal Security Support ChatBot” |
T1078 Valid Accounts | Use of compromised credentials | Post-takeover account access |
T1556.006 Modify Authentication Process: Multi-Factor Authentication | MFA bypass via interception | 2FA / verification code phishing (Scheme 2) |
T1098.005 Account Manipulation: Device Registration | Adding actor-controlled devices | Linked Device Feature Abuse (Scheme 1) |
Sources
Section titled “Sources”- Primary: FBI/CISA PSA I-032026-PSA — Russian Intelligence Services Target Commercial Messaging Application Accounts (20 March 2026)
- CISA — Phishing Guidance: Stopping the Attack Cycle at Phase One
- CISA — Mobile Communications Best Practice Guidance
- FBI — Spoofing and Phishing
- Signal Support — Registration Lock
- MITRE ATT&CK Enterprise
Related
Section titled “Related”- Adversary Threats Catalog — full catalog
- Social Engineering — sibling vectors
- Digital Force Protection Guide — prevention baseline
- Cyber Incident Response Guide — full response playbook
- Mobile Hardening Guide — device-level baseline
- GrapheneOS — strongest mobile hardening
- Secure Messaging — messenger comparison
- Email Hardening Guide — parallel guidance for email accounts
- Cyber Red Teaming — authorized testing of these patterns