A new wave of phishing attacks has emerged, specifically targeting users of the Signal messaging app, according to reports from TechCrunch. Recently, Washington Post analyst Josh Rogin shared a screenshot illustrating a deceptive tactic employed by hackers. These fraudsters pose as members of Signal's support team, alerting users that their chat backups are at risk of being permanently lost due to a supposed synchronization issue. To prevent this loss, victims are coerced into sharing their recovery key, which is essential for accessing their online backups. The message, reportedly originating from an account claiming to be "Signal Support," warns users that failing to comply might lead to losing not just their account, but all their stored data. This is a classic phishing attempt, and users are strongly advised not to follow any instructions from such messages. Rogin noted that several activists opposing the Chinese Communist Party have received these malicious communications, which raises concerns about the broader implications of this phishing campaign. Mohammed Al-Maskati, director at Access Now’s Digital Security Helpline, confirmed that two individuals shared similar phishing messages with him, indicating that the attack may not be limited to one demographic but could potentially impact a wider range of users. The effectiveness of this hacking campaign remains uncertain. Al-Maskati emphasized that obtaining the recovery keys is merely one step in the attack process; hackers still need to gain control of the victim's account. This type of attack hinges on tricking individuals into divulging sensitive information, relying heavily on the trust users place in Signal as a secure platform. It’s crucial to highlight that Signal has stated it will never initiate contact with users or request sensitive information such as registration codes, PINs, or recovery keys. Any message that appears to come from "Signal Support" is likely from malicious actors. The organization had already issued warnings about similar attacks last month. In previous campaigns, hackers focused on hijacking accounts to impersonate users, aiming to steal contacts or initiate conversations as if they were the account owner. In contrast, this latest approach specifically targets backups, which can include older chats, photos, and documents. Accessing past messages through a compromised account is not feasible due to the design of the Signal app. Signal has introduced security features like Registration Lock to protect against account takeovers. This feature requires the PIN to link a phone number to a new device, thus safeguarding against unauthorized access. Users have been encouraged to securely store their recovery keys, which are vital for restoring data from Signal's encrypted servers. Signal emphasizes that without the unique recovery key, no one—including the company itself—can decrypt or access the data in a user’s Secure Backup Archive. As the landscape of cyber threats evolves, users must remain vigilant and informed. Those who suspect they have been targeted are encouraged to reach out through secure channels for further assistance.
In a lively library setting in South Philadelphia, Charlie Bailey, a local librarian, humorously noted, "Everybody’s on ...
TechCrunch | Jul 25, 2026, 16:20
Kalshi, the prediction market platform, has taken significant legal steps against Netflix, sending a cease-and-desist le...
TechCrunch | Jul 25, 2026, 17:10
In recent years, the AI sector has been intensely focused on identifying the most advanced models. While this pursuit re...
Business Insider | Jul 25, 2026, 13:10A power line failure near Washington, DC, recently showcased a significant challenge faced by the electrical grid due to...
TechCrunch | Jul 25, 2026, 13:50
As the demand for expertise in artificial intelligence surges, many are seeking ways to break into this dynamic field. H...
Business Insider | Jul 26, 2026, 10:10