
In an unexpected turn of events, security researcher Donncha Ó Cearbhaill found himself on the receiving end of a hacking attempt earlier this year. As a prominent investigator of spyware attacks, he was alarmed to receive a message on his Signal account claiming to be from Signal Security Support ChatBot. The message warned him of suspicious activity on his device and instructed him to verify his account by entering a code, emphasizing that he should not share it with anyone, not even Signal employees. Recognizing this as a phishing attempt, Ó Cearbhaill, who leads Amnesty International’s Security Lab, decided to turn the situation into an investigation of his own. He shared with TechCrunch that he had never been the direct target of such a cyberattack before. "The opportunity to understand the attackers and their methods was too intriguing to ignore," he remarked. The attempted breach was not an isolated incident but part of a broader hacking campaign that appeared to be targeting a significant number of Signal users. The hackers employed tactics such as impersonating Signal and fabricating security threats, aiming to trick users into granting access to their accounts through devices they controlled. This approach mirrors tactics previously highlighted by various cybersecurity agencies, including CISA and counterparts in the UK and the Netherlands, who attributed these attacks to Russian state-sponsored hackers. Reports from German news outlet Der Spiegel corroborated these findings, revealing that Russian hackers had successfully compromised several individuals in Germany, including notable politicians. Ó Cearbhaill later confirmed that he was among over 13,500 identified targets in this campaign. Although he withheld specific details of his investigation to protect his methods, he noted that he discovered other victims included journalists he had collaborated with, suggesting that the attack might have stemmed from shared connections. He described the attack pattern as a “snowball hypothesis,” theorizing that hackers may have identified new targets through compromises in group chats. Additionally, Ó Cearbhaill identified the hacking system known as “ApocalypseZ,” which automates mass attacks with minimal human involvement. He observed that the interface was in Russian and that the hackers were translating victim conversations into Russian, reinforcing the connection to a Russian government-backed operation. Ó Cearbhaill continues to monitor the situation and has reported that attacks persist, indicating that the actual number of affected individuals is likely much greater than those initially observed. He expressed skepticism that the hackers would target him again, humorously noting that they might regret their initial attempt. He advised Signal users to enhance their security by enabling the Registration Lock feature, which allows them to set a PIN that prevents unauthorized registration of their phone numbers on other devices.
This past week has been challenging for the stock market, driven by several significant forces that have created turbule...
CNBC | Jul 25, 2026, 20:05
As the demand for expertise in artificial intelligence surges, many are seeking ways to break into this dynamic field. H...
Business Insider | Jul 26, 2026, 10:10Have you noticed an unusual trend where people are wrapping their wallets in aluminum foil? This peculiar practice has e...
Business Today | Jul 25, 2026, 02:45
Elon Musk's tunneling enterprise, The Boring Company, is reportedly negotiating a substantial funding round of $4 billio...
TechCrunch | Jul 25, 2026, 19:50
In recent discussions, a once-obscure topic in artificial intelligence has surged to the forefront of debates among tech...
CNBC | Jul 25, 2026, 12:15