Signal 'Secure Backups' Recovery-Key Phishing — Coordinated Campaign Impersonating Signal Support to Steal Backup Recovery Keys from Journalists, Dissidents & Activists (2026)

Signal 'Secure Backups' Recovery-Key Phishing (TL-2026-0637), also tracked as Signal Secure Backups Recovery-Key Phishing, is a high-severity phishing campaign, first published 2026-06-01. It has no confirmed attribution, affects Signal Foundation Signal Private Messenger (Secure Backups feature), maps to 8 MITRE ATT&CK techniques (T1098, T1530, T1566), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-0637

Threat ID
TL-2026-0637
Also known as
Signal Secure Backups Recovery-Key Phishing, Signal Support Impersonation Campaign, Signal Backup-Stealing Phishing Wave
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-06-01
Last reviewed
2026-06-01
Attribution confidence
NONE
Motivation
ESPIONAGE
Target sectors
media, journalism, civil-society, human-rights, ngo, political-dissidents, activism
Target regions
Global, North America, Asia, Europe
Detection rules
9
Indicators of compromise
12

A coordinated social-engineering campaign impersonates 'Signal Support' to trick high-risk users into disclosing the 64-character recovery key that protects Signal Secure Backups. Combined with secondary account/device access, the stolen key lets attackers download and decrypt the victim's entire encrypted message history from Signal's servers. Access Now's Digital Security Helpline confirmed journalists, dissidents, and activists — including anti-CCP activists — are being disproportionately targeted.

How Signal 'Secure Backups' Recovery-Key Phishing works

In late May 2026 a coordinated phishing campaign began targeting Signal users with messages impersonating 'Signal Support.' The lure claims the victim's account data is 'at risk of permanent loss due to a sync issue' and instructs the victim to retrieve their 64-character Signal recovery key from the app and paste it into the chat to 'resolve' the problem. The campaign was first publicly flagged on 2026-05-27 by Washington Post analyst Josh Rogin, who posted a screenshot on X/Twitter and noted that many anti-CCP activists had received the message. Access Now's Digital Security Helpline — which investigates cyberattacks against journalists, dissidents, and human-rights activists — independently confirmed the targeting; its director Mohammed Al-Maskati reported that two separate victims submitted near-identical phishing messages, indicating a coordinated operation rather than opportunistic spam, and that targets were not exclusively Chinese activists, suggesting the campaign may be more widespread.

The asset at risk is Signal Secure Backups, a zero-knowledge backup system that stores doubly-encrypted message archives on Signal's servers. Backups are encrypted end-to-end and then again with a backup-specific key, with padding added to obscure file sizes and prevent metadata correlation. The 64-character recovery key is generated on-device, is the sole credential capable of unlocking the backup, and — by design — never leaves the device and is never transmitted to Signal's servers. Because the key is the only thing that can decrypt the archive, its disclosure is catastrophic.

The attack is a two-step compromise chain. Step one is the recovery-key theft via the impersonation phish. Step two, per Malwarebytes, requires the attacker to also gain access to the victim's Signal account (e.g., by linking a secondary/attacker-controlled device). With both the recovery key and account/device access, the attacker can download and decrypt the full message history — not just future messages, but everything stored in the backup. Malwarebytes characterizes obtaining the key as 'a critical first move in a chain that can lead to total account compromise,' and notes this is even more damaging than a simple account hijack (which would only yield future messages). View-once messages and messages set to disappear within 24 hours are excluded from backups and therefore not exposed.

Signal has publicly responded. President Meredith Whittaker stated the team is 'working on mitigations here, and monitoring.' Signal's standing guidance is unambiguous: Signal will never proactively reach out to users first and will never request registration codes, PINs, or recovery keys. The in-app phishing messages also surface a 'Name not verified' label beneath the unknown sender, a key user-visible red flag. No IOCs (IPs, domains, file hashes, or attacker account identifiers) and no threat-actor attribution have been published in the source reporting. The strong skew toward journalists, dissidents, and anti-CCP activists is consistent with an espionage/surveillance-motivated operator, but no formal attribution exists; attribution confidence is LOW.

MITRE ATT&CK techniques used in TL-2026-0637

Persistence

T1098 Account Manipulation

Collection

T1530 Data from Cloud Storage

Initial Access

T1566 Phishing

Exfiltration

T1567 Exfiltration Over Web Service

Reconnaissance

T1589 Gather Victim Identity Information; T1598 Phishing for Information

Credential Access

T1606 Forge Web Credentials

Defense Evasion

T1684.001 Impersonation

Affected products and versions in Signal 'Secure Backups' Recovery-Key Phishing

  • Signal Foundation — Signal Private Messenger (Secure Backups feature)
    Vulnerable versions: All versions with Secure Backups enabled (Android, iOS, Desktop)
    Fixed in: N/A — social-engineering campaign, no software fix; mitigations and user awareness

Remediation for Signal 'Secure Backups' Recovery-Key Phishing

Immediate actions

  • Never share your Signal recovery key, PIN, or registration code with anyone — Signal never asks for them and never messages users first
  • Treat any inbound message claiming to be 'Signal Support' as fraudulent; verify the 'Name not verified' label under unknown senders
  • If you already pasted your recovery key, immediately rotate/regenerate the backup recovery key and review linked devices in Signal Settings > Linked Devices, removing any unrecognized device
  • Enable Registration Lock (Settings > Account > Registration Lock) to block attacker re-registration/relinking of your number

Workarounds

  • Consider not enabling Secure Backups, or disabling it, if the threat model does not justify server-side archive storage
  • Disable message preview and restrict who can message you to reduce unsolicited contact

Longer-term hardening

  • Enable device-change and linked-device alerts and review linked devices periodically
  • Use disappearing messages by default to minimize the volume of history retained in any backup
  • Store recovery keys/PINs only in a reputable password manager, never in plaintext or in any chat
  • For high-risk users (journalists, activists, dissidents), conduct periodic security checkups with organizations such as Access Now's Digital Security Helpline

Weaknesses (CWE) in Signal 'Secure Backups' Recovery-Key Phishing

CWE-1391, CWE-522

Timeline of Signal 'Secure Backups' Recovery-Key Phishing

  • Signal launches Secure Backups: zero-knowledge, doubly-encrypted message archives stored on Signal servers, unlockable only by an on-device 64-character recovery key that never leaves the device.
  • Washington Post analyst Josh Rogin posts a screenshot on X/Twitter flagging the in-app phishing message and noting many anti-CCP activists received it.
  • Signal President Meredith Whittaker states the team is 'working on mitigations here, and monitoring.'
  • TechCrunch reports the campaign; Access Now Digital Security Helpline director Mohammed Al-Maskati confirms two victims submitted near-identical messages and that targeting is not exclusively Chinese activists.
  • Malwarebytes publishes technical analysis detailing the verbatim lure, the two-step recovery-key + account-access chain, and defensive guidance (registration lock, linked-device review).
  • Security Affairs and additional outlets corroborate the coordinated targeting of journalists, dissidents, and activists.
  • Cyber Security News reports an ongoing 'new wave' of attacks; campaign assessed ACTIVE with no published IOCs or attribution.

Sources cited for Signal 'Secure Backups' Recovery-Key Phishing

More in phishing

Detection coverage for TL-2026-0637

As of 2026-06-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0637 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats