Signal 'Secure Backups' Recovery-Key Phishing — Coordinated Campaign Impersonating Signal Support to Steal Backup Recovery Keys from Journalists, Dissidents & Activists (2026) — Threadlinqs Intelligence
As of 2026-06-01, Signal 'Secure Backups' Recovery-Key Phishing — Coordinated Campaign Impersonating Signal Support to Steal Backup Recovery Keys from Journalists, Dissidents & Activists (2026) is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 12 indicators of compromise.
Threat ID: TL-2026-0637 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
A coordinated social-engineering campaign impersonates 'Signal Support' to trick high-risk users into disclosing the 64-character recovery key that protects Signal Secure Backups. Combined with
In late May 2026 a coordinated phishing campaign began targeting Signal users with messages impersonating 'Signal Support.' The lure claims the victim's account data is 'at risk of permanent loss due to a sync issue' and instructs the victim to retrieve their 64-character Signal recovery key from the app and paste it into the chat to 'resolve' the problem. The campaign was first publicly flagged on 2026-05-27 by Washington Post analyst Josh Rogin, who posted a screenshot on X/Twitter and noted that many anti-CCP activists had received the message. Access Now's Digital Security Helpline — which investigates cyberattacks against journalists, dissidents, and human-rights activists — independently confirmed the targeting; its director Mohammed Al-Maskati reported that two separate victims submitted near-identical phishing messages, indicating a coordinated operation rather than opportunistic spam, and that targets were not exclusively Chinese activists, suggesting the campaign may be more widespread.
The asset at risk is Signal Secure Backups, a zero-knowledge backup system that stores doubly-encrypted message archives on Signal's servers. Backups are encrypted end-to-end and then again with a backup-specific key, with padding added to obscure file sizes and prevent metadata correlation. The 64-character recovery key is generated on-device, is the sole credential capable of unlocking the backup, and — by design — never leaves the device and is never transmitted to Signal's servers. Because the key is the only thing that can decrypt the archive, its disclosure is catastrophic.
The attack is a two-step compromise chain. Step one is the recovery-key theft via the impersonation phish. Step two, per Malwarebytes, requires the attacker to also gain access to the victim's Signal account (e.g., by linking a secondary/attacker-controlled device). With both the recovery key and account/device access, the attacker can download and decrypt the full message history — not just future messages, but everything stored in the backup. Malwarebytes characterizes obtaining the key as 'a critical first move in a chain that can lead to total account compromise,' and notes this is even more damaging than a simple account hijack (which would only yield future messages). View-once messages and messages set to disappear within 24 hours are excluded from backups and therefore not exposed.
Signal has publicly responded. President Meredith Whittaker stated the team is 'working on mitigations here, and monitoring.' Signal's standing guidance is unambiguous: Signal will never proactively reach out to users first and will never request registration codes, PINs, or recovery keys. The in-app phishing messages also surface a 'Name not verified' label beneath the unknown sender, a key user-visible red flag. No IOCs (IPs, domains, file hashes, or attacker account identifiers) and no threat-actor attribution have been published in the source reporting. The strong skew toward journalists, dissidents, and anti-CCP activists is consistent with an espionage/surveillance-motivated operator, but no formal attribution exists; attribution confidence is LOW.
Weaknesses (CWE)
CWE-1391, CWE-522
Target sectors: media, journalism, civil-society, human-rights, ngo, political-dissidents, activism
Target regions: Global, North America, Asia, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 12 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1598, T1566, T1656, T1098, T1606, T1530, T1567