Phishing campaign targets Signal backup recovery keys
Malwarebytes has reported a phishing campaign targeting users of the Signal messaging application. Victims receive a message posing as Signal support, warning of permanent loss of account data due to a claimed sync issue unless they act within a short deadline. The message then instructs the recipient to locate their backup recovery key and paste it as a reply in the chat. If the secure backups option is in use, an attacker with access to the account could restore and decrypt previous communications. So far the targets have been journalists, dissidents and human rights activists.
What this means for your organisation
The attack sidesteps encryption by asking the user for the key directly, and the technique is easy to replicate against other services and other audiences. Organisations using Signal or similar tools for sensitive dialogue should expect the same pattern to appear against executives and key personnel. Time pressure and the threat of data loss are the classic levers, and they work as well in a messaging app as in email.
Berigo recommends
- Make it explicit internally that recovery keys and one-time codes are never to be shared, whoever asks.
- Remind staff that providers do not contact users in-app to request key material.
- Establish a simple channel for reporting suspicious approaches, including outside email.
- Include messaging apps in security training for executives and other exposed roles.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch