FBI and CISA warn of Russian phishing campaigns against Signal users

The FBI and CISA have published a public service announcement about ongoing phishing campaigns run by threat actors linked to Russian intelligence. The actors target users of commercial messaging applications such as Signal, impersonating support staff or trusted contacts. The goal is to get the victim to share verification codes, click malicious links, or link a device controlled by the attacker.

What this means for your organisation

Messaging apps are used for work-related communication in many Norwegian organisations, including where they are not formally approved. When an account is taken over, the attacker gains access to message history and contact lists, and can use the account to attack colleagues and partners. Trust in the sender is the attack vector itself, which makes such approaches hard for an individual employee to dismiss.

Berigo recommends

  • Define in policy which messaging services may carry company information, and what must not be shared there.
  • Train employees never to share verification codes, regardless of who asks, and to verify device-linking requests through a separate channel.
  • Review linked devices in the messaging apps used for work and remove anything unrecognised.
  • Establish a simple, clear route for employees to report suspicious approaches without fear of being wrong.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch