U.S. Offers $10 Million Reward To Identify UNC5792 Russian Hackers Targeting Signal And WhatsApp
Image: Zamin.uz

U.S. Offers $10 Million Reward To Identify UNC5792 Russian Hackers Targeting Signal And WhatsApp

28 May, 2026.USA.23 sources

The story in 15 seconds

  • Rewards up to $10 million under RFJ to identify or locate UNC5792/UNC4221 Russian hackers.
  • Groups UNC5792 and UNC4221 target Signal and WhatsApp accounts of US officials, journalists, and others.
  • The operation has been active since at least March; FBI advisory warns of phishing campaigns.

The divide · 1 of 3

What Signal safety prevents, and how backups defeat it.

Some stress Signal blocks history reads; others stress key theft enables archive access.

Who skipped what

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Source Diversity
23 sources
Other
11
Western Mainstream
5
Asian
4
Western Alternative
3

Western Alternative

Amnesty International
Amnesty International

Amenazas de vigilancia digital para 2020

28 May, 2026

Read the original →
Blockonomi
Blockonomi

FBI Issues Urgent Warning as Russian Hackers Target Signal Users and Compromise Thousands of American Accounts

21 March, 2026

Read the original →
Washington Examiner
Washington Examiner

Patel warns of cyber actors connected to Russian intelligence scamming Signal users

21 March, 2026

Read the original →

Western Mainstream

Ars Technica
Ars Technica

US offers $10 million for info on group behind Signal and WhatsApp hacking spree

29 June, 2026

Read the original →
Le Parisien
Le Parisien

Watch out for the voicemail scam, a fraud that is becoming increasingly hard to detect.

28 May, 2026

Read the original →
New York Post
New York Post

Russian hackers targeting US officials and journalists on Signal – have accessed ‘thousands’ of accounts, FBI warns

21 March, 2026

Read the original →
TechCrunch
TechCrunch

Hackers are trying to steal Signal users’ backups in new wave of phishing attacks

28 May, 2026

Read the original →
TF1 Info
TF1 Info

WhatsApp: beware of messages that promise easy money, between €10 and €350 per day.

29 June, 2026

Read the original →

Other

Bleeping Computer
Bleeping Computer

FBI links Signal phishing attacks to Russian intelligence services

20 March, 2026

Read the original →
BleepingComputer
BleepingComputer

U.S. offers $10 million for hackers targeting WhatsApp, Signal users

29 June, 2026

Read the original →
Corrientes Te Informa
Corrientes Te Informa

International: FBI Alert: Russian Hackers Target Messaging Accounts Worldwide.

21 March, 2026

Read the original →
CyberInsider
CyberInsider

US offers $10 million for info on Russian hackers targeting Signal accounts

29 June, 2026

Read the original →
GovInfoSecurity
GovInfoSecurity

Russian Threat Actors Continue Signal and WhatsApp Targeting

29 June, 2026

Read the original →
Korben
Korben

Russian spies on Signal - $10 million to unmask them

29 June, 2026

Read the original →
KRNV
KRNV

Russian-linked hackers phishing Signal users, other apps to hijack accounts, FBI warns

20 March, 2026

Read the original →
Security Affairs
Security Affairs

U.S. Targets Russian Cyber Spies With $10M Bounty Over Messaging App Attacks

29 June, 2026

Read the original →
SecurityWeek
SecurityWeek

US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve

29 June, 2026

Read the original →
The Record from Recorded Future News
The Record from Recorded Future News

US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp

29 June, 2026

Read the original →
Zamin.uz
Zamin.uz

Hackers are attempting to steal Signal users' backup copies.

28 May, 2026

Read the original →

Asian

Devdiscourse
Devdiscourse

Russian Hackers Exploit Messaging Apps to Target High-Value Individuals

20 March, 2026

Read the original →
NewsBytes
NewsBytes

Russian hackers targeting US officials on Signal, says FBI

21 March, 2026

Read the original →
The Straits Times
The Straits Times

Cyber actors linked to Russia targeting users of messaging apps, FBI says

21 March, 2026

Read the original →
The Times of India
The Times of India

Russian hackers target US officials, military personnel, and journalists on Signal, thousands of accounts compromised: FBI

21 March, 2026

Read the original →

Full story

$10M Bounty for UNC5792

The U.S. Department of State announced a reward of up to $10 million for information leading to the identification or location of members of UNC5792, a Russian state-linked hacking group accused of targeting Signal and WhatsApp accounts belonging to U.S. government officials, military personnel, journalists, and other high-value individuals.

The announcement says the campaign has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims' encrypted message archives in addition to taking over their accounts.

Image from Amnesty International
Amnesty InternationalAmnesty International

The FBI and CISA said Russian intelligence operators continue to impersonate messaging app support teams through phishing messages that request one-time verification codes, account PINs, or, more recently, Signal Backup Recovery Keys.

The State Department also linked UNC5792 to officers embedded in the Russian Federal Security Service (FSB) Border Guards and said it works alongside UNC4221, another cluster linked to Russian military intelligence.

The U.S. agencies warned that the key remains valid even if the victim creates a new Signal account using the same phone number, and that users must generate a new Backup Recovery Key in Signal's settings to invalidate a stolen key.

Backup Keys Replace Codes

Security Affairs reported that the U.S. government is offering rewards of up to $10 million for information on individuals associated with UNC5792 and UNC4221, and said the hackers target government officials, military personnel, journalists, and political figures through phishing attacks on Signal and WhatsApp.

It quoted the U.S. government announcement that "Rewards for Justice is offering a reward of up to $10 million for information leading to the identification or location of any person" participating in malicious cyber activities against U.S. critical infrastructure.

Image from Ars Technica
Ars TechnicaArs Technica

The FBI and CISA update described in the same coverage says the operators shifted their primary objective from stealing verification codes to stealing Signal Backup Recovery Keys.

GovInfoSecurity said the FBI's cyber division warned that "The threat actors have compromised individual CMA accounts, but not the CMA's encryption or the application itself," emphasizing that the apps' encryption is not broken.

The Record from Recorded Future News added that compromised backup recovery keys can remain valid even if victims create new accounts using the same phone number, potentially allowing attackers to regain access in the future.

Who Is Targeted Next

The U.S. advisory described the campaign as targeting current and former U.S. government officials, diplomatic staff, military leaders, NATO personnel, intelligence partners, journalists covering Russia and Ukraine, NGOs supporting Ukraine, and academic researchers focused on Russian affairs.

CyberInsider said the FBI and CISA recommend treating unsolicited messages claiming to be from Signal or other messaging platform support teams as fraudulent, and urged users to never share verification codes, PINs, or Backup Recovery Keys through chat messages.

SecurityWeek said the U.S. is willing to pay up to $10 million for information leading to the identification of UNC5792 actors, including their names, location, and biographies, and it seeks details on affiliation with Russian intelligence services and supporting entities.

GovInfoSecurity reported that the attackers are continuing to try and socially engineer high-value people in multiple jurisdictions, including in the United States, Ukraine, Australia and Europe.

The U.S. Department of State said the purpose of the hacks is to gain access to sensitive military, political and economic information exchanged by users, as well as to steal their personal data.

The deep audit

How victims, perpetrators and terms are handled across outlets.

More on USA