Russian intelligence-linked hackers target Signal users, accessing thousands of accounts
Image: Washington Examiner

Russian intelligence-linked hackers target Signal users, accessing thousands of accounts

21 March, 2026.Russia.10 sources

Key Takeaways

  • Russian intelligence-linked actors conduct phishing campaigns targeting Signal users, compromising thousands of accounts already globally.
  • The FBI and CISA issued a joint advisory linking the campaigns to Russian intelligence services.
  • Targets include US officials, military personnel, journalists, and other high-value individuals globally identified by authorities.

Global Cyber Campaign

According to multiple sources, thousands of accounts have been compromised globally through this campaign.

Image from Bleeping Computer
Bleeping ComputerBleeping Computer

FBI Director Kash Patel confirmed that cyber actors associated with Russian Intelligence Services are systematically targeting individuals.

High-value targets include current and former US government officials, military personnel, political figures, and journalists.

The campaign represents a significant security breach affecting multiple countries worldwide.

Authorities report the attacks use deceptive social engineering tactics rather than technical vulnerabilities in the apps themselves.

Attack Methods

The Russian hackers employ sophisticated social engineering techniques to bypass Signal's end-to-end encryption.

They primarily impersonate automated support accounts to trick users into compromising their own security.

Image from Blockonomi
BlockonomiBlockonomi

According to cybersecurity sources, attackers send messages masquerading as legitimate app support.

These messages request targets to click links, provide verification codes, or submit account PINs.

The phishing messages are carefully crafted to appear legitimate and urgent.

This creates a chain of trust-based attacks that are difficult for recipients to detect.

Once users perform these actions, hackers achieve 'full account takeover' without breaking encryption.

Account Compromise Impact

Multiple sources confirm attackers can view private messages and contact lists.

They can send messages as the legitimate user to their contacts.

Hackers conduct further phishing campaigns using the compromised account as a trusted source.

This creates a dangerous situation where victims' communications are silently monitored.

Their social networks are used to target additional victims.

Detection becomes more difficult as the campaign amplifies across multiple countries and organizational boundaries.

International Response

The international cybersecurity community has responded with coordinated warnings from multiple countries.

Dutch intelligence agencies were among the first to warn about similar account-hijacking operations.

Image from Devdiscourse
DevdiscourseDevdiscourse

They emphasized attacks rely on tricking users rather than exploiting technical vulnerabilities.

France's Cyber Crisis Coordination Center (C4) published an alert confirming the activity is widespread.

The campaign is ongoing across multiple countries according to international authorities.

Signal itself acknowledged the campaign on March 9.

Signal reassured users that encryption and infrastructure remain robust.

The platform urged vigilance against sophisticated phishing campaigns.

Political Context

The timing of the Russian hacking campaign coincides with heightened concerns about secure communications.

Russian-linked hackers phishing Signal users, other apps to hijack accounts, FBI warns U

KRNVKRNV

Signal gained significant attention in US political circles during Trump's second term.

Image from KRNV
KRNVKRNV

Administration officials used the app to discuss potentially classified military operations.

This included air strikes against Yemen's Houthis in group chats accidentally shared with journalists.

This history makes Signal attractive for intelligence operations seeking government communications.

It highlights tension between secure messaging platforms and proper security protocols.

High-level officials handling classified information face particular security challenges.

More on Russia