FBI alerts: Russian hackers are phishing Signal & WhatsApp users in widespread attacks.
Mar 21, 2026 // 16:23 - Norina Velotta


U.S. authorities, including CISA and the FBI, have reported that Russian intelligence-linked hackers are using phishing attacks to compromise accounts on popular messaging apps like WhatsApp and Signal. Their goal is to access the accounts of high-profile individuals.

FBI Director Kash Patel stated on X that these attacks target high-value individuals like current and former U.S. government officials, military personnel, politicians, and journalists. He added that thousands of accounts globally have been accessed, allowing the attackers to read messages, view contacts, send messages as the victim, and initiate further phishing using the compromised identity.

CISA and the FBI confirmed the compromise of thousands of CMA accounts. They emphasized that the attacks target user accounts and do not exploit vulnerabilities in the messaging platforms’ encryption.

While a specific group wasn’t named by the agencies, past reports have linked these campaigns to Russia-aligned groups known as Star Blizzard, UNC5792 (aka UAC-0195), and UNC4221 (aka UAC-0185).

France’s Cyber Crisis Coordination Center (C4) also issued a warning about similar attacks targeting messaging accounts of government officials, journalists, and business executives.

C4 stated that successful attacks can give hackers access to conversation history or allow them to control the victim’s account and send messages while pretending to be them.

The ultimate objective is to infiltrate these accounts, enabling attackers to see messages and contacts, send messages as the victim, and launch additional phishing attacks by leveraging trusted relationships.

Agencies in Germany and the Netherlands recently warned that the attack involves attackers impersonating “Signal Support” to trick users into clicking links, scanning QR codes, or providing their PIN or verification code, thus compromising their account.

The outcome for the victim varies based on the method used:

  • If the victim provides the PIN or verification code, the attacker can recover the account, preventing the victim from accessing it. While past messages are inaccessible, the attacker can monitor new messages and impersonate the victim.
  • If the victim clicks a link or scans a QR code, a device controlled by the attacker is linked to the victim’s account, granting access to all messages, including past ones. The victim retains access to the account unless manually removed from app settings.

To protect themselves, users should never share their SMS code or verification PIN, be wary of suspicious messages from unknown senders, verify links before clicking, and regularly review and remove unknown linked devices.

Signal explained that these attacks rely on social engineering, with attackers impersonating trusted contacts or services (like a fake “Signal Support Bot”) to trick victims into giving up their credentials.

Signal also emphasized that their SMS verification code is only needed when initially signing up for the app and that Signal Support will never request a code or PIN via in-app messages, SMS, or social media. Any request for a Signal-related code is a scam.

#alerts  #are  #attacks  #fbi  #hackers  #news  #phishing  #russian  #signal  #users  #whatsapp  #widespread   —   News