Russian intelligence services have reportedly launched an extensive phishing using fake SMS messages to steal the credentials of messaging accounts belonging to officials, military personnel, politicians and activists in Ukraine, Europe and the US. The Security Service of Ukraine (SSU/SBU) and the FBI have jointly uncovered this systematic cyberespionage operation, which aims to extract sensitive military, political and economic information.

According to the SSU, the attackers are sending SMS messages that mimic the official support bot of the messaging apps, pressuring users to reveal their credentials. The campaign is not limited to organizations and public figures, but also extends to personal accounts of ordinary Ukrainian citizens, revealing the systematic nature of the Russian cyberattack.
Similar attacks on Signal and WhatsApp have been attributed to Russian threat groups tracked as Star Blizzard, UNC5792 (also known as UAC-0195), and UNC4221 (also known as UAC-0185).
See also: FBI: Russian hackers target Signal and WhatsApp accounts
Russian Secret Services: The New Backup Recovery Key Tactic
The new discovery comes around the same time as the FBI and CISA have identified a new sophisticated tactic. According to US agencies, Russian intelligence agencies are no longer content with stealing SMS or PIN codes; they are now instructing victims to activate Signal backups , open the Backup Recovery Key and paste it into the conversation. Once this key is obtained, attackers can fully restore message backups, read private and group conversations and take full control of the account. The key remains valid even if the victim creates a new account with the same phone number.
See also: Netherlands: Russian hackers breach Signal, WhatsApp accounts of officials
Russian Secret Services: How to Protect Yourself
The impact of this campaign is particularly serious, as it is part of a broader context of hybrid warfare . According to data, over 150 incidents of hybrid warfare have been recorded in EU and NATO countries , while physical sabotage has quadrupled since 2024. Groups such as Sandworm and associated clusters ( KAMACITE , ELECTRUM ) demonstrate a high level of sophisticated action, moving from IT to OT systems, while hacktivist groups such as Z-Alliance have turned to destructive attacks against industrial infrastructure.

To combat these threats, authorities recommend a number of cyber hygiene. First, treat any in-app “support” messages as hostile — real support never asks for passwords or keys. Second, regularly check active sessions and connected devices in app settings and disconnect unknown connections immediately. Third, enable two-factor authentication (2FA) and use complex PINs and passwords.
See also: PLUGGYAPE malware targets Ukraine via Signal & WhatsApp
Additionally, in case you have revealed a Backup Recovery Key, you should immediately create a new key from the settings to invalidate the old one for future backups. Avoid scanning QR codes from unknown sources, clicking on suspicious links even from known contacts, and opening files from strangers. Organizations should treat cybersecurity as a business function to stay one step ahead of evolving identity theft attacks. According to The Hacker News, this campaign is a reminder that even the most secure encryption applications can be compromised when the human factor is the weak link.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
