UNC5792 , a cyber espionage group affiliated with the Russian Federal Security Service (FSB), and UNC4221 , which is linked to Russian military services, are being targeted by US authorities, who are offering a $10 million reward for information leading to the identification of their members.

The two groups have targeted current and former U.S. government officials, military leaders, coalition personnel, journalists, politicians, and key officials in Ukraine. This campaign was jointly uncovered by the Security Service of Ukraine (SSU) and the FBI in June 2026.
At the same time, CISA and the FBI issued an updated warning about sophisticated phishing by Russian groups targeting messaging apps like Signal and WhatsApp, with a new tactic of stealing Backup Recovery Keys.
See also: FBI: Russian hackers target Signal and WhatsApp accounts
The campaign began with an initial warning in March 2026 , when attackers were primarily using fake one-time verification codes to gain access to accounts. The new, sophisticated tactic focuses on stealing Signal Backup Recovery Keys — a key that provides permanent access to an account’s entire message history, even if the user changes devices or creates a new account with the same phone number .
UNC5792 – UNC4221: How the Signal phishing attack works
The attack method of UNC5792 and UNC4221 relies solely on social engineering . The attackers impersonate messaging app support accounts, sending SMS or in-app messages asking victims to click on a link or share verification codes. In more recent variants, they directly request Signal ’s Backup Recovery Key . Additionally, the use of QR codes to link attackers’ devices to victims’ accounts via Signal’s legitimate “linked devices” feature has been documented by the Google Threat Intelligence Group

The critical element of this tactic is the permanence of the access gained. As CISA and the FBI point out: “If a victim accidentally shares their Backup Recovery Key, the same key remains valid even if they create a new account with the same phone number. As a result, the attacker could potentially use the compromised key to take control of the new account in the future.” This means that simply changing the account is not enough to eliminate the attacker. The compromised accounts were also used to attacks phishing against other high-value targets, and in some cases, “group invite” pages were modified to connect the attackers’ devices to Signal accounts.
See also: Netherlands: Russian hackers breach Signal, WhatsApp accounts of officials
What users should do to protect themselves
CISA and the FBI emphasize that the attack does not breach Signal or WhatsApp ’s encryption — it solely exploits users’ trust in the app’s interface and legitimate features. This means that user awareness is the most critical line of defense. To counter the threat, authorities recommend: Treat any in-app “support” messages as hostile, as real support staff never communicate in-app to request passwords or keys. Also, never share your Backup Recovery Key , verification code, or PIN in any chat.
Additionally, it is recommended that you regularly check your Signal Settings for “Linked Devices” and immediately remove any unknown devices. If you suspect that you have shared your Recovery Key, immediately create a new one from Settings — this invalidates the old key. However, it does not save data that attackers may already have backed up. Finally, avoid scanning QR codes from unknown sources and do not follow suspicious links, even from known contacts, as their accounts may already be compromised.
See also: Hackers target Windows users via WhatsApp
The $10 million reflects the seriousness of the threat and the high value of the information sought by US authorities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
