Threats & Attacks

Signal Users Targeted in Phishing Wave Designed to Steal Account Backups

Signal Users Targeted in Phishing Wave Designed to Steal Account Backups

Attackers are running a coordinated phishing campaign against Signal users with one specific goal which includes stealing the encrypted backups that contain a target’s full message history. The campaign, confirmed by Signal and reported by TechCrunch on 28 May 2026, combines impersonation of Signal support staff with social engineering designed to extract account PINs and SMS verification codes.

Signal does not have a customer support team that contacts users proactively. Any message claiming to be from Signal Support is fraudulent. That is not a new policy but the current campaign is exploiting the fact that most users do not know it.

How the Campaign Works

The attack runs in two variants. In the first, targets receive a message from what appears to be Signal Support, requesting that they verify their account by entering an SMS code or sharing their Signal PIN. In the second, attackers compromise a contact’s account first, then use it to send the phishing message from a trusted sender. The second variant is more effective because the message arrives inside an existing conversation thread.

Signal’s own statement, reported by the BBC, described the mechanics directly, “These attacks were executed via sophisticated phishing campaigns, designed to trick users into sharing information, SMS codes and/or Signal PIN, to gain access to users’ accounts.”

The PIN is the critical target. Signal’s registration lock feature ties account access to the PIN. An attacker who obtains it along with an SMS verification code can re-register the victim’s account on a new device and pull down the encrypted backup. The message history, contacts and linked devices all transfer with it.

Malwarebytes reported on 28 May 2026 that the campaign is widespread not targeted. Attackers are running it at scale rather than selecting high-value individuals which means the risk is not limited to journalists or government officials though those groups are obvious priority targets.

Why Signal Specifically

Signal’s reputation for security is, in this context, part of the problem. Users trust it precisely because of its encryption model which creates a false sense of immunity. Encryption protects messages in transit and at rest. It does nothing against an attack that convinces the account holder to hand over their own credentials.

The BBC reported that the campaign has already been used against government officials making this more than a consumer security story. Organisations that adopted Signal for internal communications on the assumption that the app itself is the security control need to reconsider that assumption. The app is sound. The people using it remain the attack surface.

I have seen a wave of vendor-issued advisories this month framing this as a uniquely sophisticated threat. It is not. It is a phishing campaign. The sophistication lies in choosing a target population that believes it is already protected.

Registration Lock and Linked Devices

Signal’s support documentation, updated in response to this campaign, sets out the controls that block this attack.

Enable registration lock now if you have not already. It is found under Settings, then Account. Once enabled, any attempt to re-register your number on a new device requires the PIN. Without it, registration fails. This is the single most effective control against this specific campaign.

Review your linked devices list under Settings, then Linked Devices. Remove anything you do not recognise. If an attacker has already obtained access, an unfamiliar linked device entry is often the first visible sign.

Do not share your PIN with anyone. Signal will never ask for it. Neither will anyone from your contacts’ list with a legitimate reason. If a message requests it, regardless of who appears to have sent it, treat that as a compromised account at the other end.

References

  1. Hackers Are Trying to Steal Signal Users’ Backups in New Wave of Phishing Attacks
  2. Signal Issues Scam Warning to Users after Hackers Target Officials
  3. Signal Users Targeted in Backup-Stealing Phishing Attacks
  4. Staying Safe from Phishing, Scams and Impersonation
  5. Phishing attempts on Signal: How They Work and How to Protect Yourself

This post is also available in: Svenska

Per Häggdahl

Per Häggdahl is Head of Business Unit and CISO at eBuilder Security, with more than 20 years securing systems for banks, central banks, stock exchanges and central securities depositories, now leading the team that brings that same enterprise-grade protection to organisations of every size.