Signal users targeted in backup-stealing phishing attacks
ID: bd293197-6b22-5668-8c48-c9ca26cde99f
STIX ID: report--bd293197-6b22-5668-8c48-c9ca26cde99f
Feed Name: Malwarebytes Blog
A phishing campaign is impersonating Signal Support via SMS to coerce users into pasting their 64-character Secure Backups recovery key into a chat; attackers who obtain the key can download and decrypt full encrypted message archives. The report notes targeted incidents affecting journalists and activists, highlights red flags (e.g., 'Name not verified', threats of data loss), and advises users not to share recovery keys, to enable Signal security features, and to use Scam Guard to detect such messages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
