All incidents

US offers $10 million bounty for Russian hackers targeting Signal and WhatsApp

incidentclosedJun 26, 2026 — Jun 29, 2026
US offers $10 million bounty for Russian hackers targeting Signal and WhatsApp

THE United States has announced a reward of up to $10 million for information leading to the identification of Russian hackers who have been targeting Signal and WhatsApp accounts of government officials and journalists according to an official FBI notice.

The operation, linked to the groups UNC5792 and UNC4221, has been active since at least March and focuses on social engineering rather than direct exploits.

The attackers send messages that look like automated support notices from Signal or WhatsApp, urging the recipient to verify their account by following a link or providing a backup recovery key as detailed in industry reporting.

When a user shares the recovery key, the adversary can register the account on a new device and retain indefinite access to existing chats without breaking the apps’ encryption.

Campaigns have focused on senior officials, military personnel and reporters, with thousands of accounts already compromised according to warnings from US agencies via CISA guidance.

The shift to stealing recovery keys instead of one time verification codes allows the threat actors to maintain long‑term footholds in private conversations.

Security researchers attribute the activity to UNC5792 and UNC4221, which are believed to be tied to Russian intelligence services including the FSB as noted in recent threat analyses.

Although no public CVE identifiers have been assigned to the tactic, the campaign demonstrates how social engineering can bypass even strong cryptographic protections.

Users should treat any unsolicited message that asks for a recovery key or requests a link click as suspicious and verify the request through an official channel before acting.

Enabling registration lock or a PIN on the messaging app adds an extra barrier that prevents an attacker from re‑registering a number even if they obtain the key.

Organisations are encouraged to remind staff about these tactics and to report any phishing attempts to their security teams or to the FBI’s tip line.

Staying current with official advisories from the FBI and CISA helps defenders recognise emerging variations of the campaign and apply timely mitigations.

Intelligence briefing updated Jun 30, 2026

UNC5792
Root sourcewww.ic3.gov
Timeline Coverage

Swipe to explore timeline