Hackers steal Signal and WhatsApp accounts through fake backup messages
A new phishing campaign targets Signal and WhatsApp users – attackers send messages posing as technical support and lure out recovery keys.

Fake technical support steals backup recovery keys on Signal and WhatsApp
Nový Čas warns of a phishing campaign targeting users of Signal and WhatsApp applications. Attackers send messages posing as official technical support and attempt to trick victims into disclosing recovery keys to encrypted backups of conversations.
The scam was first highlighted by TechCrunch. Several activists received a message from an account claiming to be Signal technical support. The message claimed that the user risked losing backed-up messages and media due to an alleged synchronisation problem. As a solution, it urged the sending of a so-called recovery key – a backup recovery key used to access backups.
Signal last year introduced the Secure Backups feature, which allows encrypted backups of conversations to be stored on the company's servers. To read these backups, a special recovery key is required, which is available exclusively to the user themselves. Even Signal is unable to read the messages without this key – which is precisely why hackers are attempting to obtain it by all means. Signal's developers warn that this information has the same value as a password or two-factor authentication code.
Attack on people, not on the application
"With phishing, there is very often an attempt to create a sense of urgency. In this case, attackers played on fear of losing backed-up messages," says the vosveteit.zoznam.sk portal. The same scenario is being attempted by attackers on WhatsApp, which also offers encrypted backups and various security mechanisms. Security analysts have recorded new waves of attacks on both platforms with the same principle.
"The attacker poses as support for a well-known platform and attempts to trick you into disclosing login credentials or security keys," the portal adds. Hackers do not target one specific group – they attempt to reach as many users as possible and calculate that someone will fall for it.
The key shift compared to older types of attacks is that attackers do not focus on technical vulnerabilities in applications. They attack people themselves and through manipulation attempt to force them directly to disclose sensitive information. No antivirus software or security feature on a device will protect against this type of attack.
Artificial intelligence increases the persuasiveness of scams
Signal warns that even more sophisticated scams may be expected in the future. Artificial intelligence helps hackers cover up poor grammar or lack of language knowledge and allows them to compose professionally sounding messages within seconds. Distinguishing fake messages from genuine communication will become increasingly challenging.
How to protect yourself
Security analysts emphasise one basic principle: no legitimate service will ever ask for a password, PIN code, recovery key, or verification code sent via SMS through chat. If a message with such a request arrives in the inbox, it is automatically a scam. "There are no situations where asking for passwords or codes would be justified," the vosveteit.zoznam.sk portal quotes security analysts.
Recommendations for protecting your account:
- Do not share recovery keys, passwords, or verification codes via any message.
- Activate all available security features in the application.
- Use strong and unique passwords for each service.
- Store recovery keys in a trusted password manager or in a secure offline location.
The basic principle of the attack remains the same regardless of platform: whoever obtains the data needed to restore an account or backup can attempt to access sensitive messages, photographs, or documents stored in the backup.
Source: Nový Čas