Russian Intelligence Used Fake Support Texts to Hijack Messaging Accounts
According to The Hacker News, Ukraine's Security Service (SSU) and the FBI have jointly uncovered a sustained Russian intelligence campaign targeting messaging accounts belonging to government officials, military personnel, politicians, and activists across Ukraine, Europe, and the US.
The method is straightforward and effective. Attackers send SMS messages pretending to be the official support team for platforms like Signal and WhatsApp. The messages pressure targets into handing over account credentials, confirmation codes, or recovery keys.
This is social engineering (manipulating people rather than software to gain access) at its most targeted. The SSU linked similar campaigns to Russian threat groups including Star Blizzard and UNC5792, though it stopped short of attributing this specific operation to a named group.
If an attacker gets your recovery key, they can clone your messaging account to a device you have never seen. Every message you send or receive from that point forward goes to them too.
The FBI separately confirmed Russian intelligence is running a parallel phishing campaign aimed at tricking high-value targets into surrendering their backup recovery keys for commercial messaging apps.
What you should do: Open your Signal or WhatsApp settings and review all active linked devices right now. Remove anything you do not recognise. Enable two-factor authentication if you have not already, and never share confirmation codes, PINs, or recovery keys with anyone claiming to be platform support — the real support team will never ask for them.
Sources

