{"id":58164,"date":"2026-05-29T09:37:28","date_gmt":"2026-05-29T09:37:28","guid":{"rendered":"https:\/\/zero.redgem.net\/?p=58164"},"modified":"2026-05-29T09:37:28","modified_gmt":"2026-05-29T09:37:28","slug":"signal-users-targeted-in-backup-stealing-phishing-attacks","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=58164","title":{"rendered":"Signal users targeted in backup-stealing phishing attacks_MALWAREBYTES:AB4720290D95C0CACF3C1E2CB7775924"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-05-29T14:05:07&#8243;,&#8221;description&#8221;:&#8221;A new phishing campaign is targeting Signal users by attempting to steal their backup recovery keys to access encrypted message archives. \\n\\nThe attack is initiated by a text message pretending to come from Signal Support.\\n\\n![Phishing message pretending to come from Signal support](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2026\/05\/text_message.png)\\n\\n\\u003e \u201cAction Required: Data Recovery Needed  \\n\\u003e Your Signal account data (message and media) Is at risk of permanent loss due to a sync issue.  \\n\\u003e To avoid losing your messages and media:  \\n\\u003e 1\\\\. Go to Settings -\\u003e Backups -\\u003e Configure -\\u003e Enable backups -\\u003e View Recovery Key.  \\n\\u003e 2\\\\. Copy the recovery key to your clipboard.  \\n\\u003e 3\\\\. Paste the key into this chat.  \\n\\u003e This links your existing backup to your account. Failure to do this may result in losing access to your account and all stored data.\u201d\\n\\nThere are a few red flags in this message:\\n\\n  * The \u201cName not verified\u201d label under the sender\\n  * Repeated threats of losing all your data\\n  * Pasting the key into the chat. Signal Support would never ask for your recovery key\\n\\n\\n\\n* * *\\n\\n![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/11\/phishing-scam-protection-icon-0B73D5.svg?w=1024)\\n\\n### Scam or legit? Scam Guard knows.\\n\\nTRY IT NOW\\n\\n* * *\\n\\nThe attack exploits Signal&#8217;s Secure Backups feature, which allows users to store encrypted archives of their conversations on Signal&#8217;s servers. These backups are protected by a 64-character recovery key.\\n\\nThat key should never leave the user&#8217;s device and is never shared with Signal&#8217;s servers. If hackers obtain this key and gain control of a victim&#8217;s account, they can download and decrypt the entire message history.\\n\\nFor an attacker, that\u2019s even better than hijacking an account, which would only give them access to future messages.\\n\\nFor now, the attacks appear to be targeted. We have seen reports from journalists, reports of attacks on Chinese activists, and warnings from a researcher who investigates cyberattacks against journalists, dissidents, and human rights activists. But now that other cybercriminals are aware of this opportunity, the tactic could spread rapidly.\\n\\n## How to stay safe\\n\\nSignal explicitly states that it will never reach out to users first and will never request registration codes, PINs, or recovery keys. \\n\\n  * **Treat unsolicited messages from \u201cSupport\u201d as suspicious by default.** Legitimate support for apps like Signal and WhatsApp do not ask you, in a chat message, to send back verification codes, PINs, or passwords.\u200b If you receive a warning about account problems, do not follow links in the message. Open the app\u2019s settings directly or visit the official website through other means.\\n  * **Never share any secret codes,multi-factor authentication keys, or app PINs. **SMS codes are there to prove that you control a phone number. Anyone who has the code can pretend to be you. App\u2011specific PINs or passcodes are there to protect account changes. Consider anyone asking for them to be a scammer.\\n  * **Use the extra security features these apps offer.** Enable options like registration lock, registration PIN and device\u2011change alerts so that your account cannot be silently re\u2011registered without an extra secret. Store your PIN in a password manager instead of choosing something easy to guess or reusing a code. This reduces the risk of social engineering or shoulder\u2011surfing.\\n  * **Another useful feature isdisappearing messages. **Short\u2011timer and disappearing messages reduce how much content is available if an attacker gains access to a chat later, or obtains long\u2011term access to a device or backup. They are not a complete solution, but they can limit the damage.\\n  * **UseMalwarebytes Scam Guard on your device or online to check messages.** Malwarebytes Scam Guard identified this message as a phishing attempt and provided further information about how to proceed.\\n\\n\\n\\n* * *\\n\\n**Scammers know more about you than you think.**  \\n\\nMalwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. \\n\\nDownload for iOS \u2192 Download for Android \u2192&#8221;,&#8221;published&#8221;:&#8221;2026-05-29T12:07:24&#8243;,&#8221;modified&#8221;:&#8221;2026-05-29T12:07:24&#8243;,&#8221;type&#8221;:&#8221;malwarebytes&#8221;,&#8221;title&#8221;:&#8221;Signal users targeted in backup-stealing phishing attacks&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MALWAREBYTES:AB4720290D95C0CACF3C1E2CB7775924&#8243;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.malwarebytes.com\/blog\/news\/2026\/05\/signal-users-targeted-in-backup-stealing-phishing-attacks&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-05-29T14:05:07&#8243;,&#8221;description&#8221;:&#8221;A new phishing campaign is targeting Signal users by attempting to steal their backup recovery keys to access encrypted message archives. \\n\\nThe attack is initiated&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,115,13,33,7,11,5],"class_list":["post-58164","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-malwarebytes","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Signal users targeted in backup-stealing phishing attacks_MALWAREBYTES:AB4720290D95C0CACF3C1E2CB7775924 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=58164\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Signal users targeted in backup-stealing phishing attacks_MALWAREBYTES:AB4720290D95C0CACF3C1E2CB7775924 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-05-29T14:05:07&#8243;,&#8221;description&#8221;:&#8221;A new phishing campaign is targeting Signal users by attempting to steal their backup recovery keys to access encrypted message archives. nnThe attack is initiated...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=58164\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-29T09:37:28+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=58164#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=58164\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Signal users targeted in backup-stealing phishing attacks_MALWAREBYTES:AB4720290D95C0CACF3C1E2CB7775924\",\"datePublished\":\"2026-05-29T09:37:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=58164\"},\"wordCount\":835,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"malwarebytes\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=58164#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=58164\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=58164\",\"name\":\"Signal users targeted in backup-stealing phishing attacks_MALWAREBYTES:AB4720290D95C0CACF3C1E2CB7775924 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-05-29T09:37:28+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=58164#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=58164\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=58164#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Signal users targeted in backup-stealing phishing attacks_MALWAREBYTES:AB4720290D95C0CACF3C1E2CB7775924\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Signal users targeted in backup-stealing phishing attacks_MALWAREBYTES:AB4720290D95C0CACF3C1E2CB7775924 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=58164","og_locale":"en_US","og_type":"article","og_title":"Signal users targeted in backup-stealing phishing attacks_MALWAREBYTES:AB4720290D95C0CACF3C1E2CB7775924 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-05-29T14:05:07&#8243;,&#8221;description&#8221;:&#8221;A new phishing campaign is targeting Signal users by attempting to steal their backup recovery keys to access encrypted message archives. nnThe attack is initiated...","og_url":"https:\/\/zero.redgem.net\/?p=58164","og_site_name":"zero redgem","article_published_time":"2026-05-29T09:37:28+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=58164#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=58164"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Signal users targeted in backup-stealing phishing attacks_MALWAREBYTES:AB4720290D95C0CACF3C1E2CB7775924","datePublished":"2026-05-29T09:37:28+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=58164"},"wordCount":835,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","malwarebytes","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=58164#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=58164","url":"https:\/\/zero.redgem.net\/?p=58164","name":"Signal users targeted in backup-stealing phishing attacks_MALWAREBYTES:AB4720290D95C0CACF3C1E2CB7775924 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-05-29T09:37:28+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=58164#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=58164"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=58164#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Signal users targeted in backup-stealing phishing attacks_MALWAREBYTES:AB4720290D95C0CACF3C1E2CB7775924"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/58164","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=58164"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/58164\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=58164"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=58164"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=58164"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}