FBI: Russian hackers now target Signal backup recovery keys

2026-06-27T13:23:29Z3b51127cda1d0a1802e758cb74cc56c67ebb8d1f2231550613923064af18822b
active-exploitationai-evasionbackup-recovery-keysbluekitbrowser-in-the-middlecisaciscofbimacos-malwarenation-stateopenai-tenant-phishingphishingpolymarketprompt-injectionrussian-linkedshop-app-callback-phishingsignalsim-swappingsupply-chain-attackunified-communications-managerwindows-10-esu

What happened

Multiple high-impact threats and active campaigns were reported: a Russian-linked phishing campaign evolved to steal Signal Backup Recovery Keys (enabling access to historical messages); CISA issued an urgent deadline to patch an actively exploited vulnerability in Cisco Unified Communications Manager Server; a supply-chain compromise injected malicious script into Polymarket’s frontend, costing customers ~$3M; and threat actors are creating fraudulent OpenAI organization invites to harvest sensitive data. Additional notable activity includes Bluekit phishing adopting browser-in-the-middle log

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
3b51127cda1d0a1802e758cb74cc56c67ebb8d1f2231550613923064af18822b
Enrichment time
2026-06-27T13:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.