FBI: Russian hackers now target Signal backup recovery keys
2026-06-27T13:23:29Z•3b51127cda1d0a1802e758cb74cc56c67ebb8d1f2231550613923064af18822b
active-exploitationai-evasionbackup-recovery-keysbluekitbrowser-in-the-middlecisaciscofbimacos-malwarenation-stateopenai-tenant-phishingphishingpolymarketprompt-injectionrussian-linkedshop-app-callback-phishingsignalsim-swappingsupply-chain-attackunified-communications-managerwindows-10-esu
What happened
Multiple high-impact threats and active campaigns were reported: a Russian-linked phishing campaign evolved to steal Signal Backup Recovery Keys (enabling access to historical messages); CISA issued an urgent deadline to patch an actively exploited vulnerability in Cisco Unified Communications Manager Server; a supply-chain compromise injected malicious script into Polymarket’s frontend, costing customers ~$3M; and threat actors are creating fraudulent OpenAI organization invites to harvest sensitive data. Additional notable activity includes Bluekit phishing adopting browser-in-the-middle log
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 3b51127cda1d0a1802e758cb74cc56c67ebb8d1f2231550613923064af18822b
- Enrichment time
- 2026-06-27T13:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.