FBI: Russian hackers now target Signal backup recovery keys

2026-06-27T07:23:28Zd0bbc391485eef29a1da623d9bfb3bbe1e79d90b31689c3c0852cce2bfca03f3
account takeoveractive exploitationanthropic claudeanti-analysisbackup recovery keybluekitbrowser-in-the-middlecallback phishingcisacisco unified communications managerdomain seizurefederal patch deadlinefraudulent openai invitesgaslightmacos malwarephishingpirlotvpolymarketrussian intelligenceshop appsignalsim-swappingsocial engineeringsupply-chain attackwindows 10 esu

What happened

Multiple active threats and notable security developments: FBI/CISA warn a Russian-linked phishing campaign has evolved to steal Signal Backup Recovery Keys, enabling access to historical messages. CISA issued an urgent directive for federal agencies to patch an actively exploited vulnerability in Cisco Unified Communications Manager Server. Polymarket suffered a supply‑chain frontend compromise that led to ~$3M in customer losses; the platform will reimburse victims. Attackers are also using fraudulent OpenAI organization invites to socially engineer cybersecurity firms, and the Bluekit phish

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
d0bbc391485eef29a1da623d9bfb3bbe1e79d90b31689c3c0852cce2bfca03f3
Enrichment time
2026-06-27T07:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI: Russian hackers now target Signal backup recovery keys · Baitaphish