FBI: Russian hackers now target Signal backup recovery keys
2026-06-27T07:23:28Z•d0bbc391485eef29a1da623d9bfb3bbe1e79d90b31689c3c0852cce2bfca03f3
account takeoveractive exploitationanthropic claudeanti-analysisbackup recovery keybluekitbrowser-in-the-middlecallback phishingcisacisco unified communications managerdomain seizurefederal patch deadlinefraudulent openai invitesgaslightmacos malwarephishingpirlotvpolymarketrussian intelligenceshop appsignalsim-swappingsocial engineeringsupply-chain attackwindows 10 esu
What happened
Multiple active threats and notable security developments: FBI/CISA warn a Russian-linked phishing campaign has evolved to steal Signal Backup Recovery Keys, enabling access to historical messages. CISA issued an urgent directive for federal agencies to patch an actively exploited vulnerability in Cisco Unified Communications Manager Server. Polymarket suffered a supply‑chain frontend compromise that led to ~$3M in customer losses; the platform will reimburse victims. Attackers are also using fraudulent OpenAI organization invites to socially engineer cybersecurity firms, and the Bluekit phish
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d0bbc391485eef29a1da623d9bfb3bbe1e79d90b31689c3c0852cce2bfca03f3
- Enrichment time
- 2026-06-27T07:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.