You Switched to Signal for Privacy. Russian Hackers Are Now Using Signal to Spy on You.
Russian intelligence-linked hackers found a way to silently tap your Signal messages without breaking encryption — by getting you to approve their device. Here's exactly how it works and how to check if it already happened.
The Safest App Got Targeted
Signal is the app privacy experts recommend to everyone. End-to-end encrypted. No ads. No data collection. Open source. The app whistleblowers, journalists, and activists trust with their lives.
And now Russian intelligence-linked hackers have found a way in.
Not by breaking the encryption — that's still solid. But by exploiting something far simpler: you.
In May 2026, the FBI and CISA confirmed that a sophisticated phishing campaign, linked to Russian state-sponsored actors, had been targeting Signal users. Signal responded by deploying new in-app security warnings. The attack is active. It's clever. And it works because it uses Signal's own features against you.
How the Attack Works
Signal lets you link multiple devices to one account — your phone and your laptop, for example. This is a legitimate, useful feature. It's also the attack vector.
Here's the playbook:
Step 1 — You get a message from a trusted contact The attacker either compromises someone you know, spoofs their number, or creates a convincing fake. The message looks normal — maybe a shared link, maybe an invitation to a group.
Step 2 — You're asked to scan a QR code The message contains a QR code. It might be framed as a security verification, a group invite, or a link preview. It looks legitimate.
Step 3 — You scan it The QR code triggers Signal's "Link a device" flow. A prompt appears asking if you want to add a new device. If you tap confirm — or if the UI is designed to look like something else — the attacker's device is now linked to your account.
Step 4 — Silent surveillance begins Every message you send and receive going forward is delivered to both your device and the attacker's device. In real time. Your encryption is intact. The attacker is just another linked device.
Who's Being Targeted
The FBI and CISA flagged this campaign as primarily targeting:
- Government officials and their contacts
- Military personnel
- Journalists and activists
- Anyone who uses Signal specifically because they handle sensitive information
But campaigns like this spread. Once the technique is public, copycats use it against regular users.
Check Your Linked Devices Right Now
This takes 30 seconds:
On iPhone: Signal → Settings → Linked Devices
On Android: Signal → your profile icon → Linked Devices
You should see only the devices you personally set up. If you see anything unfamiliar — a device you don't recognise, added at a time you can't account for — remove it immediately.
If your list is clean, you're fine. But check now, and check again periodically.
The New Signal Warning
Signal's May 2026 update added new friction to the device-linking flow. When a QR code triggers a link request, Signal now shows a more prominent warning explaining what the action does. Attackers are already adapting — expect new social engineering scripts designed to talk users past the warning.
The technical safeguard only works if you read it.
Broader Lessons
1. No app is safe if the human is the vulnerability Signal's encryption is not broken. The attack targets trust, urgency, and distraction — not cryptography.
2. QR codes are a growing attack surface A QR code is just a URL or action trigger. You can't see where it goes by looking at it. Treat unexpected QR codes like unexpected attachments.
3. Periodically audit your accounts Linked devices, active sessions, third-party app permissions — check them quarterly. Attackers rely on the fact that most people set things up and never look again.
4. Verify out-of-band If someone sends you something unexpected on Signal — even someone you trust — confirm via a phone call or in person before taking any action.
The Uncomfortable Reality
The most private messaging app in the world became an attack vector not because of bad engineering, but because human behavior is predictable. Social engineering doesn't need a zero-day. It needs you to be busy, distracted, and trusting for 10 seconds.
Check your linked devices. Do it now, before you close this tab.
Stay invisible. Follow HackDecoded.
Sources
Common Questions About Scam
How do I know if a call is really from a government agency?
Legitimate government agencies never call demanding immediate payment, threatening arrest, or asking for gift cards, wire transfers, or cryptocurrency. Hang up and call the agency directly using their official number from usa.gov.
What is a pig butchering scam?
Pig butchering is a long-con investment fraud where scammers build fake friendships or romances over weeks before introducing a fake crypto investment platform. Losses average $120,000 per victim. Any unsolicited investment tip is a red flag.
What should I do if I have already been scammed?
Report to the FTC at ReportFraud.ftc.gov, the FBI at IC3.gov, and your state attorney general. If a bank transfer was involved, call your bank immediately — you may have a window to reverse it. Document everything: screenshots, phone numbers, transaction records.
More in scam
Stay invisible. Follow @hack_decoded
