Russian Hackers Target Signal & WhatsApp: FBI Warns of Espionage Campaign

by Anika Shah - Technology
0 comments

Russian Intelligence Targets Signal Users in Global Phishing Campaign

Russian intelligence services are actively targeting individuals of “high intelligence value” – including government officials, military personnel, policymakers, and journalists – through a sophisticated phishing campaign on encrypted messaging apps like Signal. The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint public service announcement on Friday, March 20, 2026, warning of the ongoing operation [1].

How the Attacks Perform

Unlike traditional cyberattacks that attempt to breach encryption, this campaign relies on social engineering to gain access to accounts. Attackers pose as automated customer support accounts within the messaging apps, contacting targets with claims of suspicious activity or the need for account verification. They then request users to click on links or provide verification codes or account PINs [3].

If a user complies, the attackers can either link their device to the victim’s account or seize complete control, allowing them to read messages, access contact lists, and launch further phishing attacks. The attackers exploit the apps’ registration and “linked devices” features to gain unauthorized access [4].

APT44 and Sandworm Connection

Cybersecurity researchers have linked this wave of attacks to APT44, also known as Sandworm, a Russian threat group affiliated with Unit 74455 of the GRU (Russian military intelligence) [3]. Sandworm has a history of destructive cyber operations, and espionage.

International Warnings

The U.S. Warning follows similar alerts from European allies. Dutch intelligence services warned on March 9, 2026, of a large-scale attempt to infiltrate Signal and WhatsApp accounts, with Dutch government employees among the first victims [3].

Defensive Measures

The FBI and CISA recommend the following precautions:

  • Never share verification codes or account PINs with anyone, regardless of how legitimate the request appears. Signal and WhatsApp will never ask for this information through in-app messages [4].
  • Regularly check “Linked Devices” settings in messaging apps to ensure no unauthorized devices are connected.
  • Enable phishing-resistant multi-factor authentication (MFA) and use registration locks where available.
  • For individuals in high-risk sectors, monitor group chats for suspicious activity, such as duplicate contacts or unusual messages.

The Shift to Social Engineering

This campaign represents a broader trend in state-sponsored cyber warfare: a move away from expensive technical exploits towards cheaper, more scalable, and human-centered attacks. As encryption becomes more robust, adversaries are focusing on exploiting the weakest link – the user themselves [3].

The success of this campaign may necessitate a reevaluation of secure communication practices, particularly for government and military functions. Renewed calls are emerging for communication tools that do not rely on commercial infrastructure or SMS-based verification systems, which are vulnerable to interception and spoofing.

Related Posts

Leave a Comment