The Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency are warning of ongoing phishing campaigns tied to Russian intelligence services that are targeting users of popular messaging apps.
According to a joint public advisory, the campaigns have led to unauthorized access to thousands of individual accounts. Officials say the attackers are not breaking the apps’ encryption but are instead exploiting users through deceptive messages.
The activity appears to focus on individuals considered high-value targets, including current and former government officials, military personnel, political figures, and journalists. Once an account is compromised, attackers can read messages, access contacts, and use the account to target others.
Authorities identified two primary tactics.
One method, known as “linked device” abuse, involves impersonating a trusted contact and sending a malicious link or QR code. If clicked, it can allow attackers to connect their own device to the victim’s account and monitor messages.
The second method involves account takeover. Victims receive messages designed to trick them into sharing login credentials, including PINs or two-factor authentication codes. Once provided, attackers can lock users out and take control of the account.
While reporting indicates that Signal users have been a frequent target, officials say the same tactics can be used across a range of messaging platforms.
The agencies stress that phishing remains one of the most effective cyberattack methods, often bypassing safeguards such as end-to-end encryption. Users are advised to be cautious with unexpected messages, avoid clicking unfamiliar links, and never share verification codes or PINs.
They also recommend reviewing account security settings and monitoring group chats for unfamiliar participants.
Suspected phishing attempts can be reported to an organization’s security team or the Internet Crime Complaint Center.
Officials note that legitimate support services for messaging apps do not request verification codes through direct messages and will only communicate through official channels.















