FBI says Russian intelligence hackers have a new trick for reading your Signal messages, and it works even after you change phones
TL;DR
FBI warns Russian hackers are phishing Signal users for backup recovery keys, giving persistent access to message history.
The FBI and CISA have warned that Russian intelligence hackers are now targeting Signal users’ backup recovery keys, an escalation of a phishing campaign that has already compromised thousands of accounts worldwide. The updated advisory, published Thursday, says that handing over the key once gives attackers the ability to restore an account’s backup, read its entire private and group message history, and take over the account.
The key keeps working even after the victim changes phones. If a target creates a new account on the same phone number, the old recovery key can still be used to access future backups, the advisory warns. The only fix is to generate a new key in Signal’s settings, which invalidates the old one for future downloads but cannot recover anything the attacker has already...
Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE