US Seeks Tips to Track Hackers Targeting Signal and WhatsApp

You probably wouldn’t expect a message from “Signal support” warning you about a security issue. That kind of message is usually a red flag. Scammers have exploited that trust repeatedly, and now the U.S. government has offered a large reward to help stop them: a $10 million bounty for information leading to those responsible.

This week the U.S. State Department announced the reward through its Rewards for Justice program. The bounty targets information about two groups tracked by investigators as UNC5792 and UNC4221. According to public statements and law enforcement reporting, the FBI has linked those groups to elements of Russian intelligence and military services. The reward seeks credible intelligence on identities, locations, and financial links for individuals involved with either group.

The fraudsters impersonated official Signal and WhatsApp support accounts and sent messages claiming a user’s account required a two-factor authentication check. When victims were tricked into handing over their backup recovery key or similar account recovery credentials, attackers were able to access historical messages and account data. In many cases the compromise did not involve breaking encryption: it relied entirely on social engineering and convincing people to give up secrets that unlock their own accounts.

Reported targets included U.S. government officials, military leaders, journalists covering Russia and Ukraine, and nonprofit organizations assisting Ukraine. Public notices indicate the campaign has compromised thousands of accounts through these deceptive account-recovery and support-impersonation techniques.

Why the attackers didn’t need to break any encryption

This activity does not reflect a failure of Signal or WhatsApp end-to-end encryption. Instead, attackers relied on social engineering and account recovery flows. If a user voluntarily provides a backup key or recovery code, or accepts a manipulated group invite that links an attacker’s device, attackers can access that user’s past messages without ever defeating the cryptographic protections.

Some reported techniques were more advanced: in certain incidents attackers altered group invite links so that clicking an invitation connected the attacker’s device to the victim’s account. That method effectively granted control of the account session without needing to bypass encryption. Law enforcement agencies including the FBI and cybersecurity partners such as CISA have updated guidance and advisories to highlight these tactics and recommend extra caution with account recovery processes, group invites, and any unsolicited messages that claim to be official support.

This reward is intended to generate actionable leads — names, locations, and financial ties — that could help identify those behind the campaign. Whether the $10 million bounty will result in arrests or long-term disruption of the groups remains uncertain, but it signals a high priority from U.S. authorities to halt operations that target sensitive accounts.

If you use encrypted messaging services, follow a few practical steps to reduce your risk: only trust support communications from official, documented channels; never share backup recovery keys, verification codes, or long-lived recovery tokens with anyone; enable hardware security keys when available for account recovery; review active sessions and linked devices in your app’s settings; and be cautious before clicking group invite links or accepting new device connections. Organizations and individuals with high-risk profiles — such as journalists, officials, and humanitarian workers — should adopt stricter account hygiene and consult specialized threat guidance to protect sensitive conversations.

Law enforcement and cybersecurity teams continue to monitor these campaigns. If you believe you were targeted or compromised, report the incident to your service provider through official support channels and to local authorities or national cybercrime reporting bodies. Sharing detailed information about suspicious messages, the timing of requests, and any known financial transactions can help investigators build a clearer picture of operations like those attributed to UNC5792 and UNC4221.

In short, strong encryption remains effective when paired with good operational security. The human element — recognizing phishing, protecting recovery credentials, and verifying support requests — is the critical line of defense against account takeovers that attackers attempt to obtain through deception rather than cryptographic attacks.