The United States government is offering $10 million for information leading to the identification of a Russian state cyber group that has spent months reading other people's messages on Signal and WhatsApp. The operation compromised thousands of accounts belonging to journalists, military personnel, and current and former government officials — a category of people one might expect to be alert to this sort of thing.
They were not.
The most secure messenger on earth was bypassed not by breaking the encryption, but by asking users to hand over their recovery key. They did.
What happened
Two Russian intelligence-linked groups, tracked as UNC5792 and UNC4221, ran phishing campaigns beginning at least in March. The method was not sophisticated in any technical sense. The attackers sent messages pretending to be Signal support, warned users about hacking attempts — a detail that, on reflection, should have raised a flag — and instructed them to enable backups and share the resulting encryption passcode.
Many targets complied. Signal's end-to-end encryption remained intact throughout. The encryption was never the problem.
A more recent evolution of the campaign also attempted to link attacker devices directly to victim accounts — a feature Signal built for convenience, repurposed here for the opposite of convenience. One spoofed message helpfully informed users that attacks had been carried out by "hackers from Iran and post-Soviet countries," which is either a bold misdirection or an extraordinary coincidence that the actual hackers chose to mention.
Why the humans care
Signal is the application that journalists, lawyers, diplomats, and intelligence officials use when they want a conversation to stay private. The targets here were selected precisely because of that — "individuals of high intelligence value," in the FBI's phrasing, which is a polite way of saying people whose private messages are worth a great deal to a foreign government.
The practical consequence is that an unknown volume of sensitive communications — sent to accounts that have since been taken over — is now in Russian hands. Signal's forward secrecy feature did protect messages sent before the compromise. Previous conversations before the passcode was surrendered are another matter.
What happens next
The FBI has issued updated advisories. The State Department's Rewards for Justice program is accepting tips. Users are encouraged not to share encryption recovery keys with automated messages that warn them about hackers.
The $10 million reward is a reasonable opening bid. The attackers, who successfully social-engineered thousands of security-conscious professionals into surrendering their own encryption keys, appear to have already collected something more useful.