The FBI’s warning about Russian hackers infiltrating Signal accounts largely flew under users’ radar. (Image by BleepingComputers.com) If you’re a journalist these days and you get a call from the FBI, as I did the other day, your first instinct is to be on guard.
Did the bureau want to grill me as part of a leak investigation? Seize my phone (as it notoriously did to a Washington Post reporter earlier this year?) Or try to coerce me into being a witness against some target of the Justice Department sprawling investigations into President Trump’s political enemies?
Alas, in my case, it was precisely the opposite. The FBI agent from the Washington D.C. field office who reached out on my cell phone wanted to be helpful and alert me to something I was totally unaware of: My account on the Signal messaging app had been compromised, she informed me.
By the Russians, she added.
It turns out I had been targeted by an audacious “phishing” scheme orchestrated by Russia’s FSB, the country’s all-powerful intelligence agency, which has been breaking into one of the most widely used—and presumptively secure—commercial messaging service.
To say that I was dismayed would be something of an understatement. Signal, of course, is routinely used by journalists to communicate with confidential sources. And not just journalists, as the world discovered last year when The Atlantic revealed that Secretary of Defense Pete Hegseth used Signal to discuss with other senior Trump national security officials imminent plans to attack the Houthis in Yemen.
But as I quickly learned as well, I shouldn’t have been surprised by the security breach. It turns out the FBI has issued two alerts this year about the Russian cyber operations that, although they have gotten relatively little attention, should have set off alarm bells across the board. FBI Director Kash Patel had even posted about it on X.
Neither he nor the bureau pulled any punches about what the Russians were up to. “The activity targets individuals of high intelligence value, such as current and former U.S. government officials, military personnel, political figures, and journalists,” the bureau wrote in a public alert last March. (I suppose I should be flattered that somebody in Moscow thinks I have “high intelligence value.”)
This is another free SpyTalk post without a paywall. It’s kind of an experiment: We’ll do more of these if readers will continue to sponsor us with paid subscriptions. We can’t do our wide-ranging reporting without you. And we certainly appreciate your generosity. Thanks.
But I was far from alone. “This global campaign has resulted in unauthorized access to thousands of individual [messaging] apps,” the March alert added. “After compromising an account, malicious actors can view the victims’ messages and contact lists, send messages, and conduct additional phishing against other [messaging] accounts” noting that the “threat actors specifically target Signal accounts.”
In June, the bureau issued a follow up alert specifically identifying the FSB, the Russian intelligence service that ex-KGB agent Vladimir Putin once headed and which to this day maintains tight control over, as the culprit. “Russian Federal Security Service (FSB) officers embedded with the FSB Border Guards and others working on behalf of the Russian military services” were behind the Signal attacks, according to the June 26, 2026 alert.
Moreover, the attacks on Signal and other message apps, like WhatsApp, are very much an ongoing operation, the European Union warned just this week.
To be sure, Russia’s aggressive hacking is hardly a new phenomenon. Eight years ago, I co-authored a book, Russian Roulette, that documented how the Russians penetrated the email accounts of the Democratic National Committee and the Hillary Clinton campaign as part of a plot to disrupt the 2016 U.S. presidential election.
But since then, and especially in the wake of the invasion of Ukraine, Russia’s cyber warriors have dramatically stepped up their game with new and innovative tactics, according to Steven Adair, the president of Volexity, a cybersecurity firm that advises clients on how to protect their data.
“There has essentially been a slew of new techniques that have been extraordinarily successful by the Russians,” Adair told me when I called to tell him how I had been victimized by the FSB.
While his firm had monitored Russian cyber operations for over a decade, in a six month period last year, “we saw more actual breeches than we’d seen in the past 10 years,” Adair added. “In terms of cyber access, it’s through the roof.”
Don’t miss the latest SpyTalk podcast, with former CIA Chief Learning Officer Steve Hirsch on how Russia, China, and Iran exploit the cracks in US intelligence.
So how did the Russians do it? In my case, it began with a message that popped up on my Signal account on May 29 stating it was from “Signal Support” with the blue-rounded circle that is Signal’s signature logo.
“We found logging in to your account from a new device,” it read. “If it wasn’t you, write, ‘it’s not me’ in the chat and follow the further recommendations.” These included instructions on how to enter my “recovery key”— a long hodgepodge of random letters and numbers that are apparently unique to each users’ account.
At first, I didn’t respond. But then, four days later, on June 3, I got a follow up “Signal Support” message that got my attention. “Warning,” it read. “You did not enter your recovery key. Your account will be deleted.”
Not wanting to lose access to an account I believed to be secure and regularly use, I stupidly did what the bogus Signal Support team recommended, including the final step: “Paste the key here immediately to keep your account.”
Remedial Phone Work
When the FBI agent called me this week, she explained what I had done wrong and how I was among a rather large group of Signal users—in the thousands—who had fallen for the scam. She then patiently walked me through how to correct matters by creating a new recovery key and pin that preserves my account and keeps it secure.
So, amidst all the outrageous FBI actions in pursuit of the Trump administration’s attacks on a free press, the bureau in this case was doing a public service.
So a big thank you, Kash Patel. One of your agents was actually helpful to a reporter — and has now helped me to do my job to report on everything you’re doing wrong.
As the FBI explained, anybody who thinks their account has been compromised should click on the circle in the upper left when you open up your Signal account, go to Settings and create a new recovery key and pin. The FBI’s public service alert last March also states: “If you or someone you know has fallen victim to this phishing campaign, file a complaint with IC3. For additional information, see FBI’s guidance on Spoofing and Phishing as well as a previous Public Service Announcement about how “Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud.” Additionally, see CISA’s “Phishing Guidance: Stopping the Attack Cycle at Phase One | CISA“ and “Mobile Communications Best Practice Guidance.”
Thank you for reading this. SpyTalk is an entirely reader-supported publication. To receive new posts and support the work of all of us here, please consider taking out a paid subscription. We can’t do it without you. Just click below for a no-obligation free trial.