惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
人人都是产品经理
人人都是产品经理
云风的 BLOG
云风的 BLOG
小众软件
小众软件
F
Fortinet All Blogs
爱范儿
爱范儿
WordPress大学
WordPress大学
N
Netflix TechBlog - Medium
Recent Announcements
Recent Announcements
Google DeepMind News
Google DeepMind News
C
Check Point Blog
博客园 - 聂微东
D
Docker
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
aimingoo的专栏
aimingoo的专栏
Vercel News
Vercel News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
A
About on SuperTechFans
博客园 - 【当耐特】
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog
宝玉的分享
宝玉的分享
Jina AI
Jina AI
H
Hackread – Cybersecurity News, Data Breaches, AI and More

GRAHAM CLULEY

Former AT&T store worker jailed after moonlighting as a SIM-swap gang's inside man 'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars Smashing Security podcast #484: How websites are tracking you with silence CRPx0 ransomware: what you need to know The US military just turned off ad tracking on its phones. Maybe you should too How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Smashing Security podcast #483: This AI helps thieves steal your iPhone Revolut scam steals £180,000 from Jersey residents in just four weeks Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more US Navy tells sailors and their families: scrub your social media, enemies are watching Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Gunra ransomware: what you need to know Smashing Security podcast #481: Never say this to a robot dog Prison for data analyst who tried to extort $2.5 million from his employer An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras Smashing Security podcast #480: This is the AI service you should never sign up to Meta's Ray-Bans are being banned from pubs, restaurants, and theatres Beware cut-price AI services that read your every word Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Fake IRS letters target cryptocurrency holders The $5 million threat: AI Is supercharging phishing attacks North Korea's elite hackers turned on their own government — and got caught Smashing Security podcast #478: This job interview could destroy your company OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Ukraine warns fake CAPTCHAs are being used to make you hack yourself Google's Gemini lets strangers send messages from your locked Android phone
Your Signal account is safe - unless you fall for this trick
2026-03-12 · via GRAHAM CLULEY

Signal, the encrypted messaging app trusted by security-savvy users around the world, has confirmed that hackers have managed to takeover accounts — with government officials and journalists among those being targeted.

The warning came earlier this week, when Signal posted on Bluesky that attacks had taken place, while underlining that its encryption and underlying central infrastructure remained intact and uncompromised.

The problem is not with Signal itself, but rather with its users being tricked into handing over the keys to their accounts.

On the same day, the Dutch General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) published a joint advisory blaming attacks against Signal and WhatsApp users on Russian-backed hackers.

According to the Dutch intelligence agencies, the operation is "large-scale and global," with victims confirmed to include Dutch government employees. Journalists are also understood to have been targeted.

The attacks highlight that even the strongest encryption cannot protect you if you are tricked into control of your account over to a malicious hacker.

Rather than trying to break the cryptography which protects messages sent via Signal or WhatsApp, attackers are simply persuading users to hand over their verification codes or unwittingly link a second device to their account — quietly giving attackers a access to private conversations.

The hacking campaign uses two main techniques, neither of which requires exploiting any vulnerability in Signal or WhatsApp. Instead, the attackers rely on the tried-and-trusted trick of social engineering.

As Signal explained in its post, targeted victims receive an in-app message which purports to come from "Signal Security Support Chatbot", or a similar official-sounding account.

The message claims that suspicious activity has been detected, and the victim is prompted to complete a "verification procedure" by entering their SMS verification code and Signal PIN.

Of course, once the credentials have been handed over, attackers can register the victim's account on a device under their control - gaining access to incoming messages and group chats.

Another attack method abuses the "linked devices" feature used by Signal and WhatsApp. A hacker can send their intended target a QR code or link that appears to be a group chat invitation or routine security prompt. The reality is that scanning the QR code links the attacker's device to the victim's account, allowing their conversations to be monitored surreptitiously.

According to Signal, it is working on adding more warnings within its app to alert users to the potential dangers of responding to a phishing message.

According to the company, it says it will never contact users via in-app messages, SMS, or social media to request verification credentials. And if someone contacts you claiming to be the "Signal Security Support Chatbot" - well, they're an attacker.

You can review what devices are linked to your Signal and WhatsApp accounts by going to Settings > Linked Devices, and remove anything that you do not recognise.

And remember - no amount of encryption can save you from being socially engineered.