惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
G
Google Developers Blog
J
Java Code Geeks
爱范儿
爱范儿
Microsoft Azure Blog
Microsoft Azure Blog
美团技术团队
人人都是产品经理
人人都是产品经理
Martin Fowler
Martin Fowler
IT之家
IT之家
博客园_首页
B
Blog RSS Feed
Google DeepMind News
Google DeepMind News
B
Blog
U
Unit 42
Apple Machine Learning Research
Apple Machine Learning Research
L
LangChain Blog
Stack Overflow Blog
Stack Overflow Blog
罗磊的独立博客
N
Netflix TechBlog - Medium
T
Tailwind CSS Blog
博客园 - 聂微东
腾讯CDC
A
About on SuperTechFans

TechCrunch

Robots beat human records at Beijing half-marathon Palantir posts mini-manifesto denouncing inclusivity and ‘regressive’ cultures TechCrunch Mobility: Uber enters its assetmaxxing era Cracks are starting to form on fusion energy’s funding boom Blue Origin successfully re-uses a New Glenn rocket for the first time ever Tesla brings its robotaxi service to Dallas and Houston VC Ron Conway says he has a ‘rare form of cancer’ AI chip startup Cerebras files for IPO Anthropic’s relationship with the Trump administration seems to be thawing The App Store is booming again, and AI may be why “Tokenmaxxing” is making developers less productive than they think Hackers are abusing unpatched Windows security flaws to hack into organizations Zoom teams up with World to verify humans in meetings Gigs turns your concert history into a personal live music archive Chef Robotics escaped the robot cooking graveyard and says it’s thriving — here’s why Uber will now pick up your returns from your doorstep Anthropic launches Claude Design, a new product for creating quick visuals Google’s AI Mode can now help you find products in stock nearby Bluesky confirms DDoS attack is cause of continued app outages Bluesky confirms DDoS attack is cause of continued app outages Netflix plans to add a vertical video feed, use AI for recommendations SaySo is a new short-form video app that aims to restore users’ trust in news Loop raises $95M to build supply chain AI that predicts disruptions Are we tokenmaxxing our way to nowhere? New leaders, new fund: Sequoia has raised $7B to expand its AI bets Netflix co-founder and chair Reed Hastings to leave board Upscale AI in talks to raise at $2B valuation, says report Physical Intelligence, a hot robotics startup, says its new robot brain can figure out tasks it was never taught From the Startup Battlefield stage to the International Space Station: geCKo Materials built a sticky product Slash, a Ramp competitor founded by teenagers, raises $100M at $1.4B valuation
Hackers are trying to steal Signal users’ backups in new ...
Lorenzo Franceschi-Bicchierai · 2026-05-29 · via TechCrunch

Hackers are targeting Signal users in an attempt to steal their chat backups as part of a new hacking campaign, TechCrunch has learned. 

On Wednesday, Washington Post analyst Josh Rogin posted a screenshot of a new kind of attack against Signal users, where hackers pretend to be the app’s support team and warn the target that their backed-up chats and media are “at risk of permanent loss due to a sync issue.” To avoid that, the message said, the target needs to share the recovery key that is used to access their online backups in the chat with the hackers. 

“This links your existing backup to your account. Failure to do this may result in losing access to your account and all stored data,” read the message purporting to come from an account called Signal Support.

This is a phishing attempt. If you get this message on Signal, do not follow the instructions. Many anti-CCP activists have also received this phishing attempt. Beware and be aware. pic.twitter.com/8J1YDcpUAX

— Josh Rogin (@joshrogin) May 27, 2026

Rogin said that several anti-Chinese Communist Party activists have received this malicious message. 

Mohammed Al-Maskati⁩, the director at Access Now’s Digital Security Helpline, which investigates cyberattacks against journalists, dissidents, and human rights activists, told TechCrunch that two people shared similar messages with him. Al-Maskati said that the two are not Chinese activists. This suggests that the hacking campaign could be more widespread and targeting other communities, or there may be different groups of hackers using the same strategy.

It’s not clear how effective the hacking campaign has been. Al-Maskati said that stealing the victim’s recovery keys for their chat backups is only one step in the attack, and that the hackers still have to take over the victim’s account. 

“We’re working on mitigations here, and monitoring,” Signal president Meredith Whittaker told TechCrunch.

In general, this type of attack relies on phishing targets, meaning tricking them into sharing some important and private information with the hackers. In this particular case, the hackers are pretending to be Signal’s support team to exploit the target’s trust in the app and the organization behind it.

It’s important to note that Signal says it “will never reach out” to users first, and will never ask for their registration code, PIN, or recovery key. That means any chat pretending to be coming from “Signal Support” is actually coming from malicious hackers. The organization publicly warned about this exact type of attack last month. 

Contact Us

Do you have more information about these attacks against Signal users? Or other similar attacks? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.

While there have been several campaigns of hackers impersonating Signal support in recent months, this is a new type of attack because it specifically targets backups, which can contain a victim’s older chats, photos, and documents.  

Previous hacking campaigns targeting Signal users attempted to hijack a victim’s account and then impersonate them, often with the potential goal of stealing the victim’s contacts or starting conversations with other people as if they were the account owner. In these cases, the hackers do not get access to past messages, since the attacks rely on them re-registering the victim’s account on a device they control. Because of how Signal is designed, older messages do not appear on the new device. 

Hackers can take over Signal accounts by hijacking someone’s phone number, for example. But Signal offers opt-in security features to protect against that, such as Registration Lock, which prevents attackers from linking a target’s number to a new device unless they steal the target’s PIN. 

In that scenario, one way to see older messages would be to access a victim’s online backup, which requires the recovery key.

Last year, Signal launched Secure Backups, a new opt-in feature that lets users upload their account’s contents to Signal’s servers, which are encrypted with a recovery key that the organization says is “never shared with Signal’s servers,” and “never leaves” the users’ device. Signal says users should store the recovery key securely on a notebook or inside a password manager. 

“Without your unique recovery key, no one (including Signal) can read, decrypt, or restore any of the data in your Secure Backup Archive,” Signal said.

That means only the user can access their archive in a scenario where they register their account on a new phone, download the encrypted backup from Signal’s servers, and then decrypt it with the recovery key. 

Updated to include comment from Signal.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy.

You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com, via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.

View Bio