惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
S
SegmentFault 最新的问题
V
Visual Studio Blog
J
Java Code Geeks
宝玉的分享
宝玉的分享
美团技术团队
博客园 - Franky
酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hackread – Cybersecurity News, Data Breaches, AI and More
有赞技术团队
有赞技术团队
量子位
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
Google DeepMind News
Google DeepMind News
Jina AI
Jina AI
博客园 - 叶小钗
月光博客
月光博客
P
Proofpoint News Feed
D
DataBreaches.Net
Blog — PlanetScale
Blog — PlanetScale
博客园_首页
腾讯CDC
Microsoft Azure Blog
Microsoft Azure Blog
Stack Overflow Blog
Stack Overflow Blog

The Hindu: Latest News today from India and the World, Breaking news, Top Headlines and Trending News Videos.

U.K. pauses its plan to cede Chagos Islands after U.S. opposition Driver jailed for 7 days for driving sleeper bus in drunken condition Kim Jong Un supports China’s “multipolar world” vision during talks with Wang Yi Uttar Pradesh boat tragedy: Punjab town mourns deaths Relief for Bengaluru commuters as Silk Board flyover set to open fully, but inspection by BTP reveals likely bottleneck Repolling underway at booth of Karimganj North Assembly seat in Assam PM Modi interacts with Rahul Gandhi as leaders gather to pay tribute to Mahatma Jyotiba Phule Anil Kapoor’s ‘24’ set to release on OTT Vance, Iranian delegation arrives in Islamabad for U.S. talks amid ceasefire hopes Fire at Hyderabad’s Chintal Basti apartment, 17 residents evacuated safely Centre nudges States to view farm solarisation as a route to wiping off ₹2.4 lakh crore subsidy bill Why voter turnout hit record highs in Assam, Kerala & Puducherry Strait of Hormuz to be open “fairly soon”, says Trump ‘Jana Nayagan’ leak tests new legal penalties, torrent downloads under scanner Vijay’s ‘Jana Nayagan’ controversy explained: From legal battles to piracy chaos HYDRAA brings down guest house and other structures at Ameenpur Row erupts over removal of Ambedkar statue at midnight in Secunderabad Cantonment area Nitish may resign as Bihar CM on April 13; son Nishant likely to become one of two JD(U) Dy CMs Police open fire on youth while he was trying to flee Struggling CSK look to snap their losing streak | Vidyut Sivaramakrishnan ED raids former Trinamool Minister Partha Chatterjee’s residence Karnataka’s Gruha Jyothi scheme dimmed the scope of PM’s Surya Ghar Muft Bijli Yojana: KRESMA After Artemis II, NASA looks to SpaceX, Blue Origin for Moon landings Ayush Shetty storms into Badminton Asia Championships final Scholarships: April 11, 2026 Andhra Pradesh’s Socio-Economic Survey missing in recent Budget Session; efforts underway Inside Péro’s fun office Penciljam sessions in Bengaluru help hone artistic talent Watch: The mistake killing high-concept films | Escalation without calibration | FMM 19 Tamil Nadu Assembly election 2026: DMK demands reinstatement of N. Muruganandam as Chief Secretary
How a social engineering attack challenged the Signal app
2026-05-16 · via The Hindu: Latest News today from India and the World, Breaking news, Top Headlines and Trending News Videos.

The story so far: Russia-based hackers targeted high-profile users in Germany, according to reports from the German media over the past few weeks. Der Spiegel reported that 300 Signal accounts belonging to politically connected individuals were attacked. On May 7, the German outlet said the Signal attacks show that “Putin’s agents in Germany act so brazenly.” Such cyber-attacks were seen as an attack on Signal itself. But the attackers actually used social engineering tactics that depended on the victims’ compliance; it was not a structural breach of Signal’s end-to-end encryption.

Was Signal hacked by attackers?

It is important to distinguish a hacked platform from a hacked user account. In this case, some users were deceived by malicious actors through phishing attacks: a type of cyber-attack that tricks victims into giving up private security data like passwords or PIN numbers.

Signal explained that the attackers changed their own profile pictures and pretended to be part of Signal’s support team in order to steal user credentials. After this, they took over the victim’s account, changed their phone number, and convinced victims that being de-registered was part of this process. This led to victims losing access to their Signal account and being moved to another one, without realising what was happening to their accounts. Then, the attackers impersonated the victim and tried to target those in the victim’s contact list.

While Russia-based cyber-attacks carried out on end-to-end encrypted platforms like Signal, Telegram, and WhatsApp are not new, Signal receives special attention as the application is known for its security-focused infrastructure. Its users include government officials, journalists, activists, and others who handle sensitive information. In 2025, for example, there was an uproar after Jeffrey Goldberg, editor-in-chief of the Atlantic outlet, was added to a Signal chat where senior U.S. government officials were discussing bombings and diplomatic relations.

In February 2026, a Google Threat Intelligence Group report stated that targets for Russian espionage actors were not just Ukrainian tech users, but also international allies of Ukraine.

Meanwhile, The U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) listed potential targets such as current and former U.S. government officials, military personnel, political figures, and journalists. The U.S. advisory stated that there had been unauthorised access to thousands of user accounts.

What was Signal’s response?

Signal promised to roll out measures to help protect users from such phishing attempts, sparking questions about whether messaging platforms or users should be held accountable in the case of social engineering attacks. Some social media users questioned why the attackers were allowed to impersonate official Signal handles, while others wanted to understand why government officials did not receive better cybersecurity training or access to more secure, non-Signal communication platforms.

On May 12, Signal introduced extra confirmation steps and educational messaging in the app to help users detect fraudulent profiles. The features include “Name not verified” profiles labels, a new confirmation step for message requests, detailed safety tips, and reminders to not trust senders pretending to be from Signal.

The platform has warned users to be vigilant about phishing attacks and account takeover attempts. The company reminded users that no legitimate member of its support team would send message requests or ask for credentials such as their registration verification code and Signal PIN.

Signal account-holders can also make use of the Registration Lock feature via their settings; this enables users to set a PIN for account registration purposes, in addition to SMS-based verification.

“While it’s true that all messaging platforms are susceptible to scammers and phishing that betrays people’s trust and convinces them to “unlock the front door” where no backdoor exists, we are looking to do everything we can to help people avoid and detect such scams,” stated Signal.

How can users protect themselves?

Unlike cyber-attacks that try to breach a platform’s underlying technology, social engineering attacks can be launched with far less technical skill. Rather than destabilising a secure system, they target specific individuals, small groups, or select victims’ accounts. Social engineering attacks involve communication-based tactics such as manipulating the victim, assessing their psychological weaknesses, issuing threats, evoking sympathy, impersonating others, or sending persuasive messages containing harmful links.

The FBI also shared safety advice in its March advisory that warned about ongoing phishing campaigns by cyber actors associated with the Russian Intelligence Services (RIS). It further noted that on the basis of reporting, threat actors specifically targeted Signal accounts.

Some basic security tips they shared include stopping all communication on messaging apps after suspecting a scam, blocking and reporting unknown messages, verifying with friends through alternative channels after receiving “odd” requests from them, enabling message expiration features, screening unknown links before clicking them, monitoring group chat lists for duplicate accounts, and reporting security incidents without delay.

However, a flood of Generative AI tools such as chatbots, deepfake image generators, and voice cloning apps have made it easier than ever for attackers to launch social engineering attacks and for underprepared users — especially children, the elderly, or the vulnerable — to be turned into victims.