New Signal Scam Puts Private Chat Backups at Risk

Sophia Taylor

By Sophia Taylor

Published:

Hackers are targeting Signal users with a phishing scam designed to steal access to their encrypted chat backups. The attackers are pretending to be Signal’s support team and warning people that their saved messages and media could be lost unless they hand over a recovery key.

The scam is especially concerning because Signal is widely trusted for private messaging. That trust is exactly what the attackers are trying to exploit. By using an account name such as “Signal Support,” they hope users will believe the request is legitimate and share sensitive information.

According to reports, the fake message claims there is a backup “sync issue” and says the user must provide their recovery key to avoid losing access to stored chats and media. This is false. The recovery key is what protects a user’s encrypted backup, and sharing it can help attackers unlock older messages, photos, and files.

Fig 1. The Phishing attempt. (Source: Josh Rogin)

Signal has made clear that it will not contact users to ask for private account details. The company will never ask for a registration code, PIN, or recovery key. Any message asking for this information should be treated as a scam, even if it appears to come from an official-looking account.

Why the recovery key matters

Signal’s Secure Backups feature is optional and lets users save encrypted copies of their account data to Signal’s servers. These backups can include older conversations and shared media, but they are protected by a recovery key that only the user should have.

Signal says the recovery key is not shared with its servers and does not leave the user’s device. That means Signal itself cannot read or restore the backup without the key. It also means that if a criminal tricks someone into sharing it, the attacker may gain access to information the user believed was securely protected.

This makes the latest campaign different from some earlier Signal scams. In previous account takeover attempts, attackers often tried to re-register a victim’s phone number on a new device. Because of how Signal works, old messages usually would not appear on that new device. By targeting backups, attackers are trying to reach older data as well.

Who is being targeted

Some reports suggest activists and other high-risk users, including journalists and dissidents, have received these messages. However, cybersecurity experts have also indicated the tactic may be spreading beyond one community, or that more than one group of attackers may be using the same approach.

Even if you are not a public figure or activist, the advice is the same: do not share your recovery key with anyone. Phishing attacks often spread because they look urgent and official. A message warning that your data could be deleted is designed to make you act quickly without checking.

How to protect your Signal account

If you receive a message from “Signal Support” or another official-looking account asking for your recovery key, PIN, registration code, or other private details, ignore it. Do not reply with any sensitive information.

You should also enable Registration Lock in Signal. This feature adds another layer of protection by requiring your PIN before your phone number can be registered on a new device. To turn it on, open Signal, go to Settings, then Account, and enable Registration Lock.

Fig 2. Turning on the Registration Lock.

Anyone using Secure Backups should store their recovery key somewhere safe, such as a secure offline note. It should never be sent in a chat, email, or text message.

The main warning is simple: Signal’s privacy protections depend on keeping your private keys and PINs private. If someone contacts you unexpectedly and asks for them, it is not support. It is a scam.