MilikMilik

How Hackers Hijack Signal and WhatsApp Without Breaking Encryption

How Hackers Hijack Signal and WhatsApp Without Breaking Encryption
Interest|Mobile Apps

Strong Encryption, Weak Accounts: The Real Signal and WhatsApp Risk

Phishing-based account takeovers on encrypted messaging apps occur when attackers impersonate support or security teams to trick users into revealing verification codes or backup keys, allowing the attackers to link their own device or restore data and read conversations despite end-to-end encryption being intact. If you think end-to-end encryption alone keeps you safe on Signal or WhatsApp, you’re mistaken. Russian state-linked hackers have shown that they don’t need to defeat the crypto; they only need to convince you to hand over the keys. End-to-end encryption scrambles message contents between devices, but it does nothing to stop someone who successfully phishes your login, links a rogue device, or steals your backup credentials. The uncomfortable truth is that messaging app security now depends as much on your habits as on the app’s mathematics.

Inside the Attack: WhatsApp Phishing and Signal Account Hijacking

The current wave of WhatsApp phishing attacks and Signal account hijacking campaigns follows a clear pattern: attack the user, not the algorithm. A typical Signal lure is an official-looking alert claiming hackers are targeting your account, urgently walking you through steps to “secure” your Backup Recovery Key—ending with you pasting that key into the chat. That’s equivalent to handing over a master key to your entire conversation history, including backups, even if you later re-register with the same phone number. On both Signal and WhatsApp, another tactic is support-bot impersonation: attackers send messages saying your account is compromised and instruct you to click a link or share a verification code, which they then use to exploit Signal’s device-linking feature and silently add their own device to your account, reading messages in real time without breaking any encryption. The encryption held. The people didn’t.

How Hackers Hijack Signal and WhatsApp Without Breaking Encryption

Who’s Being Targeted—and Why Encryption Limits Matter

These operations are not random spam; they focus on people whose chats are geopolitically valuable. Advisories describe thousands of accounts compromised among current and former government officials, military leaders, diplomats, journalists covering Russia and Ukraine, and NGOs supporting Ukraine. According to one advisory, “Thousands of accounts have already fallen,” a stark reminder that even experienced professionals can be phished. End-to-end encryption protects the contents of messages but leaves metadata such as sender identity, timestamps, and often backups more exposed, especially when stored in third-party cloud services. Backups in many apps are not covered by end-to-end encryption, creating another path for attackers once they obtain keys or codes. This distinction between encryption strength and account security is vital: a messaging app can use excellent E2EE while still being vulnerable at the account level if its device-linking, backup, and verification flows can be weaponized against distracted or rushed users.

What You Should Do Now to Hardening Messaging App Security

If your daily life runs through Signal or WhatsApp, you need to treat account security as seriously as the apps treat encryption. First rule: never share verification codes, PINs, or Backup Recovery Keys in response to any in-app message; legitimate support does not ask for these secrets over chat. If you have already shared a Signal backup key, go straight to Signal’s settings and generate a new one; it won’t erase the damage but it will stop future access with that key. On WhatsApp, turn on end-to-end encrypted backups in Settings > Chats > Chat Backup > End-to-End Encrypted Backup, so cloud copies aren’t left weaker than your live chats. Enable two-factor protection for your accounts where available, pay attention to new-device or login alerts, and be suspicious of urgent messages pushing you toward links or security steps you didn’t request. Good habits are now part of the encryption model.

Don’t Confuse Crypto Strength with Real-World Safety

The big lesson from these campaigns is uncomfortable but necessary: messaging app security is not a product feature you can enable once and forget. End-to-end encryption is powerful, but it only covers the message contents—not metadata, not backups, and not what happens when you give an attacker your keys. Meanwhile, Russian intelligence-linked groups UNC5792 and UNC4221 have turned trusted app features—device linking, backup systems, in-app notifications—into weapons against high-value users. The US State Department’s Rewards for Justice program is now offering up to USD 10 million (approx. RM46,000,000) for information identifying members of these groups, underscoring how serious governments consider these hijacks. Users should stop treating “encrypted” as synonymous with “safe” and start asking harder questions about account takeover risks, phishing defenses, and backup handling. Your chats are only as private as the weakest link in your security behavior—and right now, that weakest link is often you.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!