MilikMilik

Hackers Are Hijacking Signal and WhatsApp Through Phishing

Hackers Are Hijacking Signal and WhatsApp Through Phishing
Interest|Mobile Apps

The uncomfortable truth: encryption can’t save you from phishing

Messaging app security against phishing attacks on WhatsApp and Signal refers to protecting user accounts and credentials from social-engineering tricks that hijack access to encrypted chats, bypassing end-to-end encryption limits by targeting people rather than the cryptographic protections built into the apps. That’s the uncomfortable truth: your messages can be perfectly scrambled in transit while an attacker sits inside your account, reading everything in real time. Russian state-linked groups have figured out that they do not need to defeat end-to-end encryption; they only need to defeat you. And thousands of accounts have already fallen. We have treated end-to-end encryption as a magic shield, a brand promise that says “you’re safe now.” In practice, it protects content, not access. When users assume encryption covers every angle of messaging app security, they become soft targets for phishing campaigns that thrive on that false confidence.

Hackers Are Hijacking Signal and WhatsApp Through Phishing

How Russian-linked hackers hijack Signal and WhatsApp without cracking the code

The core threat is Signal account hijacking and phishing attacks on WhatsApp that exploit features users trust most. Attackers pose as Signal or WhatsApp support bots, sending urgent messages claiming your account has been compromised and instructing you to click a link or share a verification code. Once you cooperate, they use Signal’s legitimate device-linking feature to silently add their own device to your account so they can read every message in real time. In the evolved phase, they walk victims through enabling Signal backups, viewing their Backup Recovery Key, and then pasting that key into the chat. Sharing that key is the messaging-app equivalent of handing your house keys to someone who slid a note under your door claiming to be your landlord. This is classic credential harvesting via malicious links and impersonation, tailored to encrypted apps. The encryption held. The people didn’t. That’s the design flaw in our behavior, not in the protocol.

Encryption’s limits: why secure messages still lead to compromised accounts

End-to-end encryption works by scrambling your messages so only the intended recipient can decrypt them, and it’s great for protecting the contents of your conversations in transit and at rest. But its limits are often misunderstood. End-to-end encryption only works on the contents of your message itself; it does not encrypt metadata like the identity of the sender and receiver, their location, or timestamps. More importantly in this context, it does nothing to secure your login credentials or backup keys. When you back up messages to third-party cloud storage, those backups are no longer protected end-to-end and there is a window where they can be intercepted by WhatsApp, Apple, or Google. According to one analysis, “E2EE does not protect you against spyware, keyloggers, or other kinds of malicious attacks directed directly at your phone or workstation.” The same goes for social engineering: encryption protects message content, not the decisions you make when a fake support alert demands urgent action.

Who is being targeted—and why authorities are sounding the alarm

These attacks are not random drive-by scams. Russian intelligence operatives tied to named groups are actively targeting Signal and WhatsApp users through social engineering campaigns. FBI and CISA advisories identify current and former government officials, military leadership, diplomats, journalists covering Russia and Ukraine, and NGOs supporting Ukraine among the targets. The goal is obvious: gain live access to sensitive conversations without needing to break the underlying cryptography. The US State Department’s Rewards for Justice program is now offering up to USD 10 million (approx. RM47,000,000) for information identifying members of two Russian state-linked groups, UNC5792, tied to FSB Border Guards, and UNC4221, linked to military services, according to the FBI. That bounty is a quotable signal of severity. When authorities put that amount of money on the table, they are telling you this threat is not theoretical. It is active, it is strategic, and it thrives wherever users overtrust encryption and under-protect their accounts.

How to spot and stop account hijacking before it happens

The immediate lesson: treat account security as seriously as message content. Common phishing tactics include fake login pages, SMS or in-app impersonation, and credential harvesting through malicious links. Here’s what you should do now. Never share a verification code, PIN, or backup recovery key in response to any in-app message; legitimate app support does not work that way. If you already shared a Signal Backup Recovery Key, open settings and generate a fresh one immediately to invalidate the old key. Harden your messaging app security with built-in options. On WhatsApp, go to Settings > Chats > Chat Backup > End-to-End Encrypted Backup to enable encryption during the backup process. Though many enhanced security features are opt-in and not enabled by default, they are there to reduce the attack surface when you exchange sensitive information. The bottom line: end-to-end encryption is powerful, but it only does its job if you do yours—by refusing to hand over the keys to your own encrypted kingdom.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!