MilikMilik

US Bounty on Messaging App Hackers Shows Encryption Is Not Your Weak Point

US Bounty on Messaging App Hackers Shows Encryption Is Not Your Weak Point
Interest|Mobile Apps

Phishing, Not Broken Encryption, Is the Real Threat to Your Chats

WhatsApp phishing attacks and Signal account hijacking refer to campaigns where attackers impersonate official support, trick users into sharing verification codes or backup keys, and silently link attacker-controlled devices to secure messaging accounts without breaking end-to-end encryption. The US government is offering a reward of up to USD 10 million (approx. RM46,000,000) for information that helps identify or locate members of a Russian state-linked cyber group accused of compromising thousands of Signal and WhatsApp accounts. This is not a story about cracked ciphers; it is a warning that people, not protocols, are the weakest link in messaging app security. If you think encrypted apps make you untouchable, this bounty is the loudest possible signal that your habits can still expose everything.

US Bounty on Messaging App Hackers Shows Encryption Is Not Your Weak Point

How Russian Operators Turn Trust Features into Attack Vectors

Russian state-linked groups UNC5792 and UNC4221 did not punch through Signal or WhatsApp’s encryption; they weaponized the apps’ own convenience features instead. Their phishing messages look like automated support alerts, warning of account hacks or data loss, then pushing you to click a link, share a verification code, or provide an account passcode. Follow the script and you unknowingly connect an attacker-controlled device to your account, giving them live access to new messages and, in some cases, full control while you are locked out. In the evolved phase, victims are walked through creating Signal backups and viewing their Backup Recovery Key, then told to paste that key into the chat. That single mistake hands over entire conversation histories. The encryption held; users did not.

Who Is Being Targeted, and Why the Bounty Matters for Everyone

These phishing campaigns are not random scams; they focus on people whose private chats can shift geopolitics. Targets include current and former government officials, military personnel and leadership, diplomats, political figures, journalists covering Russia and Ukraine, and NGOs supporting Ukraine. Thousands of accounts have already been compromised on commercial messaging applications. When high-value figures lose control of WhatsApp and Signal, the fallout ripples through entire networks of contacts, sources, and family members. By putting up to USD 10 million (approx. RM46,000,000) on the table for information on UNC5792 and UNC4221, the US State Department is making a blunt statement: "The attackers did not exploit any security weakness in the platforms’ encryption systems," yet they have still compromised thousands of individual accounts. This bounty is less about punishing two groups and more about drawing a red line around messaging app compromise as a national and global security problem.

The Hard Truth: You Are the Security Feature That Keeps Failing

Every detail of these campaigns underscores one uncomfortable reality: social engineering and credential theft can defeat any encrypted app when users treat in-app messages as trustworthy by default. The attackers pose as support bots, inject urgency, and rely on tired, distracted targets to react first and think later. They do not need zero-day exploits when they can talk you into handing over verification codes or recovery keys. Legitimate support services for commercial messaging applications do not ask users to provide verification codes inside the app or send links demanding that you verify or restore your account. Yet thousands still complied. If investigative journalists, diplomats, and military personnel are falling for this, ordinary users should stop assuming they are too savvy to be fooled. Messaging app security fails when we treat any “official-looking” prompt as gospel.

Practical Phishing Protection Tips to Lock Down WhatsApp and Signal

The fix is not more fear; it is better habits. For WhatsApp phishing attacks and Signal account hijacking, the most effective defense is refusing to act on unverified prompts. Never share verification codes, PINs, or backup recovery keys in response to any in-app message; legitimate app support does not work that way. Users should never provide a verification code without confirming that the request came through an official communication channel. If you already shared a Signal backup key, you must generate a new Backup Recovery Key in Signal settings; this invalidates the old key for future backup downloads. Turn on two-factor protection or registration locks where available, and verify that “support” messages are genuine by checking official websites or known channels. Users should also avoid reacting immediately to messages that create a sense of urgency; even legitimate requests rarely collapse if you wait an hour or two. In short: slow down, verify, and lock down your linked devices before an attacker does it for you.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!