US Posts $10 Million Reward Over Russian-Intelligence Signal and WhatsApp Phishing
A coordinated US law-enforcement push against a Russian-intelligence messaging-app campaign pairs a Rewards for Justice bounty with an FBI advisory on Signal backup-recovery-key theft.
A coordinated US law-enforcement push against a Russian-intelligence messaging-app campaign pairs a Rewards for Justice bounty with an FBI advisory on Signal backup-recovery-key theft.
WASHINGTON — The US State Department on or about June 29, 2026 posted a reward of up to $10 million for information on the people behind a Russian-intelligence-linked phishing campaign against Signal and WhatsApp accounts, escalating a months-long government response into a public bounty. The offer, made through the department's Rewards for Justice program, names two clusters tracked by researchers as UNC5792 and UNC4221, which US authorities associate with Russia's Federal Security Service (FSB) and military services respectively. It landed alongside a refreshed FBI advisory warning that the same operators have changed their phishing playbook to target a more durable prize: the Signal Backup Recovery Key.
The pairing of a financial reward with a defender-facing advisory gives the campaign a distinctly law-enforcement framing. Rather than a one-off disclosure, the US action treats the messaging-app activity as a continuing counter-intelligence problem aimed at high-value targets, and it follows a June 28 disclosure from Ukraine's CERT-UA documenting a closely related effort to harvest messaging credentials. Together the two notices sketch a coordinated, cross-border view of how Russian intelligence services have leaned on secure-messaging apps as a collection channel.
What the State Department Posted
The Rewards for Justice program, run by the State Department's Diplomatic Security Service, announced a reward of up to $10 million for information leading to the identification or location of people who, acting on behalf of a foreign government, have engaged in malicious cyber activity against US critical infrastructure. In this instance the notice points specifically at two clusters tracked in industry reporting as UNC5792 and UNC4221, which US authorities tie to Russian intelligence and military services.
According to the department, the activity at issue is a widespread phishing campaign aimed at the Signal and WhatsApp accounts of US government officials, military leaders, and allied personnel. Investigators describe operators abusing legitimate features of the apps — most notably the device-linking workflow — to gain access to private messages and contact lists. The reward seeks information on the names, locations, and affiliations of the actors and their support personnel, including any connections to Russian intelligence agencies, contractors, and third-party service providers.
Rewards for Justice is a long-running State Department program originally created for counter-terrorism tips and expanded in recent years to cover foreign state-sponsored cyber activity against the United States. Posting a bounty does not constitute an indictment, and the department has not, in this notice, attached individual names to the clusters; the offer is structured to elicit the kind of identifying detail that could support future attribution or charges.
The FBI Parallel Advisory in Context
Released alongside the reward was a refreshed FBI advisory, published as PSA I-062626-PSA, that updates a March 2026 warning about Russian intelligence phishing of Signal accounts. The headline change is a shift in objective. Earlier waves of the campaign chased one-time SMS verification codes and account PINs, or used doctored "group invite" links that silently linked an attacker-controlled device to a target's account. The updated advisory says the operators now walk targets through enabling Signal backups, opening their Signal Backup Recovery Key, and pasting it into the chat.
That distinction matters for defenders because of what the recovery key unlocks. Where a stolen verification code or a linked device tends to yield access that can be revoked — by unlinking the device or re-registering the number — the recovery key is tied to the encrypted backup itself. The FBI advisory warns that once a target hands the key over, an operator can restore the account's backup and read its private and group message history, and that the key continues to work even if the target later creates a new account on the same phone number. The relevant defensive guidance is therefore narrow and concrete: a Signal Backup Recovery Key should be treated as a long-lived secret that legitimate support staff will never ask for, and it should never be typed or pasted into a chat in response to a prompt, however urgent the message appears.
The advisory reportedly prints two sample lures to help recipients recognize the pattern: one framed as a mandatory two-factor-authentication rollout, the other as an urgent "data recovery" fix for messages supposedly at risk of being lost. Both rely on a posed Signal support identity and on manufactured time pressure — the familiar mechanics of credential phishing applied to a secure-messaging context that many high-risk users assume is out of reach.
Cross-Reference: the June 28 Ukraine-CERT-UA Disclosure
The US notices do not stand alone. A day earlier, on June 28, 2026, Ukraine's Computer Emergency Response Team, CERT-UA, documented a related effort to harvest messaging-app credentials from Ukrainian targets, attributing the activity to Russian intelligence. Read together, the two disclosures describe overlapping tradecraft — social-engineering lures that turn the device-linking and backup features of secure messengers into a collection channel — pursued against parallel sets of high-value targets on both sides of the Atlantic.
The clustering is consistent with how Russian intelligence services have been described targeting messaging platforms over the past two years. Public reporting has previously tied separate Russia-aligned groups to Signal device-linking abuse, and European governments have made their own attributions: Germany, for one, has formally blamed Russia for Signal phishing aimed at members of its parliament. The Rewards for Justice notice and the CERT-UA advisory add US and Ukrainian government weight to a picture that had, until recently, been assembled largely from private-sector threat research.
That convergence is the practical significance of the timing. Two government bodies in two countries, within a day of each other, characterized secure-messaging compromise as a state-directed intelligence operation rather than ordinary cybercrime — a framing that aligns with broader allied efforts, including a recent Five Eyes statement on emerging cyber risks, to treat nation-state activity against trusted software and platforms as a shared problem.
Messaging-App User Awareness for High-Risk Roles
For the audiences the campaign targets — current and former government officials, military personnel, political figures, journalists, and officials in Ukraine — the advisory translates into a small set of habits rather than a software fix. The first is recognizing that the apps themselves are not broken. Signal's and WhatsApp's end-to-end encryption is not what is being defeated here; the operators are persuading targets to perform legitimate actions, such as linking a new device or revealing a backup key, that hand over access. The defense is social and procedural, aimed at the moment a user is asked to do something with their account.
Concretely, the guidance reduces to a few checks that apply regardless of which lure arrives. Treat any unsolicited message that invokes account security, a mandatory update, or data loss as suspect, especially when it carries time pressure or a link. Never share a verification code, account PIN, or — most importantly under the updated advisory — a Signal Backup Recovery Key in response to a prompt; no legitimate support process requires a user to paste that key into a conversation. Periodically review the list of linked devices in each messaging app and remove any that are unfamiliar, since a silently linked device is a primary route to a target's message stream.
High-risk users can also harden the surface in advance. Enabling a registration lock or equivalent PIN, scrutinizing group-invite links before acting on them, and confirming any account-related request through a separate, trusted channel all raise the cost of the social-engineering step the campaign depends on. None of these measures is novel, but the FBI advisory's value is in directing them at a specific, currently active technique against a specific population that is unusually likely to be targeted.
Open Questions
Several aspects of the US action remain open. The Rewards for Justice notice associates UNC5792 and UNC4221 with Russian intelligence and military services but does not, in public materials, name individuals or attach criminal charges; whether the bounty produces identifying information that supports an indictment is, by design, not yet knowable. The scale of the campaign is described in reporting by CyberScoop and Dark Reading as having affected thousands of messaging accounts, but a precise count, and a full accounting of which organizations and individuals were ultimately accessed, has not been published.
It is also not established from the public notices alone how directly the US-targeted activity and the CERT-UA-documented effort are operationally linked, beyond shared tradecraft and a common adversary. The two disclosures are best read as complementary rather than as a single confirmed operation. Similarly, while the FBI advisory describes the backup-recovery-key technique in detail, the notices do not quantify how many targets fell for it versus the earlier verification-code lures.
What is firmly established is enough to act on. A US government program has put a public price on information about two named Russian-intelligence-linked clusters; a federal advisory has documented a specific, current phishing technique against secure-messaging apps; and a partner government issued a closely related warning a day earlier. For the high-risk individuals these notices address, the durable takeaway is procedural — guard the recovery key, scrutinize account-security prompts, and audit linked devices — and it holds regardless of how the attribution and any future charges ultimately resolve.
The CyberSignal Analysis
The reported facts above are the US government's; what follows is The CyberSignal's editorial reading of what defenders and high-risk users should take from them. None of the judgments below are new reported facts.
Signal 01 — A Bounty Signals Priority, Not a Fix
A $10 million reward is a statement of intent, not a control. Our reading is that the Rewards for Justice posting tells defenders how seriously the US government now rates this campaign — enough to attach a headline price to identifying the operators — but it changes nothing about the exposure of an individual high-risk user tomorrow morning. The bounty is aimed at attribution and deterrence over a long horizon; the phishing lure arriving in someone's chat is a near-term problem that no reward addresses.
The practical implication is to read the reward as a prioritization cue rather than a countermeasure. When a government elevates a messaging-app campaign to the same program it uses for its most serious foreign-threat cases, that is a prompt for targeted populations to revisit their own habits now, on the assumption that the activity is active and ongoing, not winding down. The deterrent value accrues later; the defensive work is entirely on the user's side and entirely present-tense.
Signal 02 — The Backup Recovery Key Is the Durable-Access Prize to Protect
The most important shift the FBI advisory documents is a move away from perishable secrets toward a durable one. A stolen verification code expires; a linked device can be unlinked; a re-registered number resets much of the exposure. The Signal Backup Recovery Key is different in kind — it is tied to the encrypted backup itself and, per the advisory, keeps working even after a target creates a new account on the same number. Our assessment is that this single change is what makes the current wave worth a distinct warning: the operators are now optimizing for access that survives the usual remediation steps.
That reframes the defensive priority for anyone in a targeted role. The recovery key should be modeled as a long-lived credential on par with a password manager's master key, not as a routine app setting — something that legitimate support will never ask for and that must never be pasted into a conversation. The durability of what it unlocks is precisely why it belongs in the small set of secrets a high-risk user treats as never-shareable, regardless of how urgent or official the prompt appears.
Signal 03 — High-Risk Roles Need Role-Specific Habits, Not Generic Anti-Phishing
Standard anti-phishing advice assumes the payload is a malicious link or attachment. Here it is not: the operators persuade targets to perform legitimate, sanctioned actions — linking a device, revealing a backup key — inside apps whose encryption is not being defeated. Our reading is that the populations these notices name — government officials, military personnel, journalists, political figures, and Ukrainian officials — need guidance calibrated to that reality, because the usual "don't click suspicious links" reflex does not fire when the ask is to complete a normal in-app workflow.
The role-specific habits that follow are narrow and repeatable: audit linked devices on a schedule and remove anything unfamiliar, confirm any account-security request through a separate trusted channel before acting, and treat verification codes, PINs, and the recovery key as things no legitimate process ever requests in-chat. For individuals unusually likely to be targeted, our assessment is that building these into routine — rather than reacting lure by lure — is the defense that actually scales to a campaign designed to look like ordinary account maintenance.