---
title: "Signal: a phishing campaign targets users' backups"
description: A phishing campaign targets Signal users directly within the app. Mobile phishing is impersonating everyday services.
image: https://blog.pradeo.com/hubfs/Template%20article%20(30)-1.png
---

[![pradeo\_logo\_color](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_color.png?width=220&height=33&name=pradeo_logo_color.png "pradeo_logo_color")](https://pradeo.com)

- Solutions 
    - [Mobile Threat Defense](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Secure Private Store](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
    - [Mobile Application Compliance Audit](https://pradeo.com/en/solutions/mobile-application-security/application-compliance-audit/)
    - [Runtime Application Self Protection](https://pradeo.com/en/solutions/mobile-application-security/rasp/)
    - [Shielding](https://pradeo.com/en/solutions/mobile-application-security/application-shielding/)
    - [Application Security Testing](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
- Use cases 
    - [Cybersecurity in MDM/ UEM](https://pradeo.com/en/use-cases/cybersecurity-in-mdm-uem/)
    - [Securing mobile devices](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Securing Mobile Applications](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
    - [Malware / leakware protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Phishing protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Ensuring compliance for applications](https://pradeo.com/en/compliance/)
    - [Ensuring compliance for mobile fleet](https://pradeo.com/en/compliance/)
    - [Securing BYOD](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
- [Become partner](https://pradeo.com/become-partner/)
- Resources 
    - [Solution briefs](https://pradeo.com/en/resources/?solution-briefs)
    - [Customer Cases](https://pradeo.com/en/resources/?customer-cases)
    - [Integration briefs](https://pradeo.com/en/resources/?integration-briefs)
    - [White Papers](https://pradeo.com/en/resources/?white-papers)
    - [Analyst reports & guides](https://pradeo.com/en/resources/?analyst-reports-guides)
    - [On demand webcast](https://pradeo.com/en/resources/?webcasts-on-demand)
    - [About us](https://pradeo.com/en/about/)
- [Blog](https://blog.pradeo.com/)
- [Contact](https://pradeo.com/contact/)
- en 
    - [**FR**](https://blog.pradeo.com/fr)
    - [**DE**](https://blog.pradeo.com/de)

### Topics

- Select a Topic

### Stay up to date

 SUBSCRIBE TO OUR BLOG

### Stay up to date

[Security Alert](https://blog.pradeo.com/topic/security-alert) [News](https://blog.pradeo.com/topic/news)

# Signal: a phishing campaign targets users' backups

![Picture of Clara Campos](https://blog.pradeo.com/hubfs/1711636314862%20(1).jpg)

 By [Clara Campos](https://blog.pradeo.com/author/clara-campos) on June, 4 2026

[mailto:?subject=Take%20a%20look%20at%20this%20article](mailto:?subject=Take%20a%20look%20at%20this%20article)

![](https://blog.pradeo.com/hubfs/Template%20article%20(30)-1.png)

Discovered in late May 2026, a new phishing campaign targets [Signal](https://www.malwarebytes.com/blog/news/2026/05/signal-users-targeted-in-backup-stealing-phishing-attacks)users with the aim of stealing victims' backup recovery keys. What sets this attack apart is that the fraudulent message is sent directly within the Signal mobile application. A development that shows mobile phishing is now infiltrating even encrypted messaging apps.

## Mobile phishing on the rise

This new campaign is far from an isolated case. [Pradeo's 2026 Mobile Security Report](https://pradeo.com/en/form/mobile-security-report-2026/) revealed that a professional mobile device receives an average of **288 phishing attempts per year**, and that **45% of users click** on the links they receive.   
Smishing (SMS phishing) remains the most common vector, accounting for 55% of mobile phishing.

The trend is towards diversification of channels. Attacks no longer come solely through email, they are infiltrating SMS, instant messaging apps, and QR codes. And they share an increasingly common trait: attackers impersonate a trusted authority figure, technical support, public services, financial institutions, to push their victims into acting without verification.

 

## Signal under attack

The attack is straightforward. Attackers send a message directly within Signal from an account presenting itself as "Signal Support". The message claims that the user's data is at risk of being lost due to a synchronisation issue, and contains a link redirecting the victim to a page outside the application, where they are asked to enter their recovery key.

This key is what allows the decryption of backups stored on Signal's servers. Stealing the key is the first step, the attackers must then gain control of the account to access the backups. An approach that no longer targets only ongoing conversations, but also the entirety of the archived message history.

Identified targets reportedly include [journalists, activists](https://techcrunch.com/2026/05/28/hackers-are-trying-to-steal-signal-users-backups-in-new-wave-of-phishing-attacks/), but also individuals outside activist circles, suggesting a broader campaign than initially thought.

This attack on Signal is not an isolated incident. In March 2026, the [FBI and CISA had already issued a joint advisory](https://www.malwarebytes.com/blog/news/2026/03/fbi-cisa-warn-of-russian-hackers-hijacking-signal-and-whatsapp-accounts) warning of campaigns linked to Russian intelligence targeting Signal and WhatsApp, using QR codes and device-linking requests. In Germany, politicians, military personnel and journalists had been targeted [using the same techniques,](https://therecord.media/germany-warns-phishing-campaign-signal-gov-officials-journalists) and [CERT-EU](https://cert.europa.eu/publications/threat-intelligence/cb26-03/) confirmed that the campaign extended to several European countries.

Signal reminds users that it will never reach out first and will never ask for a recovery key, PIN code or registration code. Any message claiming to be from "Signal Support" should be ignored.

 

## When phishing impersonates everyday services

The mechanism exploited against Signal, impersonating a trusted authority figure, is the same one used at scale to imitate well-known services. Attackers exploit context (tax season, parcel deliveries, administrative renewals) to trigger an immediate reaction.

In the United Kingdom, the [National Cyber Security Centre (NCSC)](https://securityjournaluk.com/phishing-attack-alert-2026/) reported a significant increase in campaigns impersonating HMRC (the tax authority), Royal Mail, the NHS and the DVLA in early 2026. Phishing-related losses exceeded £1.2 billion in 2025 according to UK Finance.

A [coordinated smishing operation was also uncovered in May 2026 across 19 countries](https://hunt.io/blog/massive-smishing-campaign-governments-postal-telecoms) in Europe, the Americas and the Caucasus. The investigation traced 1,628 malicious URLs linked to a single infrastructure, targeting government payment portals, delivery services, road police portals, tax authorities and telecom operators. All using the same mechanism, fraudulent SMS impersonating trusted institutions to redirect victims to fake payment pages.

 

## How Pradeo protects against mobile phishing

With phishing campaigns growing in number and sophistication, securing mobile devices is essential to protect corporate data.

[Pradeo Mobile Threat Defense](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/) protects mobile devices against all threat vectors, including phishing. The solution automatically detects and blocks all malicious links received on the mobile device (SMS, instant messaging, QR codes…), preventing the user from clicking before infection or data theft occurs.

###### About The Author

[More from this author](https://blog.pradeo.com/author/clara-campos)

![](https://blog.pradeo.com/hs-fs/hubfs/1711636314862%20(1).jpg?height=100&name=1711636314862%20(1).jpg)

###### Clara Campos

#### Recommended articles

[![Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/hubfs/Template%20article%20(34).png)](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

###### [Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 \- June 30, 2026

[![2026 World Cup: Cyberattacks Target Fans' Mobile Devices](https://blog.pradeo.com/hubfs/Template%20article%20(31)-1.png)](https://blog.pradeo.com/2026-world-cup-cyberattacks-target-fans-mobile-devices)

###### [2026 World Cup: Cyberattacks Target Fans' Mobile Devices](https://blog.pradeo.com/2026-world-cup-cyberattacks-target-fans-mobile-devices)

 \- June 11, 2026

#### Recommended articles

### Popular articles

### Stay up to date

### Recent articles

### Articles récents

[Fence integrates Pradeo's technology to secure its clients' mobile fleets](https://blog.pradeo.com/fence-integrates-pradeos-technology-to-secure-its-clients-mobile-fleets-1)

 \- 4 June, 2026

[RedHook: the banking trojan that grants itself system-level access on Android](https://blog.pradeo.com/redhook-the-banking-trojan-that-grants-itself-system-level-access-on-android)

 \- 4 June, 2026

[What Google's latest report reveals about mobile threats](https://blog.pradeo.com/what-googles-latest-report-reveals-about-mobile-threats)

 \- 4 June, 2026

[Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 \- 4 June, 2026

[Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 \- 4 June, 2026

### Topics

- [Mobile Security (56)](https://blog.pradeo.com/topic/mobile-security)
- [Mobile Application Security (46)](https://blog.pradeo.com/topic/mobile-application-security)
- [Expertise (31)](https://blog.pradeo.com/topic/expertise)
- [Security Alert (30)](https://blog.pradeo.com/topic/security-alert)
- [Cybersecurity (29)](https://blog.pradeo.com/topic/cybersecurity)
- [News (28)](https://blog.pradeo.com/topic/news)
- [Partners (25)](https://blog.pradeo.com/topic/partners)
- [Corporate (12)](https://blog.pradeo.com/topic/corporate)
- [Events (4)](https://blog.pradeo.com/topic/events)
- [Actualité (2)](https://blog.pradeo.com/topic/actualité)
- [predictions (2)](https://blog.pradeo.com/topic/predictions)
- [cyberattack (1)](https://blog.pradeo.com/topic/cyberattack)

see all

[![New Call-to-action](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f)

### Get in touch with mobile security experts

[Contact us](https://www.pradeo.com/en-US/contact-us)

[![](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_white_square.png?width=90&height=74&name=pradeo_logo_white_square.png)](https://pradeo.com)

European leader in mobile security, Pradeo protects business mobile devices and applications.

[Read More](https://www.pradeo.com/en-US/)

- [Resources](https://www.pradeo.com/en-US/pradeo-ressources#white_papers)
- [UEM security](https://www.pradeo.com/en-US/uem-mdm-security)
- [Use cases](https://www.pradeo.com/en-US/pradeo-ressources#use-case)
- [Data protection](https://www.pradeo.com/en-US/mobile-data-privacy-regulation)
- [Contact us](https://www.pradeo.com/en-US/contact-us)

- [Mobile Threat Defense](https://www.pradeo.com/en-US/mobile-threat-defense)
- [Mobile Application Security Testing](https://www.pradeo.com/en-US/application-security-testing)
- [In-App Protection](https://www.pradeo.com/en-US/in-app-protection)
- [Secure Private Store](https://www.pradeo.com/en-US/private-app-store)
- [Mobile Threat Intelligence](https://www.pradeo.com/en-US/mobile-threat-intelligence#perso-threat-intelligence)

![email.svg](https://cdn2.hubspot.net/hubfs/3067823/awwal/email.svg "email.svg")

[contact@pradeo.com](mailto:contact@pradeo.com)

Copyright @ 2022. All Right Reserved.

- <https://www.linkedin.com/company/pradeo-security-systems>
- <https://twitter.com/pradeo>
- <https://www.youtube.com/channel/UCD7hgYE8WuipxJtxsHDUdMA>

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Clara Campos"
  },
  "dateModified" : "June 4, 2026, 7:46:39 AM",
  "datePublished" : "2026-06-04 07:46:39",
  "description" : "A phishing campaign targets Signal users directly within the app. Mobile phishing is impersonating everyday services.",
  "headline" : "Signal: a phishing campaign targets users' backups",
  "image" : {
    "@type" : "ImageObject",
    "url" : "https://2378615.fs1.hubspotusercontent-eu1.net/hubfs/2378615/Template%20article%20%2830%29-1.png"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://2378615.fs1.hubspotusercontent-eu1.net/hubfs/2378615/Logo%20Pradeo%20D%C3%A9grad%C3%A9%20Long%20Couleurs.svg"
    },
    "name" : "Pradeo"
  }
}
```