Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
State Department Offers $10 Million Reward for Russian Hackers Who Compromised Signal and WhatsApp Accounts of U.S. Officials and Journalists

What Happened
The U.S. government has put a $10 million bounty on two Russian intelligence-linked hacker groups — tracked as UNC5792 and UNC4221 — after a months-long phishing campaign targeting Signal and WhatsApp accounts of high-value individuals.
Targets include current and former U.S. government officials, military personnel, political figures, and investigative journalists, according to the FBI.
How the Attack Works
The operation began with a relatively simple approach. Attackers sent messages impersonating Signal or WhatsApp support bots, asking users to click a link or hand over verification codes. If the target complied, the attacker silently linked their own device to the victim's account, gaining the ability to read all incoming messages going forward.
Signal's architecture does offer one protection: end-to-end encryption means that past conversations stored locally on a compromised device are not automatically readable by an attacker who links a new device. The attackers adapted around this.
According to an FBI update published last week, the campaign evolved to target backup encryption keys. Fake support messages now instruct users to "back up" their Signal conversations by navigating to Settings → Backups → Enable Backups → View Recovery Key, and then sending that long passcode back in the chat. That passcode decrypts backups stored on Signal's servers, giving attackers access to historical conversations, not just future ones.
The FBI published an initial advisory warning about this campaign in March 2026. The update last week confirmed the two Russian groups responsible and described the evolved tactics.
What the Fake Messages Look Like
The FBI released examples of the phishing text. One poses as an official Signal policy notice:
> "Signal is here. Recently, attempts to hack users of our messenger with the connection of third-party devices to the account have become more frequent... Signal updates Terms of Service & Privacy Policy, and introduces Mandatory Two-factor Verification for users. Not to lose your messages and media, set up your Signal Backup..."
Another is styled as an urgent data-loss warning:
> "Action Required: Data Recovery Needed. Your Signal Account data (messages and media) is at risk of permanent loss due to a sync issue..."
Both messages direct users through the same steps to expose their recovery key. The social engineering is straightforward but effective. The instructions mirror Signal's real interface, and the urgency framing pushes users to act before thinking.
National Security Implications
Signal and WhatsApp are widely used by government officials and journalists precisely because they are considered more secure than standard SMS or email. Targeting these platforms is a deliberate strategy to reach people who believe they have already taken reasonable precautions.
UNC5792 and UNC4221 have managed to compromise thousands of accounts, according to the FBI. This is a sustained intelligence-collection campaign that has been running for months, not a narrow, targeted operation.
A Counterargument Worth Considering
Some security researchers and civil liberties advocates raise a legitimate concern: aggressive government warnings about encrypted messenger vulnerabilities can, intentionally or not, erode public confidence in end-to-end encryption tools that protect ordinary people from surveillance, including government surveillance. If the takeaway from this campaign becomes "Signal isn't safe," that could push users toward less secure alternatives or discourage encrypted communication altogether. That outcome would benefit authoritarian governments, not just Russian hackers.
Signal's encryption architecture itself has not been broken. The attack exploits human behavior, not cryptographic weakness. Signal's protocol remains sound. The vulnerability here is social engineering, not a flaw in the encryption. Users who understand how the backup recovery key works and who do not share it with anyone are not exposed by this specific attack vector.
What the FBI Is Asking For
The $10 million reward comes through the State Department's Rewards for Justice program, which has previously offered similar bounties for information on ransomware operators and state-sponsored hackers. The program pays for information leading to the identification or location of the individuals responsible.
The FBI's practical guidance for potential targets: do not click links in unexpected support messages from Signal, WhatsApp, or any messaging platform. Never share a backup recovery key or account verification code with anyone, through any channel. Legitimate support bots for Signal and WhatsApp do not ask for these credentials.
As of June 30, 2026, federal authorities have named the Russian groups but have not publicly identified specific individuals within UNC5792 or UNC4221. Whether the $10 million reward produces actionable intelligence and whether any indictments follow remains to be seen.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.