started · updated
NÚKIB warns of Russian-linked phishing attacks on Signal users
The Czech National Cyber and Information Security Agency (NÚKIB) has issued a warning regarding phishing attacks targeting users of the Signal encrypted messaging application. These attacks are attributed to actors primarily linked to Russia and are specifically targeting politicians, government officials, and security experts.
Rather than attempting to break Signal’s encryption, attackers are utilizing social engineering techniques. Common methods include sending fraudulent messages disguised as Signal support requesting a PIN code, or using malicious links and fake QR codes presented as group invitations. The goal is to trick users into linking an unauthorized device to their account or revealing personal identification numbers.
Similar campaigns have been reported earlier this year in the Netherlands, Germany, and Ukraine. NÚKIB emphasizes that Signal will never ask for a PIN or login credentials through a message, and urges all users to remain vigilant when receiving unsolicited messages or connection requests.
Entities
National Cyber and Information Security Agency · NÚKIB · Russia · Signal