US offers $10 million for info on group behind Signal and WhatsApp hacking spree

Russian state-sponsored cyber groups (UNC5792 and UNC4221) have compromised thousands of Signal and WhatsApp accounts belonging to US government officials, military personnel, and journalists through sophisticated phishing campaigns, with the US offering a $10 million reward for intelligence on the perpetrators. This represents a critical threat to organizational security as even well-trained personnel remain vulnerable to social engineering, and attackers can gain access to encrypted communications through account takeover without exploiting platform vulnerabilities. IT organizations must recognize that end-to-end encryption alone is insufficient protection and that user authentication and account security are now primary attack surfaces requiring enhanced monitoring and controls.

Dan GoodinArs Technica2 min read
Read full article
US offers $10 million for info on group behind Signal and WhatsApp hacking spree
Federal authorities are offering a reward of up to $10 million for information leading to the identification or location of a Russian state cyber group that has compromised thousands of Signal and WhatsApp accounts belonging to investigative reporters and US government employees. The operation has been active since at least March, when the FBI published an advisory warning of ongoing phishing campaigns targeting high-value targets by attackers associated with Russian intelligence services. Messages masquerading as automated support communications ask that users click a link or provide verification codes or account passcodes. In the event the user complies, they unknowingly link the attacker's device to their account or have their account completely taken over and are locked out. Read full article Comments