Visualização normal

Antes de ontemStream principal
  • ✇Security Affairs
  • EU Targets FSB-Linked Hackers in New Sanctions Over Cyber Sabotage Pierluigi Paganini
    EU sanctions target nine people and four entities tied to Russia’s FSB over a 15-year cyberespionage and critical infrastructure sabotage campaign. The European Union imposed sanctions on Monday targeting nine individuals and four entities linked to a Russian cyberespionage and sabotage operation that Brussels says has been running since 2010. The targets include Russian military intelligence officers, hackers, and private companies. ù The European Council said the sanctioned actors helpe
     

EU Targets FSB-Linked Hackers in New Sanctions Over Cyber Sabotage

13 de Julho de 2026, 09:23

EU sanctions target nine people and four entities tied to Russia’s FSB over a 15-year cyberespionage and critical infrastructure sabotage campaign.

The European Union imposed sanctions on Monday targeting nine individuals and four entities linked to a Russian cyberespionage and sabotage operation that Brussels says has been running since 2010. The targets include Russian military intelligence officers, hackers, and private companies. ù

The European Council said the sanctioned actors helped Russia destabilize the EU and its partners. The cyberespionage campaign affected at least nine countries.

The European Council stopped short of publishing their names in its public statement, which is an unusual level of restraint for a sanctions announcement.

The sanctions focus on the FSB ‘s 16th Center, the signals intelligence division of Russia’s Federal Security Service.

“The EU focused its measures on the 16th Center of Russia’s Federal Security Service, or FSB. It said the FSB has been “controlling a variety of cyberthreat groups,” and said it “has conducted a wide range of malicious cyberactivities with growing severity.”” EU states.

Fifteen years of documented activity is a long time for a sanctions package to catch up with, but here we are.

The European Council named nine countries as confirmed targets: France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland, described as “among others.”

“The names of the individuals and entities — which usually companies, government agencies, banks or other organizations — were not listed on the statement.” reports the Associated Press. It said France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland, “among others” have been targeted.”

The operations didn’t just involve stealing information. The EU explicitly accused the network of carrying out sabotage against critical infrastructure, including heating systems and power plants, alongside more conventional espionage against government targets.

Foreign Minister Jean-Noël Barrot said strategic infrastructure, ministries, businesses, and Poland’s railway network were targeted. France and Germany summoned the Russian ambassador, while the EU is preparing sanctions against nine individuals and four entities. Paris also highlighted the role of Viginum and ANSSI in countering cyber threats and foreign digital interference.

Barrot intends to summon the Russian ambassador in the coming days.

Poland’s railway infrastructure has been referenced in multiple European government warnings about Russian physical and digital sabotage operations over the past two years.

Monday’s action didn’t emerge from nowhere. In April, Sweden attributed a cyberattack on a heating plant to a pro-Russian group with links to Russian security and intelligence services. Around the same time, officials in Poland, Norway, Denmark, and Latvia were warning publicly that Russia was systematically attacking critical infrastructure across Europe. Several countries have also accused Russian-linked actors of attempting to interfere with their elections using a combination of cyberattacks and disinformation.

The formal attribution of a single coordinated network spanning at least nine countries and 15 years represents a deliberate escalation in how the EU is publicly framing Russia’s cyber operations. Whether sanctions against unnamed individuals and unlisted companies produce any practical deterrence is a different question, and one that European officials probably didn’t expect to answer favorably when they signed off on this package.

In January 2025, the European Union sanctioned three members of Russia’s GRU Unit 29155, Nikolay Korchagin, Vitaly Shevchenko, and Yuriy Denisov, for cyberattacks targeting Estonian government institutions in 2020. The operations enabled unauthorized access to ministries’ systems and the theft of thousands of confidential documents, including cybersecurity strategies and sensitive state information.

The EU highlighted the growing role of cyber operations as a tool of hybrid warfare and destabilization. The U.S. and allies have linked unit 29155 to global espionage, sabotage, and attacks targeting critical infrastructure across government, energy, finance, transport, and healthcare sectors.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, FSB)

  • ✇Security Affairs
  • New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages Pierluigi Paganini
    FBI warns Russian spies now target Signal Backup Recovery Keys, enabling access to message history and long-term account takeover. The FBI and CISA updated their March 2026 warning about Russian intelligence phishing campaigns, and the new advisory adds a detail that wasn’t in the original: the operators have shifted their primary objective from stealing verification codes to stealing Signal Backup Recovery Keys. The March warning covered FSB-linked groups targeting government officials,
     

New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages

27 de Junho de 2026, 13:08

FBI warns Russian spies now target Signal Backup Recovery Keys, enabling access to message history and long-term account takeover.

The FBI and CISA updated their March 2026 warning about Russian intelligence phishing campaigns, and the new advisory adds a detail that wasn’t in the original: the operators have shifted their primary objective from stealing verification codes to stealing Signal Backup Recovery Keys.

The March warning covered FSB-linked groups targeting government officials, military personnel, journalists, and Ukrainian officials through fake Signal support messages. The June update gives those groups public tracking names: UNC5792 and UNC4221, both linked to Russian Federal Security Service officers including those embedded with FSB Border Guards and others working on behalf of Russian military services.

“RIS cyber threat actors have compromised individual CMA accounts, but not the CMA’s encryption or the application itself. To date, this activity has been publicly tracked as UNC5792 and UNC4221.” reads the PSA alert published by the FBI.. “RIS cyber threat actors continue to masquerade as automated CMA support accounts in updated phishing messages but have evolved their tactics to attempt to elicit victims’ Backup Recovery Keys.”

The earlier version of this campaign asked targets for SMS verification codes, account PINs, or tricked them into clicking doctored group invite links that silently linked an attacker’s device to the account. The new version is more damaging. The phishing message walks the target step by step through enabling Signal backups, navigating to the Recovery Key, and pasting it into the chat. Two sample messages are printed in the advisory: one dressed as a mandatory two-factor rollout announcement, the other as an urgent data recovery warning claiming messages are at risk of permanent loss.

The Recovery Key is what makes this particularly serious.

“RIS cyber threat actors continue to elicit victims’ verification codes and account PINs (see Figure 1). If a targeted user backs up their CMA messages as directed in Figure 1 and later provides their Backup Recovery Key (see Figure 2), RIS cyber threat actors can view the account’s historical messages, private and group messages, and take over the victim’s account.” continues the alert.

A backup recovery key doesn’t just unlock one session. It unlocks the entire message archive, and unlike a stolen code that expires, this key keeps working.

“If a victim inadvertently shares their Backup Recovery Key, that same key remains valid even if they create a new account following the compromise using the same phone number.” continues the report. “Consequently, the actor could potentially use the compromised key to take over the new account in the future as well.”

Making a new account doesn’t help if the old key still works against it. The only fix is generating a new key through Settings, which invalidates the old one for future backup downloads. That doesn’t recover anything the attacker already pulled, and the advisory is clear about that.

The FBI and CISA are unambiguous on one point that tends to get lost in coverage of these incidents: none of this breaks Signal’s encryption or the application itself. The attackers aren’t cracking anything. They’re walking through a legitimate feature with a key the user handed them, which is a completely different problem with a completely different solution.

Alongside the advisory, the State Department’s Rewards for Justice program announced it’s offering up to $10 million for information on UNC5792. The activity overlaps with warnings issued earlier this year by Dutch intelligence, Germany’s BfV and BSI, and France’s ANSSI, and it builds on Google Threat Intelligence Group’s documentation of UNC5792 abusing Signal’s linked-device feature in early 2025. The same tradecraft has since been observed against WhatsApp and Telegram.

For anyone using Signal who works in government, security, journalism, or military-adjacent roles, the advisory’s guidance is direct. Treat any in-app message claiming to be Signal support as hostile: real support doesn’t contact users inside the app to ask for codes, PINs, or Recovery Keys.

Open Settings, check Linked Devices, remove anything unrecognized. If you think you handed over your Recovery Key at any point, generate a new one now and assume anything backed up before that moment is already in someone else’s possession.

The encryption holds. The account is the weak point, and the advisory makes clear that the targeting is deliberate, sustained, and still active.

“To mitigate this risk, the user must generate a new Backup Recovery Key within the Settings control; this action will invalidate the previous key for all future backup downloads. However, please note that this does not prevent the actor from having already downloaded a backup of the original account.” concludes the alert.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

❌
❌