Skip to content

Russian Intelligence Services Continue to Target Commercial Messaging Applications

Fbi • June 26, 2026

The FBI and CISA are issuing this update to the March 20, 2026 , Public Service Announcement I-032026-PSA to provide additional information to the public and encourage device owners to take actions to protect themselves.

The FBI has identified multiple clusters of Russian Intelligence Services ( RIS ) cyber threat actors responsible for an ongoing commercial messaging application ( CMA ) phishing campaign against individuals of high intelligence value. Russian Federal Security Service ( FSB ) officers embedded with the FSB Border Guards and others working on behalf of the Russian military services continue to target current and former U.S. and international government officials, military personnel, political figures, journalists, and key officials located in Ukraine. RIS cyber threat actors have compromised individual CMA accounts, but not the CMA's encryption or the application itself. To date, this activity has been publicly tracked as UNC5792 and UNC4221.

RIS cyber threat actors continue to masquerade as automated CMA support accounts in updated phishing messages but have evolved their tactics to attempt to elicit victims' Backup Recovery Keys. RIS cyber threat actors continue to elicit victims' verification codes and account PINs (see Figure 1 ). If a targeted user backs up their CMA messages as directed in Figure 1 and later provides their Backup Recovery Key (see Figure 2 ), RIS cyber threat actors can view the account's historical messages, private and group messages, and take over the victim's account.

If a victim inadvertently shares their Backup Recovery Key, that same key remains valid even if they create a new account following the compromise using the same phone number. Consequently, the actor could potentially use the compromised key to take over the new account in the future as well.

To mitigate this risk, the user must generate a new Backup Recovery Key within the Settings control; this action will invalidate the key for all future backup downloads. However, please note that this does not prevent the actor from having already downloaded a backup of the original account.

For additional details on how cyber threat actors gain unauthorized access to CMA accounts and guidance to protect yourself from phishing campaigns, see the March 2026 Public Service Announcement I-032026-PSA .

If you or someone you know has fallen victim to this phishing campaign, file a complaint with IC3 , report it to your local FBI field office , to CISA via the agency's Incident Reporting System or its 24/7 Operations Center ( [email protected] ) or by calling 1-844-Say-CISA ( 1-844-729-2472 ). For additional information, see the FBI's guidance on Spoofing and Phishing . Additionally, see CISA's " Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications | CISA ," " Phishing Guidance: Stopping the Attack Cycle at Phase One " and " Mobile Communications Best Practice Guidance ."

Extracted Entities

Attack Types (1)

Countries (1)

Domains (1)

Email Addresses (1)

Industries (1)

MITRE ATT&CK (1)