The United States has announced a reward of up to $10 million for information leading to the identification or location of two alleged Russian-linked hacking groups accused of targeting users of the encrypted messaging services Signal and WhatsApp.
The reward , announced by the US Department of State under its Rewards for Justice (RFJ) programme, focuses on the groups known as UNC5792 and UNC4221, which US authorities say are linked to Russia's security and military intelligence services.
According to the State Department, the campaign is part of wider efforts to disrupt foreign cyber operations that threaten US national security and critical infrastructure.
Officials allege that UNC5792, which they associate with the Russian Federal Security Service's (FSB) Border Guards, has carried out extensive phishing operations against US government officials, military leaders and personnel from allied nations using Signal and WhatsApp.
The government seeks the following information:
Officials say the hackers relied on social engineering rather than targeting flaws in the messaging platforms themselves.
They also abused legitimate account-linking features to trick victims into connecting their messaging accounts to devices controlled by the hackers, allowing them to access conversations, lists and group chats.
Once an account had been compromised, the attackers used it to send convincing phishing messages to additional targets, expanding the scope of the campaign.
In some cases, investigators said the hackers modified genuine Signal group invitation pages, redirecting victims to malicious websites that silently linked the victim's account to an attacker-controlled device.
The tactic demonstrates how attackers are increasingly targeting users, rather than the underlying technology, to gain access to secure communications.
US officials said the campaign has compromised thousands of messaging accounts across multiple countries.
Among those most frequently targeted were government officials, diplomats, defence and intelligence personnel from the United States and NATO allies, as well as journalists reporting on Russia and Ukraine, researchers specialising in Russian affairs and organisations supporting Ukraine.
The announcement follows an updated advisory issued by the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) last week, which outlined newly observed tactics linked to the two hacking groups.
It also comes days after Ukraine's Security Service (SBU) said it had partnered with the FBI to expose a long-running Russian cyber-espionage campaign. That operation targeted encrypted messaging accounts used by officials, military personnel, politicians and activists across Ukraine, Europe and the United States.
According to SBU, the campaign sought to collect military, political and economic intelligence while simultaneously stealing personal information from its targets.
Signal has repeatedly warned users phishing attempts designed to hijack accounts. The company says it is developing additional protections to counter increasingly sophisticated social engineering techniques.
Signal has urged users to remain cautious of unsolicited messages claiming to come from Signal support, reminding them that its staff will never request registration verification codes or Signal PINs through the messaging service.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
