Russian intelligence-linked actors have been sending targeted messages to high-value Signal users asking them to supply their backup recovery keys. The reporting surfaced publicly on 26 June. The approach bypasses the app's encryption entirely by exploiting the recovery workflow itself.

Once an operator obtains the key, they can restore the full message archive on another device. That gives them the target's complete history plus the ability to impersonate the account when contacting others in the network. For principals and their immediate circles, the exposure includes prior discussions on sensitive matters, contact lists, and the appearance of continued legitimacy.

The vector works because recovery procedures still depend on the user making a correct decision under pressure. No zero-day or protocol break is required.

Secvred maps every recovery key to a single physical token held offline and split across two people, neither of whom can complete restoration alone. Any request for the key triggers an immediate out-of-band verification call to a pre-listed number using a shared code phrase that changes monthly. Linked devices are limited to two, both enrolled only after in-person confirmation and removed automatically after 30 days of inactivity. Staff receive exact templates for any legitimate Signal support message, with cryptographic signatures that must match before any action is taken. Phone number changes or account migrations route through a standing legal and security contact list; no ad-hoc instructions are accepted. The recovery key never becomes something an incoming message can obtain.