Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

Signal linked-device hijacking by Russia-aligned operators

Updated 25.11.2025 08:42
Case score 56
Members 1 First seen 25.11.2025 08:42 Latest activity 25.11.2025 08:42

Overview

Russia-aligned operators are hijacking **Signal** accounts by abusing the app's **linked devices** feature. The activity has been visible since the start of the year and is aimed at high-value people in government, military, political, and civil society circles across the United States, the Middle East, and Europe. The access path depends on social engineering and account-linking abuse rather than a single software flaw. Current evidence points to unauthorized access risk and follow-on impersonation, but it does not provide a public victim count or a confirmed remediation outcome.
Latest development

CISA warns of Russia-aligned Signal linked-devices hijacking campaign

CISA warned that multiple Russia-aligned threat actors are actively targeting Signal users by abusing the app's "linked devices" feature to hijack target accounts and facilitate further compromise of mobile devices. The campaign focuses on high-value individuals, including current and former high-ranking government, military, and political officials, along with civil society organizations and individuals across the United States, the Middle East, and Europe.

Signals

Impact signals
CVEs/products
Geographic context
Status

Malware context

1 families

Technical intelligence

Existing Case data

Member happenings

Campaign Russia-aligned Signal linked-devices account hijacking campaign
Updated 25.11.2025 08:42 Lead Contribution 56
Campaign Active

**Multiple Russia-aligned threat actors** are running an active **Signal account hijacking** campaign that abuses the app's **linked devices** feature. The operation has been visible **since the start of the year** and targets **high-value mobile messaging users** across the **United States, the Middle East, and Europe**. It matters because compromising an encrypted messaging account can expose private communications and enable follow-on intrusion activity.