phishing
US Offers $10M for Russian Hackers Phishing Signal Users
2026-06-29

The US State Department has put up to $10 million on the table for anyone who can help identify or locate members of UNC5792 and UNC4221, two crews it ties to Russia's FSB Border Guards and military intelligence. The money comes via Rewards for Justice, the long-running programme usually reserved for people accused of going after American critical infrastructure.
What makes this one worth paying attention to is the tradecraft. It is almost aggressively unfancy.
No zero-days, just a polite DM
These groups are not breaking the encryption on Signal or WhatsApp. They are not burning expensive exploits. They are sending direct messages inside the apps themselves, pretending to be Signal support staff, and walking targets through a fake mandatory two-factor verification.
The prize at the end of that conversation is the victim's Signal Backup Recovery Key. Hand that over and the attacker quietly walks off with the entire message history. No alerts, no broken padlock icon, no dramatic compromise. Just a helpful chat with a stranger who said the right things.
Thousands of accounts, the people you'd expect
According to the FBI and CISA, thousands of accounts have already been pulled in this way. The target list reads like a who's who of people Russia would obviously want to read:
- US and NATO officials
- Diplomats
- Defence and intelligence staff
- NGOs working on Ukraine
- Journalists and analysts covering the region
None of these are casual users. Most of them chose Signal and WhatsApp because they wanted strong encryption. And the encryption did its job. It held. The humans on either end of it are the part that gave way.
The bit worth pinning to your forehead
Signal's actual support team only ever contacts users through official company email. They do not DM you inside the app. They do not ask for a verification code. They do not send a link to restore your account.
That is the whole tell. If a message inside a chat app claims to be from the chat app, that alone is enough to stop and think. The same goes for WhatsApp, Telegram, Microsoft Teams, Slack, and every other platform that occasionally needs to email you about something serious. Support lives outside the channel, not inside it.
Why a $10M bounty for this, of all things
Rewards for Justice usually surfaces in stories about ransomware crews bleeding hospitals or grid operators. Putting that same price tag on operators who are, in essence, very persistent phishers tells you how seriously Washington is treating the haul.
It is also a quiet admission of where the front line actually sits. The interesting attacks against high-value targets are not always the ones with exotic malware and clever persistence. Sometimes they are a friendly message, a fake form, and someone senior enough to know better having a busy Tuesday.
The crews behind UNC5792 and UNC4221 have worked out that the cheapest path into a secure conversation is to ask politely. The bounty is a bet that someone, somewhere, knows their names.