What we found
- The core account comes from an official FBI and CISA public service announcement, an update to an earlier announcement from the same agencies.
- The advisory reproduces the actual phishing message text, so the lure wording and requested item are described by the source itself rather than inferred.
- Only the title of the earlier March 2026 announcement was harvested, so any detail unique to it is outside what we can cite.
- Reviewed by 3 models, 2 from independent houses.
What we don’t know
- How many messaging accounts were compromised, and over what period.
- Which messaging applications beyond the Signal-branded lure were imitated in these messages.
- How targets are selected and how the initial chat reaches them.
- What the March 2026 announcement says in full, since only its title was harvested.
The bench — who voted
3 INDEPENDENT AI MODELS REVIEWED THIS. ALL 3: HIGH RISK.
The card names a count. Here are the seats behind it, with what each one said.
DISSENT, PRESERVEDThe defensible version of this alert is short: FBI and CISA, in a 26 June 2026 update, say actors tied to Russian Intelligence Services pose as automated messaging-app support and now try to elicit Backup Recovery Keys as well as PINs and login codes; never paste such a value into a chat. Everything beyond that should be cut or re-sourced before publication.
DISSENT, PRESERVEDI grade the underlying pattern high regardless of the sourcing defects. A key that unlocks the victim's stored message history, that survives re-registration on the same number, and whose rotation does not claw back an already-downloaded backup means a single successful lure is close to irreversible. The practical instruction — treat any chat requesting a recovery key, backup key, PIN or code as an attack — is sound advice and should survive even if the panel strips the unsupported detail.
DISSENT, PRESERVEDReproducing lure text verbatim in a consumer alert is useful, but doing so without a citation row risks the publication becoming the origin of a lure template that cannot be traced back to any agency document.
Reviewed by 3 independent models; all judged the finding to go beyond the evidence.
▼ Protocol & challenge record
ON THE RECORDI do not accept 'high' as the confidence label without a scope qualifier. What is high here is fidelity to one document. Attribution to Russian intelligence services, the FSB Border Guards detail, and the UNC5792/UNC4221 mapping are single-sourced government assertions that this desk cannot and did not independently test, and one of the two cited rows is a bare title with no body text. Say 'high confidence in what the advisory states' or drop to medium.
ON THE RECORDThe claim line should not have shipped in the indicative. The advisory says actors CAN read history and CAN take over accounts if a key is handed over. The claim line says they are 'then reading their message history and seizing the account.' That is the desk converting a stated capability into a reported outcome, and it is exactly the kind of drift these checks exist to catch. One word fixes it.
ON THE RECORD'Send this to any two-factor you know.' should never have reached the options list. The pipeline caught three identical malformations and put them in targeting_dropped, then let a fourth through into directive_options. That is a filter that is running but not trusted to run on the right list, and I would treat it as a process defect rather than a one-off typo.
ON THE RECORDOmitting 'individuals of high intelligence value' is the change I object to most on substance. The FBI drew a boundary around who is at risk and the draft erased it while keeping every scary consequence. The result reads broader than the source and I think that is a real, if small, act of amplification.
The sources
Official sourceRussian Intelligence Services Continue to Target Commercial Messaging Applications2026-06-26
According to the advisory the actors masquerade as automated messaging-app support accounts and have evolved their tactics to elicit victims' Backup Recovery Keys, while still trying to obtain account PINs and the codes sent to an account.
Official sourceRussian Intelligence Services Target Commercial Messaging Application Accounts2026-03-20
On 26 June 2026 the FBI and CISA published an update to their March 2026 public service announcement about Russian Intelligence Services actors running a phishing campaign against commercial messaging application accounts.
Other checks
Published under standing founder pass (A9) — every claim source-mapped by the machine.
▼ What the machine checked
- ✓ Not a community submission.
- ✓ No entity is named.
- ✓ All 7 material sentence(s) map to FBI/IC3.
- ✗ anthropic returned "overstated"; groq returned "overstated"; openrouter returned "overstated" — published on the receipt, not blocking (A9 amendment).
- ✓ No audience band is set.
No human affirmed these. They were verified by the classifier described in Amendment A9, on 2026-08-18.
Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.
Phishy? Send it → sharelivefraud.com/squire-it
Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.
Naming a source is not an endorsement, and being named here is not an accusation against any company.
Powered by SquireIt™