FRAUD CHECK — Squire It™
sharelivefraud.com/squire-it
LIVE FRAUD ALERT
LIVEFRAUD Check #21
FBI WARNS

FBI and CISA say Russian intelligence actors are posing as automated messaging-app support to talk targets into handing over their Backup Recovery Key, then reading their message history and seizing the account.

HIGH CONFIDENCEPublished 2026-08-18
S
Q
U
I
R
E
D
E
S
K
·
C
H
E
C
K
E
D
·
B
A
T
T
L
E
D
·
R
E
C
E
I
P
T
E
D
·
S

What we found

On 26 June 2026 the FBI and CISA published an update to their March 2026 public service announcement about Russian Intelligence Services actors running a phishing campaign against commercial messaging application accounts. The update says multiple clusters, including Russian Federal Security Service officers and others working on behalf of the Russian military services, continue to target current and former U.S. and international government officials, military personnel, political figures, journalists, and key officials located in Ukraine, and that the activity has been publicly tracked as UNC5792 and UNC4221. According to the advisory the actors masquerade as automated messaging-app support accounts and have evolved their tactics to elicit victims' Backup Recovery Keys, while still trying to obtain account PINs and the codes sent to an account. One sample lure reproduced in the advisory is dressed up as a notice from Signal announcing new account security rules and walking the reader through Settings to enable backups and copy the recovery key, and a second sample, headed "Action Required: Data Recovery Needed", tells the target their messages and media are at risk and instructs them to paste that key into the chat. The advisory states that if a target backs up their messages as directed and then supplies the Backup Recovery Key, the actors can view the account's historical private and group messages and take over the account. It also warns that a shared key stays valid even if the victim opens a new account with the same phone number, that the user must generate a new Backup Recovery Key in Settings to invalidate the old one, and that doing so does not undo a backup the actor already downloaded. The FBI says the actors compromised individual accounts rather than the messaging application itself or its encryption. Treat any chat asking for a recovery key, backup key, PIN or login code as an attack: never type or paste it into a message thread, no matter how official the sender looks. Our harvested material does not say how many accounts were taken over, how many people received these messages, or which other applications beyond the Signal-branded lure were imitated, and we hold only the title of the March 2026 announcement rather than its text. LIVEFRAUD ALERTS is independent and not affiliated with any agency or messaging service named here; this alert rests only on the harvested rows cited above.
THE RULE
Handing over a backup recovery key exposes stored private and group message history and can lose the account, and the same key can still work against a rebuilt account on the same phone number.

What we don’t know

The bench — who voted

3 INDEPENDENT AI MODELS REVIEWED THIS. ALL 3: HIGH RISK.

The card names a count. Here are the seats behind it, with what each one said.

ANTHROPICclaude-opus-5 · HIGH
The headline consequence — that surrendering the Backup Recovery Key lets the actors read historical private and group messages and take over the account — is not present in either evidence row. Row [1] covers only the impersonation of automated support accounts and the solicitation of recovery keys, PINs and codes. The most alarming and most publishable part of the claim rests on nothing cited.
DISSENT, PRESERVEDThe defensible version of this alert is short: FBI and CISA, in a 26 June 2026 update, say actors tied to Russian Intelligence Services pose as automated messaging-app support and now try to elicit Backup Recovery Keys as well as PINs and login codes; never paste such a value into a chat. Everything beyond that should be cut or re-sourced before publication.
DISSENT, PRESERVEDI grade the underlying pattern high regardless of the sourcing defects. A key that unlocks the victim's stored message history, that survives re-registration on the same number, and whose rotation does not claw back an already-downloaded backup means a single successful lure is close to irreversible. The practical instruction — treat any chat requesting a recovery key, backup key, PIN or code as an attack — is sound advice and should survive even if the panel strips the unsupported detail.
DISSENT, PRESERVEDReproducing lure text verbatim in a consumer alert is useful, but doing so without a citation row risks the publication becoming the origin of a lure template that cannot be traced back to any agency document.
GROQopenai/gpt-oss-120b · HIGH
The finding adds numerous specifics—multiple actor clusters, UNC identifiers, sample Signal lures, detailed account‑takeover mechanics, key‑persistence warnings, and FBI statements about compromising individual accounts—that are not present in the two cited evidence rows.
OPENROUTERopenrouter/free · HIGH
The finding states that the update mentions multiple clusters, including Russian Federal Security Service officers and others working on behalf of the Russian military services, but evidence row [2] only confirms the publication date and that it is an update; no detail about clusters is provided.

Reviewed by 3 independent models; all judged the finding to go beyond the evidence.

▼ Protocol & challenge record
Objection (medium): Claim-line tense overclaims. The advisory is conditional and capability-framed: 'If a targeted user backs up their CMA messages as directed... and later provides their Backup Recovery Key... RIS cyber threat actors CAN view the account's historical messages... and take over the victim's account.' The headline claim asserts the outcome as ongoing fact — 'then reading their message history and seizing the account.' Nothing in the harvested row states that any account history was actually read or any account actually seized via the recovery-key vector. The finding body handles this correctly ('the actors can view'); the claim line does not. Fix: 'and can then read their message history and seize the account.'
Not resolved — preserved on the record.
Objection (high): Directive option 'Send this to any two-factor you know.' is malformed output and is not publishable. It is the same class of defect the pipeline already caught in targeting_dropped ('runs', 'sensitive', 'app') — a noun phrase lifted from source text and slotted into a person-shaped template. It survived into directive_options and would ship if selected. Any share directive that names a group also implies that group is targeted (§11 Rule 2), and 'two-factor' is not a group at all. Drop it; also note 'Forward this to the journalists in your life' and 'Send this to any journalist you know' are near-duplicates, so the real usable set is two options, not four.
Not resolved — preserved on the record.
Objection (medium): Scope qualifier dropped. The source says the campaign is 'against individuals of high intelligence value' — an explicit narrowing the draft never reproduces. The finding lists the target categories but omits the framing sentence, and the audience callout plus the unconditional advice line read as a general-population alert. This inflates perceived reader exposure. Add the 'high intelligence value' qualifier verbatim; it is one clause and it is the single most important calibration in the advisory.
Not resolved — preserved on the record.
Objection (medium): Entity-fairness gap around Signal. Signal appears in the harvested row only inside two reproduced phishing lures — it is the impersonated brand. The draft names Signal three times (finding twice, unknowns once) and never says plainly that Signal is being spoofed and is not the compromised party. The 'not the messaging application itself or its encryption' sentence sits three sentences later, refers to 'the messaging application' generically, and is attributed to the FBI's statement about CMAs in general, not to Signal specifically. A skimmer takes away 'Signal breach'. Fix: attach the disclaimer to the Signal mention, e.g. 'a lure impersonating Signal — the advisory does not allege any compromise of Signal itself.'
Resolved: Partially resolved as drafted: the finding does carry 'The FBI says the actors compromised individual accounts rather than the messaging application itself or its encryption,' which is a faithful rendering of the source and does defuse a 'Signal was hacked' reading — but only for a reader who gets to the seventh sentence. Residual risk is placement, not accuracy.
Objection (medium): Confidence 'high' conflates two different things. The draft is a high-fidelity restatement of one official document, but the substantive claims inside it — Russian state attribution, FSB involvement, the UNC5792/UNC4221 mapping — are the FBI's assertions, uncorroborated in the harvested set and unverifiable from it. Only one of the two rows has body text; the other is a bare title. 'High' should be scoped explicitly to 'high confidence that the advisory says this', not to the underlying attribution. The confidence_reasons come close but do not say it.
Resolved: Partially resolved: every substantive sentence in the finding is attributed ('the update says', 'according to the advisory', 'the advisory states', 'the FBI says'), and the claim line opens 'FBI and CISA say'. The draft never asserts the attribution in its own voice. The remaining problem is only that the confidence label is unqualified.
Objection (low): Two source sentences are collapsed into one draft sentence, producing a small attribution stretch. The source says (a) 'The FBI has identified multiple clusters of RIS cyber threat actors responsible for an ongoing... campaign' and separately (b) 'FSB officers embedded with the FSB Border Guards and others working on behalf of the Russian military services continue to target...'. The draft renders this as 'multiple clusters, including Russian Federal Security Service officers and others...' — an inference that the FSB/military actors ARE the clusters. Probably correct, but it is the draft's inference, not the source's sentence. The specific detail 'embedded with the FSB Border Guards' is also dropped without flagging.
Not resolved — preserved on the record.
Objection (low): Actionable victim guidance present in the source is omitted entirely: IC3 complaint, local FBI field office, CISA Incident Reporting System, report@cisa.gov, 1-844-729-2472. For an alert aimed at journalists and officials — the exact population that may already have pasted a key — the reporting channel is arguably more useful than the generic 'never paste it' advice. This is an omission, not an error, but it weakens the piece.
Not resolved — preserved on the record.
Objection (low): No currency check on the update itself. The harvested row is by construction an update to an earlier PSA on the same URL pattern (PSA260320 -> PSA260626), which establishes that this series gets superseded. The draft asserts the 26 June text as current without any statement of when the check was run or whether a later PSA in the 2026 series was looked for. Date-stamp the check.
Resolved: Partially resolved: the limitation sentence discloses that only the March PSA's title was harvested, which signals the draft knows its coverage of the series is incomplete.
Objection (low): risk_line hardens a hedge. Source: 'the actor could POTENTIALLY use the compromised key to take over the new account in the future.' Draft risk_line: 'the same key CAN still work against a rebuilt account on the same phone number.' The 'remains valid' part is verbatim-supported; the takeover part is not asserted as certain in the source.
Not resolved — preserved on the record.
Objection (low): 'Backup Recovery Key' is treated as a generic cross-app concept. In the harvested row the term appears in the FBI's own prose about CMAs generally, but the only concrete Settings path shown ('Settings -> Backups -> Enable backups -> View recovery key') is from a Signal-branded lure. The mitigation advice 'the user must generate a new Backup Recovery Key within the Settings control' is therefore being handed to readers of unnamed other apps where that control may not exist under that name. The unknowns note flags that other imitated apps are unidentified, but the advice text does not.
Resolved: Partially resolved: the limitation sentence and unknowns both state that the harvested material does not identify which applications beyond the Signal-branded lure were imitated.
Preserved dissent
ON THE RECORDI do not accept 'high' as the confidence label without a scope qualifier. What is high here is fidelity to one document. Attribution to Russian intelligence services, the FSB Border Guards detail, and the UNC5792/UNC4221 mapping are single-sourced government assertions that this desk cannot and did not independently test, and one of the two cited rows is a bare title with no body text. Say 'high confidence in what the advisory states' or drop to medium.
ON THE RECORDThe claim line should not have shipped in the indicative. The advisory says actors CAN read history and CAN take over accounts if a key is handed over. The claim line says they are 'then reading their message history and seizing the account.' That is the desk converting a stated capability into a reported outcome, and it is exactly the kind of drift these checks exist to catch. One word fixes it.
ON THE RECORD'Send this to any two-factor you know.' should never have reached the options list. The pipeline caught three identical malformations and put them in targeting_dropped, then let a fourth through into directive_options. That is a filter that is running but not trusted to run on the right list, and I would treat it as a process defect rather than a one-off typo.
ON THE RECORDOmitting 'individuals of high intelligence value' is the change I object to most on substance. The FBI drew a boundary around who is at risk and the draft erased it while keeping every scary consequence. The result reads broader than the source and I think that is a real, if small, act of amplification.

The sources

Official sourceRussian Intelligence Services Continue to Target Commercial Messaging Applications2026-06-26
According to the advisory the actors masquerade as automated messaging-app support accounts and have evolved their tactics to elicit victims' Backup Recovery Keys, while still trying to obtain account PINs and the codes sent to an account.
Authority: official. Retrieved 2026-08-18.
Limitation: The announcement gives no victim counts, no date range for the campaign and no detail on how the lures are delivered to a given target.
Open the original source →
Official sourceRussian Intelligence Services Target Commercial Messaging Application Accounts2026-03-20
On 26 June 2026 the FBI and CISA published an update to their March 2026 public service announcement about Russian Intelligence Services actors running a phishing campaign against commercial messaging application accounts.
Authority: official. Retrieved 2026-08-18.
Limitation: Only the title and publication date of this March announcement were harvested; its body text is not available to us.
Open the original source →

Other checks

Every check we have published →

Share this receipt
sharelivefraud.com/check/rBAp440

Published under standing founder pass (A9) — every claim source-mapped by the machine.

▼ What the machine checked
  • ✓ Not a community submission.
  • ✓ No entity is named.
  • ✓ All 7 material sentence(s) map to FBI/IC3.
  • ✗ anthropic returned "overstated"; groq returned "overstated"; openrouter returned "overstated" — published on the receipt, not blocking (A9 amendment).
  • ✓ No audience band is set.

No human affirmed these. They were verified by the classifier described in Amendment A9, on 2026-08-18.

Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.

Phishy? Send it → sharelivefraud.com/squire-it

Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.

Naming a source is not an endorsement, and being named here is not an accusation against any company.

Powered by SquireIt™

Verify this receipt at squireit.com

Join Squire’s First Watch

Alerts before the feed. Credit when your summons becomes a receipt. A vote on what we check next. Founding names are permanent.

Get the next one

We publish a receipt for every alert, including the ones we decide not to run.

We will ask you to confirm before anything is sent. Your address is used for this and nothing else, and is never shared.