Signal users are being targeted in a sophisticated phishing campaign that aims to steal their backup recovery keys. This attack leverages the app's in-app messaging system, creating a sense of urgency by falsely claiming that users' data is at risk of permanent loss due to a sync issue. The messages, which appear to come from 'Signal Support', instruct victims to reveal their recovery keys, which are crucial for accessing encrypted chat backups. This campaign specifically targets the Secure Backups feature, a security measure that allows users to store encrypted copies of chats and media on Signal's servers. These backups are protected by a unique recovery key that never leaves the user's devices, making it the only way to decrypt the backup. The attack is not random but coordinated, with multiple victims receiving near-identical messages, indicating a deliberate and organized effort. The campaign's focus on archive theft is particularly concerning, as it targets years of past conversations rather than just future messages. This is a significant shift from earlier Signal hijacking attempts that aimed to steal registration codes to take over live accounts. Security experts emphasize that backups often contain sensitive information, including old documents, photos, and discussions, which users might assume are safe due to Signal's encryption. The targeting of journalists, dissidents, and anti-Chinese Communist Party activists suggests a politically motivated or surveillance-oriented threat actor. Signal has issued a strong statement, reiterating that it will never contact users first within the app and will never ask for registration codes, PINs, or backup recovery keys. To protect themselves, users are advised to treat any in-app chat claiming to be 'Signal Support' and requesting sensitive codes or keys as malicious. This includes blocking and reporting such accounts, never pasting recovery keys or login codes into chat windows, enabling the registration lock, using a strong Signal PIN, and turning on device-change alerts. Additionally, enabling disappearing messages by default can help reduce the potential damage if a backup is ever compromised.