Elektrine lite

← Feed

@signalapp@mastodon.world

Post #1174738

2026-03-09 16:16 UTC

These attacks, like all phishing, rely on social engineering. Attackers impersonate trusted contacts or services (such as the non-existent “Signal Support Bot”) to trick victims into handing over their login credentials or other information. To help prevent this, remember that your Signal SMS verification code is only ever needed when you are first signing up for the Signal app.

Replies (6)

  • @signalapp@mastodon.world 2026-03-09 16:17

    To protect people from such phishing, Signal actively warns users against sharing their SMS code and PIN. We also want to emphasize that Signal Support will *never* initiate contact via in-app messages, SMS, or social media to ask for your verification code or PIN. If anyone asks for any Signal related code, it is a scam. We make this clear when users receive their SMS code during initial signup.

    Open ##1174737

  • @sonjdol@ohai.social 2026-03-09 16:34

    @signalapp@mastodon.world this might be worth a push message to all users

    Open ##2993884

  • @lennybacon@infosec.exchange 2026-03-09 19:30

    @signalapp@mastodon.world LOL! The day Signal puts a bot in the app would be the day I stop using it…

    Open ##2993885

  • @dresstokilt@mastodon.social 2026-03-09 21:39

    @signalapp@mastodon.world probably doesn't help that your app suggests that I verify my PIN - which apparently I will ever need? - every time I'm in it.

    Open ##2993886

  • @yuliyan@nahe.social 2026-04-24 11:16

    @signalapp@mastodon.world Wouldn't it be pretty easy to just prohibit accounts being able to use "Signal", "support" and so on as a user name?

    Open ##2993887

  • @lasagne@chaos.social 2026-04-27 07:21

    @signalapp@mastodon.world How about a local filter that matches new conversations on the relevant words that then puts a warning over this new contact, that users have to intentionally click on two separate things to make it go away. These things should look out of the ordinary. Like TLS warnings but better explanation. "This new contacts mesages look like a phishing attack. If you are not intentionally adding a contract right now, your should block this." Or something.

    Open ##2993888