Elektrine lite

← Feed

@signalapp@mastodon.world

Post #609108

2026-03-09 16:16 UTC

We are aware of recent reports regarding targeted phishing attacks that have resulted in account takeovers of some Signal users, including government officials and journalists. We take this very seriously. To be clear: Signal’s encryption and infrastructure have not been compromised and remain robust. These attacks were executed via sophisticated phishing campaigns, designed to trick users into sharing information – SMS codes and/or Signal PIN – to gain access to users’ accounts.

Replies (6)

  • @signalapp@mastodon.world 2026-03-09 16:16

    These attacks, like all phishing, rely on social engineering. Attackers impersonate trusted contacts or services (such as the non-existent “Signal Support Bot”) to trick victims into handing over their login credentials or other information. To help prevent this, remember that your Signal SMS verification code is only ever needed when you are first signing up for the Signal app.

    Open ##1174738

  • @cmthiede@social.vivaldi.net 2026-03-09 16:20

    @signalapp@mastodon.world time to re-up their cyber awareness campaigns

    Open ##2993889

  • @patricus@gts.posix.live 2026-03-09 16:21

    @signalapp@mastodon.world how to move signal account from a phone to an other? just a question.

    Open ##2993890

  • @scathach@stereophonic.space 2026-03-09 17:32

    @signalapp@mastodon.world These attacks wouldn't be possible if you stopped requiring phone numbers

    Open ##2993891

  • @ariarhythmic@ohai.social 2026-03-09 17:51

    @signalapp@mastodon.world "SMS codes" sounds like a you problem, though.

    Open ##2993897

  • @adulau@infosec.exchange 2026-03-09 17:52

    @signalapp@mastodon.world Since Signal always asks for a PIN code for backups, it seems logical that threat actors are exploiting this behavior to trick users.

    Open ##2993898