What we found
- Both rows are official FBI/IC3 public service announcements, the later one an update to the earlier.
- The advisory quotes the phishing messages in full, so the tactic description comes from primary source text.
- Scale, victim counts and dates of individual compromises are absent, so the alert stays with mechanism rather than numbers.
- Reviewed by 2 models from independent houses.
What we don’t know
- How many accounts have been compromised, and how many people were sent these lures.
- Which messaging applications beyond the one named in the sample lure are being impersonated.
- How the actors select and reach specific targets, and from what accounts the messages are sent.
- Whether anyone whose key was exposed has had a replacement account taken over.
The bench — who voted
2 INDEPENDENT AI MODELS REVIEWED THIS. ALL 2: HIGH RISK.
The card names a count. Here are the seats behind it, with what each one said.
Reviewed by 2 independent models; all judged the finding to go beyond the evidence.
▼ Protocol & challenge record
ON THE RECORDThe finding's opening sentence misattributes. The advisory says 'The FBI has identified multiple clusters of Russian Intelligence Services cyber threat actors.' Writing 'The FBI and CISA say they have identified' puts a joint intelligence attribution in CISA's mouth that the harvested text does not put there. CISA co-issued; it did not co-identify. This is a small edit and there is no good reason not to make it.
ON THE RECORDThe claim line should not say 'users.' The advisory says 'individuals of high intelligence value' and then enumerates them. 'Phishing users' is the one sentence in this packet that could be fairly read as telling the general public they are under attack by the FSB, and the rest of the alert's careful targeting language does not travel with a headline.
ON THE RECORDI do not think 'confidence: high' is wrong, but I record that the high rating is being carried almost entirely by a single row. Row 91d920ff contributes a title and a date and nothing else; describing the evidence base as 'both rows are official FBI/IC3 public service announcements' overstates the corroboration, since the second row corroborates only that a prior PSA exists.
ON THE RECORDThe advice as written tells readers to check a 'device list.' No harvested row mentions devices. If that phrase stays, it is the alert asserting knowledge it did not harvest, which is exactly the failure mode the targeting_dropped entries were policing against elsewhere in the same packet.
ON THE RECORDDropping the backup-enablement step is the most consequential omission here. Lure 1 is an instruction to turn on backups; a target with no backup has no recovery key to steal. Telling readers only 'never paste a key into a chat' leaves the first half of the attack chain unmarked.
The sources
Official sourceRussian Intelligence Services Continue to Target Commercial Messaging Applications2026-06-26
The FBI and CISA say Russian Intelligence Services cyber threat actors posing as automated messaging-app support accounts are phishing targeted individuals for Backup Recovery Keys, login codes and account PINs, and that a shared key stays valid even for a new account on the same phone number.
Official sourceRussian Intelligence Services Target Commercial Messaging Application Accounts2026-03-20
An earlier FBI public service announcement dated March 20, 2026 addressed Russian intelligence services targeting commercial messaging application accounts.
Other checks
Published under standing founder pass (A9) — every claim source-mapped by the machine.
▼ What the machine checked
- ✓ Not a community submission.
- ✓ No entity is named.
- ✓ All 7 material sentence(s) map to FBI/IC3.
- ✗ groq returned "overstated"; openrouter returned "overstated" — published on the receipt, not blocking (A9 amendment).
- ✓ No audience band is set.
No human affirmed these. They were verified by the classifier described in Amendment A9, on 2026-08-18.
Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.
Phishy? Send it → sharelivefraud.com/squire-it
Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.
Naming a source is not an endorsement, and being named here is not an accusation against any company.
Powered by SquireIt™