FRAUD CHECK — Squire It™
sharelivefraud.com/squire-it
LIVE FRAUD ALERT
LIVEFRAUD Check #20
FBI WARNS

FBI and CISA warn that Russian intelligence-linked actors posing as automated messaging-app support are phishing users for their backup recovery keys, login codes and account PINs.

HIGH CONFIDENCEPublished 2026-08-18
S
Q
U
I
R
E
D
E
S
K
·
C
H
E
C
K
E
D
·
B
A
T
T
L
E
D
·
R
E
C
E
I
P
T
E
D
·
S

What we found

The FBI and CISA say they have identified multiple clusters of Russian Intelligence Services cyber threat actors behind an ongoing commercial messaging application phishing campaign aimed at current and former U.S. and international government officials, military personnel, political figures, journalists, and key officials located in Ukraine. According to the advisory, the actors masquerade as automated app support accounts and have evolved their tactics to try to obtain victims' Backup Recovery Keys, while still trying to elicit login codes and account PINs. The advisory reproduces two sample lures: one written as a "Signal is here" notice claiming a joint investigation with the U.S. government and European partners and announcing a mandatory two-step sign-in change, and one headed "Action Required: Data Recovery Needed" that walks the reader through Settings to view a recovery key and paste it into the chat. The FBI states the actors have compromised individual accounts, but not the application's encryption or the application itself. The advisory says that if a victim shares their Backup Recovery Key, the actors can view historical private and group messages and take over the account, and that the same key stays valid even if the victim creates a new account with the same phone number, so it could be used to take over that new account later. Generating a new Backup Recovery Key in Settings invalidates the previous key for all future backup downloads, but the FBI notes this does not undo a backup the actor already downloaded. This June 26, 2026 notice is an update to a March 20, 2026 Public Service Announcement on the same targeting of commercial messaging application accounts. Never paste a backup recovery key, a login code or an account PIN into any chat: if a message pressures you to reveal one, leave the chat and open your app's Settings yourself to check your backup and device list. The harvested advisory does not say how many accounts were compromised, how many people received these messages, or over what period the recovery-key tactic has been in use. The claim about an investigation with European partners and about hackers from Iran and post-Soviet countries appears inside the sample lure text itself, and our harvested material does not present it as a finding of the agencies. LIVEFRAUD ALERTS is independent and not affiliated with the FBI, CISA or any messaging service named here; this alert was assembled only from the harvested rows listed above.
THE RULE
Handing over a backup recovery key can expose past private and group messages and can let an attacker seize the account again even after it is re-created with the same phone number.

What we don’t know

The bench — who voted

2 INDEPENDENT AI MODELS REVIEWED THIS. ALL 2: HIGH RISK.

The card names a count. Here are the seats behind it, with what each one said.

GROQopenai/gpt-oss-120b · HIGH
Finding adds specifics about multiple clusters and precise target audiences (U.S./international officials, military, journalists, Ukraine officials) not present in the sourced evidence, which only mentions phishing of individuals for keys, codes, and PINs.
OPENROUTERopenrouter/free · HIGH
The finding adds details about targeting of government officials, military personnel, journalists, and Ukrainian key officials, and describes specific sample lures, which are not present in the harvested evidence rows.

Reviewed by 2 independent models; all judged the finding to go beyond the evidence.

▼ Protocol & challenge record
Objection (medium): Attribution stretch on the finding's lead sentence. The source says 'The FBI has identified multiple clusters of Russian Intelligence Services (RIS) cyber threat actors' — the identification is attributed to the FBI alone. CISA is a co-issuer of the update ('The FBI and CISA are issuing this update'), not a co-identifier. The draft's 'The FBI and CISA say they have identified multiple clusters' silently promotes CISA to joint attributor of an intelligence finding. Fix: 'The FBI, in an update co-issued with CISA, says it has identified...'
Not resolved — preserved on the record.
Objection (medium): The headline claim says actors 'are phishing users,' which reads as a general-population threat. The advisory is explicit that this is a targeted campaign 'against individuals of high intelligence value' — current and former U.S. and international government officials, military personnel, political figures, journalists, and key officials in Ukraine. The finding paragraph carries the targeting, but the claim line does not, and the claim is what gets read and screenshotted. Fix: 'phishing targeted officials, journalists and military personnel' or similar.
Not resolved — preserved on the record.
Objection (medium): Mechanism gap that changes the advice. The source conditions the harm: 'If a targeted user backs up their CMA messages as directed in Figure 1 AND later provides their Backup Recovery Key...' Sample Lure 1 exists to get a victim to ENABLE backups they may not have had; Lure 2 then harvests the key. The draft's finding drops the enable-backups step and presents the harm as flowing from key disclosure alone, and the advice line therefore only warns against pasting a key. A reader who follows Lure 1's 'Settings -> Backups -> Enable backups' instructions is already halfway compromised and has been given no warning about that step.
Not resolved — preserved on the record.
Objection (medium): The advice sentence is under-supported in one part and under-inclusive in another. 'Check your ... device list' appears nowhere in the harvested material (linked-device compromise was the March PSA's subject, which was NOT harvested beyond its title) — it is imported knowledge dressed as guidance from this advisory. Meanwhile the two remediation actions the source actually specifies are missing from the advice: generate a new Backup Recovery Key in Settings if you may have exposed one, and report to IC3 / your FBI field office / CISA (report@cisa.gov, 1-844-729-2472). A fraud alert that omits the source's own reporting channel is leaving the most actionable line on the floor.
Not resolved — preserved on the record.
Objection (low): Terminology drift. The source says 'verification codes and account PINs'; the draft says 'login codes' in both claim and finding. 'Two-factor Verification' in the lure becomes 'two-step sign-in change.' Both paraphrases are defensible in plain English but they are paraphrases of the exact strings a reader might search for or recognise in a real lure. Prefer the source's words with a gloss.
Not resolved — preserved on the record.
Objection (medium): Internal inconsistency in the §11 Rule 2 filtering. Two directives were dropped because 'encrypted' and 'app' users are not described as targeted, yet the surviving directive option 'Send this to colleagues who back up their chats and store a recovery key' names exactly the same kind of behaviour-defined group that no harvested source describes as a targeting criterion. The advisory targets by role (officials, military, political figures, journalists, Ukraine officials), not by backup habits. Either the rule applies to all three or the two drops were arbitrary.
Not resolved — preserved on the record.
Objection (medium): Callout option 'ATTENTION: EVERYONE' is affirmatively contradicted by the source, which restricts the campaign to 'individuals of high intelligence value.' Offering it as a selectable option invites a published headline that misstates who is at risk. 'ATTENTION: VETERANS' is a weaker but real stretch: the source says 'former ... military personnel,' which overlaps with but is not identical to 'veterans' as a US benefits/identity category, and it risks pulling in the large veteran-scam-alert audience who are not in scope.
Not resolved — preserved on the record.
Objection (low): Omitted specifics that are in the harvested text and would strengthen verifiability: the actors are described as 'Russian Federal Security Service (FSB) officers embedded with the FSB Border Guards and others working on behalf of the Russian military services,' and the activity is 'publicly tracked as UNC5792 and UNC4221.' The draft's generic 'Russian intelligence-linked actors' is weaker than the source supports and drops the cluster names that let a reader cross-check against vendor reporting.
Resolved: Partially self-resolved: the unknowns list already asks which applications beyond the one named in the lure are impersonated, which correctly preserves the FBI's deliberate use of the generic 'CMA' rather than asserting Signal is the only affected app. The remaining fix is only to restore FSB/UNC5792/UNC4221 detail.
Objection (low): Icon set includes 'phone.' Nothing in the harvested material describes a voice-call or SMS vector; every described lure is an in-app message from a fake support account. The icon implies a delivery channel not in evidence.
Not resolved — preserved on the record.
Objection (low): Date currency: the whole alert rests on a single 2026-06-26 PSA that is itself an update to a 2026-03-20 PSA — i.e. the agencies revised guidance within roughly three months. Nothing in the packet establishes that no further update has issued since harvest. The alert should carry an 'as of' stamp on the advisory rather than presenting the June text as the standing state of the campaign.
Resolved: Partly mitigated by the finding sentence that dates both PSAs explicitly and labels the June notice as an update, which lets a reader locate any successor themselves.
Preserved dissent
ON THE RECORDThe finding's opening sentence misattributes. The advisory says 'The FBI has identified multiple clusters of Russian Intelligence Services cyber threat actors.' Writing 'The FBI and CISA say they have identified' puts a joint intelligence attribution in CISA's mouth that the harvested text does not put there. CISA co-issued; it did not co-identify. This is a small edit and there is no good reason not to make it.
ON THE RECORDThe claim line should not say 'users.' The advisory says 'individuals of high intelligence value' and then enumerates them. 'Phishing users' is the one sentence in this packet that could be fairly read as telling the general public they are under attack by the FSB, and the rest of the alert's careful targeting language does not travel with a headline.
ON THE RECORDI do not think 'confidence: high' is wrong, but I record that the high rating is being carried almost entirely by a single row. Row 91d920ff contributes a title and a date and nothing else; describing the evidence base as 'both rows are official FBI/IC3 public service announcements' overstates the corroboration, since the second row corroborates only that a prior PSA exists.
ON THE RECORDThe advice as written tells readers to check a 'device list.' No harvested row mentions devices. If that phrase stays, it is the alert asserting knowledge it did not harvest, which is exactly the failure mode the targeting_dropped entries were policing against elsewhere in the same packet.
ON THE RECORDDropping the backup-enablement step is the most consequential omission here. Lure 1 is an instruction to turn on backups; a target with no backup has no recovery key to steal. Telling readers only 'never paste a key into a chat' leaves the first half of the attack chain unmarked.

The sources

Official sourceRussian Intelligence Services Continue to Target Commercial Messaging Applications2026-06-26
The FBI and CISA say Russian Intelligence Services cyber threat actors posing as automated messaging-app support accounts are phishing targeted individuals for Backup Recovery Keys, login codes and account PINs, and that a shared key stays valid even for a new account on the same phone number.
Authority: official. Retrieved 2026-08-18.
Limitation: Gives no count of compromised accounts, no volume of phishing messages sent, and no timeframe for the recovery-key tactic.
Open the original source →
Official sourceRussian Intelligence Services Target Commercial Messaging Application Accounts2026-03-20
An earlier FBI public service announcement dated March 20, 2026 addressed Russian intelligence services targeting commercial messaging application accounts.
Authority: official. Retrieved 2026-08-18.
Limitation: Only the title and publication date were harvested, so no detail from this notice supports anything beyond its existence, subject and date.
Open the original source →

Other checks

Every check we have published →

Share this receipt
sharelivefraud.com/check/bTzmJgQ

Published under standing founder pass (A9) — every claim source-mapped by the machine.

▼ What the machine checked
  • ✓ Not a community submission.
  • ✓ No entity is named.
  • ✓ All 7 material sentence(s) map to FBI/IC3.
  • ✗ groq returned "overstated"; openrouter returned "overstated" — published on the receipt, not blocking (A9 amendment).
  • ✓ No audience band is set.

No human affirmed these. They were verified by the classifier described in Amendment A9, on 2026-08-18.

Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.

Phishy? Send it → sharelivefraud.com/squire-it

Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.

Naming a source is not an endorsement, and being named here is not an accusation against any company.

Powered by SquireIt™

Verify this receipt at squireit.com

Join Squire’s First Watch

Alerts before the feed. Credit when your summons becomes a receipt. A vote on what we check next. Founding names are permanent.

Get the next one

We publish a receipt for every alert, including the ones we decide not to run.

We will ask you to confirm before anything is sent. Your address is used for this and nothing else, and is never shared.