This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Signal Scam Scheme to Obtain Backup Keys
The backup recovery key is a 64-character secret key (a combination of letters and numbers) generated on the phone when enabling Signal encrypted backups. The user receives a fake notification from "Signal Support" about mandatory two-factor authentication or is informed that Signal is updating its terms of service and privacy policy, threatening data loss. The user is advised to perform the following steps: open the Signal app, go to Settings -> Backups -> Set up -> Enable backups -> View recovery key -> Copy to clipboard -> Next -> Enter the recovery key (this step is correct, but the recovery key should not be shared) -> Next -> Continue -> select backup plan. After following these instructions, Signal messages are backed up using the Secure Backups feature, which stores encrypted copies on Signal's cloud servers. Once the recovery key is provided, scammers can restore account backups on their devices and access all messages, including private and group chats. If an attacker obtains the user's recovery key, creating a new Signal account with the same phone number does not invalidate the previously stolen key.