The US State Department is offering a $10 million bounty for information that helps identify or locate members of two Russian state-backed hacking groups behind a campaign targeting Signal and WhatsApp users. The reward, offered under the department's Rewards for Justice program, marks a serious escalation in efforts to shut down a phishing operation that has compromised thousands of encrypted-messaging accounts.

A low-key photo of a MacBook keyboard illustrating an account hack.

Who the hackers are targeting

The campaign focuses on high-value individuals rather than the general public. According to the FBI, targets have included current and former US government officials, military personnel, political figures and journalists. The bureau launched its investigation into the phishing operation earlier, and US authorities are now stepping up the hunt for those responsible.

The FBI attributes the attacks to two groups it tracks as UNC5792 and UNC4221. US officials say the former is associated with the Russian Federal Security Service's Border Guards, while the latter operates on behalf of Russian military intelligence. That state backing is a major reason the response has been so aggressive.

How the phishing attack works

The mechanics are deceptively simple, which is what makes them dangerous. Messages masquerade as automated support communications and ask users to click a link or provide verification codes or account passcodes.

  • If a target complies, they can unknowingly link the attacker's device to their account.
  • In some cases the account is taken over completely, locking the real owner out.
  • For Signal specifically, attackers try to defeat protections that stop linked devices from seeing past conversations by instructing targets to create a backup and hand over its recovery key.

That last detail is important. Signal is built so that a newly linked device cannot read old messages, but tricking a user into sharing a backup recovery key sidesteps that safeguard. It is a reminder that even strong encryption can be undone by social engineering, a recurring theme across mobile security stories.

Why the bounty matters

A $10 million reward signals how seriously US authorities view this threat. State-sponsored campaigns against secure messaging apps strike at tools that officials, journalists and activists rely on precisely because they are supposed to be private.

The Rewards for Justice program is designed to crowdsource intelligence on hard-to-reach adversaries, and tipsters can submit information about the UNC5792 group through the program's official channel. Whether or not the bounty produces arrests, it raises the cost and visibility of the operation.

How to protect your accounts

The core defense is simple: legitimate services do not ask you to share verification codes, passcodes or recovery keys. Treat any such request as a red flag, even if the message looks like official support.

  • Never share one-time codes, account passcodes or backup recovery keys with anyone.
  • Be suspicious of unsolicited messages urging you to click a link or verify your account.
  • Check your app's linked devices regularly and remove any you do not recognize.
  • Enable extra protections your messaging app offers, such as PINs or registration locks.

These attacks succeed through trust, not by breaking encryption, so awareness is the strongest safeguard. For more on protecting your devices, see our ongoing mobile coverage.

Frequently asked questions

How much is the reward?

The US State Department is offering up to $10 million through its Rewards for Justice program for information identifying or locating members of the two hacking groups.

Are Signal and WhatsApp themselves hacked?

No. The campaign relies on phishing and social engineering to trick users into linking attacker devices or handing over codes, rather than breaking the apps' encryption.

How can I tell if my account was compromised?

Check the linked-devices list in your messaging app. If you see a device you do not recognize, remove it and change any related credentials immediately.