Encryption protects messages in transit. It does not protect an account when a fake support message talks a user into handing over access.
That is the real lesson behind a new FBI and CISA warning issued on March 20, 2026. According to the alert, Russian intelligence-linked actors are running phishing campaigns against commercial messaging application accounts, and the campaign has already led to unauthorized access to thousands of accounts. The agencies said the attackers did not break Signal’s encryption or the app itself. Instead, the attackers used social engineering, fake support messages, malicious links, and requests for verification codes or account PINs to gain access.
For regular users and small businesses, the lesson goes beyond Signal. A secure app can still become a weak point when a user trusts a fake warning, shares a one-time code, or approves a device link they did not initiate. The software may still be working as designed. The attacker wins by abusing trust.
What Happened
The FBI Internet Crime Complaint Center and CISA published a joint public service announcement warning that Russian intelligence service actors are targeting commercial messaging applications through phishing. The alert says the campaign has hit people of high intelligence value, including current and former U.S. government officials, military personnel, political figures, and journalists, but the method itself is not limited to those groups.
The same tactic can work against any user who trusts a fake message enough to respond. According to the warning, threat actors send phishing messages that look like automated support accounts for messaging platforms. Those messages pressure targets into clicking a link, sending a verification code, or sharing an account PIN.
If the victim complies, the attacker can gain unauthorized access by linking the attacker’s device to the victim’s account or by taking over the account outright. Signal matters here because the alert notes reporting showing these actors specifically target Signal accounts, even though the same methods can be used against other messaging platforms too.

Why This Matters To Normal Users
Many people hear the phrase secure messaging app and assume every part of the experience is secure. That is where the trouble starts.
End-to-end encryption protects message content inside the platform’s security model. It does not stop a user from replying to a fake support bot, handing over a one-time code, or tapping a malicious link. The FBI and CISA made that distinction directly by saying the actors compromised accounts, not the apps or their encryption.
Regular users deal with this kind of pressure every day. One message claims suspicious activity. Another says an unfamiliar device signed in. Another warns of a possible data leak. The wording changes, but the pattern stays the same. The attacker creates urgency, claims to be helping, and pushes the victim into taking an action that benefits the attacker.
This story matters beyond Signal because the core issue is trust abuse. A fake support message can do real damage when a user believes it.
How The Signal Support Scam Works
The attack chain is simple.
- A fake support or security message appears in chat. The government warning includes examples that pretend to come from “Signal Security support ChatBot” or “Signal support.” Some messages claim suspicious activity was detected. Some claim a third-party device has connected to the account. Some ask the user to complete a quick verification step.
- The message creates pressure. The attacker wants the target to feel rushed, concerned, and off balance. A nervous user is more likely to act before thinking the situation through.
- The fake support message asks for something specific. In the FBI and CISA warning, that includes verification codes, account PINs, or actions involving a malicious link.
- The victim complies. Once that happens, the attacker can link a new device to the victim’s account or seize control of the account outright. The government says compromised actors can then read messages, view contact lists, send messages, and launch more phishing attacks against other accounts.
Why Encryption Does Not Stop Account Theft
Encryption protects data from outsiders who try to intercept or read message content without authorized access. It does not stop account abuse after an attacker gets inside through deception.
The FBI and CISA spelled this out clearly. Their alert says phishing can bypass encryption entirely by gaining access to user accounts. The attacker does not need to crack the encryption if the victim has already handed over the keys through a fake support exchange.
That distinction matters because people often think a secure app failed when an account gets hijacked. In this case, the better explanation is different. The app’s encryption may still be working exactly as intended, while the account owner has been tricked into authorizing the wrong person.
Red Flags To Watch For
The FBI and CISA warning gives users a clear basis for spotting this kind of scam.
Urgent Security Warnings
A message that suddenly claims suspicious activity, a data leak, or an unfamiliar login attempt is trying to push the user into panic mode. Panic leads to bad decisions.
Requests For Codes Or PINs
The government warning says attackers are asking victims for verification codes and account PINs. A chat message that asks for those items is a major red flag. Legitimate support should not need a user to send sensitive codes through chat.
Fake Support Or Security Bot Language
The sample phishing messages in the alert use language such as “Signal Security support ChatBot” and “Signal support.” The words sound official on purpose. The attacker wants the message to feel automated, neutral, and trustworthy.
Pressure To Click A Link Immediately
The FBI and CISA specifically warn users to scrutinize links before clicking. A message that pushes instant verification through a link is not just annoying. The link may lead to malware, account abuse, or device linking controlled by the attacker.
Strange Requests From Known Contacts
The government also warns that even messages from “friends” may be suspicious if the request feels odd or unusual. A compromised account can be used to phish the next person in the contact list.
How To Protect A Signal Account From Phishing
The best defense is simple, boring, and effective.
Never share verification codes, PINs, or two-factor authentication codes for an action you did not start yourself. The government warning states that users should never share their PIN or 2FA codes for an action they did not initiate.
Do not trust unsolicited support messages sent through chat. The FBI and CISA say legitimate messaging app support services generally communicate through official email addresses, will not request verification codes through direct messages inside the application, and do not send users links to “verify” or “restore” accounts.
Open the app directly instead of tapping the link in the message. If an account warning looks serious, check account settings, linked devices, and security features from inside the app or from the official website you navigate to yourself.
Review linked devices and active sessions regularly. The government alert explains that one attack path involves linking the attacker’s device to the victim’s account. A routine check helps catch something the user did not authorize.
Use a second channel to verify suspicious messages. The FBI and CISA recommend contacting the sender through another means of communication before providing any information. A phone call, separate email, or verified website is safer than trusting the message that just arrived.
Pay attention to group chats. The government guidance tells users to verify group participant lists regularly and watch for duplicates or fake accounts. A fake duplicate profile in a work group or family chat can become the next entry point for phishing or impersonation.
Never Do These Three Things
- Never send a verification code, PIN, or 2FA code through chat.
- Never tap a support link inside a suspicious message without checking the account directly.
- Never assume a message is safe just because it looks official or comes from a known contact.
Why Small Businesses Should Care
Small businesses often use chat platforms for quick approvals, staff coordination, customer contact, file sharing, and internal problem-solving. That convenience creates risk when one hijacked account can expose conversations, impersonate an employee, or launch new phishing messages from a trusted identity.
The FBI and CISA warning says compromised accounts can be used to view messages, access contact lists, send messages, and conduct additional phishing against other messaging accounts. For a small business, that can mean exposed internal discussions, fake requests sent from a manager’s account, or customer conversations that suddenly become fraud bait.
A small company does not need an expensive security stack to reduce this risk. A small company does need clear habits. Staff should know that support messages inside chat deserve suspicion. Staff should know not to send one-time codes in conversation. Staff should know how to verify account issues through official channels instead of in-message prompts.
What To Do After A Signal Account Compromise
Anyone who already clicked, replied, or shared a code should act fast.
- Start by checking for linked devices and removing anything unfamiliar. The FBI and CISA warning describes linked-device abuse as one of the main ways attackers maintain access.
- Reset the account’s security protections where the platform allows it. Review account recovery methods, PIN settings, and any other sign-in or device-approval controls tied to the account.
- Warn contacts that suspicious messages may come from the compromised account. A stolen chat account is not just a privacy problem. It can become a launchpad for more scams.
- Review other accounts that may use similar recovery methods or similar contact paths. An attacker who gains access to one trusted communication channel may try to leverage that access elsewhere.
- Report the incident. The IC3 says it is the central hub for reporting cyber-enabled crime and advises the public to file a report even if they are unsure whether the complaint qualifies.
Frequently Asked Questions
Can Signal Encryption Stop Phishing?
No. The FBI and CISA warning describes account theft that happens when users are tricked into sharing codes or taking actions that give attackers access. The agencies said the actors compromised accounts, not the app’s encryption or the application itself.
Can A Fake Support Message Take Over An Account?
Yes. The government warning says attackers can gain unauthorized access by adding their device as a linked device or through a full account takeover after the victim complies with the phishing request.
Should Support Ever Ask For A Verification Code In Chat?
Treat that as suspicious. The FBI and CISA warning says legitimate support services will not request verification codes through direct messages inside the application and do not send users links to “verify” or “restore” accounts.
Is This Only A Signal Problem?
No. The warning covers commercial messaging applications broadly, while noting that reporting shows the actors specifically target Signal accounts and can apply similar methods against other commercial messaging platforms.
Final Takeaway
Secure apps still depend on insecure human decisions.
The danger is not always malware, a coding flaw, or broken encryption. Sometimes the real problem is a message that sounds official, creates urgency, and gets a user to cooperate with the wrong person. The March 20, 2026 FBI and CISA warning makes that clear. Russian intelligence-linked actors did not need to break Signal’s encryption to get results. They only needed users to trust the wrong message.
Secure software matters, but trust is still one of the easiest systems to hack.
Where JENI Fits After A Phishing Scare
After a phishing scare, users still have to inspect the local device, clean up clutter, and document what was checked. That is where JENI fits. JENI does not stop a user from handing over a verification code in a fake support chat, and it does not replace careful habits. JENI fits on the cleanup, review, and recovery side of the problem by helping keep the local system cleaner, more stable, and easier to assess.
Practical Value During Cleanup And Review
When a phishing scare happens, the goal is not magic protection. The goal is reducing confusion, checking the machine, clearing junk, and making follow-up steps easier. JENI supports that practical side by improving system clarity, removing clutter, and producing a report that helps document what was done after a suspicious event.
- Browser cache, temp files, logs, and stale clutter can bury useful clues after a phishing scare. Cleaning the system helps users review recent activity with less noise.
- A stable PC matters after account fraud concerns. Faster response, fewer errors, and cleaner storage make it easier to check devices, sessions, and saved data safely.
- A maintenance report creates a simple record of cleanup steps after suspicious messages, which helps small businesses track what was checked and when it happened.
JENI makes the most sense as part of the recovery and hygiene side of this problem, not as a substitute for careful user behavior. Fake support scams succeed because people trust the wrong message, so the first fix is always better habits. After that, a clean, stable, well-documented system helps users review accounts, remove clutter, and handle the aftermath with less confusion and less wasted time.


