Signal adds security warnings for social engineering, phishing attacks
Signal has introduced new in-app confirmations and warning messages as additional safeguards against phishing and social engineering attempts that could lead to various forms of fraud.
The purpose is to introduce enough friction that users get the time to evaluate the safety of an external request.
Recently, there have been attacks targeting high-profile users with bogus โSignal Supportโ alerts, as highlighted by the FBI , the Dutch government , and the German authorities .
All incidents were attributed to Russian state-sponsored hackers, who abused the Linked Device feature to gain access to the targetโs account, chats, and contacts lists.
The attack works by convincing the victim to scan a QR code or share one-time codes, supposedly as part of a verification process to protect their accounts from suspicious activity. This allows threat actors to link their device to the target account and obtain access to all the data.
โTo help protect Signal users from phishing and social engineering attacks, weโve introduced additional confirmations and educational messaging in the app to help people better detect fraudulent profiles, especially message requests from scammers posing as Signal,โ the vendor explained .