Hi everyone,
This week on Shared Security, we discuss Russian intelligence targeting Signal, WhatsApp, and Telegram users. The important lesson is not that encrypted messaging is useless and vulnerable. It’s that encryption does not save you when an attacker steals your account, adds a linked device, compromises an endpoint, or talks you into handing over recovery information.
That distinction matters. The scary headline is “Russian intelligence targets secure messaging apps.” The useful takeaway is more practical: account recovery, linked-device approvals, endpoint hygiene, and support-message skepticism are part of secure messaging too.
If someone can convince you to hand over a recovery key, scan a QR code, approve a linked device, or trust a fake support flow, they do not need to break Signal’s encryption. They can go around it.
In this episode, we talk through what the FBI warning actually says, why QR-code phishing and linked-device abuse are so effective, and how to talk about this without turning every encrypted messaging story into a panic situation.
Links from the episode
FBI IC3 PSA — Russian Intelligence Services Continue to Target Commercial Messaging Applications: https://www.ic3.gov/PSA/2026/PSA260626
The Hacker News — FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys: https://thehackernews.com/2026/06/fbi-warns-russian-intelligence-hackers.html
Infosecurity Magazine — FBI Sounds Alarm Over Russian Intelligence Signal Phishing: https://www.infosecurity-magazine.com/news/fbi-alarm-russian-intelligence/
Rewards for Justice — UNC5792: https://rewardsforjustice.net/rewards/unc5792/
SecurityWeek — US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve: https://www.securityweek.com/us-offers-10-million-bounty-for-russian-state-hackers-as-messaging-app-attacks-evolve/
Quote from this week’s episode
No matter how secure the transmission is, the endpoints are your weakness.
— Kevin Tackett
Tom’s take
Secure messaging is still worth using. Signal, WhatsApp, and Telegram are not suddenly worthless because intelligence services are targeting their users. But the security conversation has to include the things around the app: account recovery, linked devices, endpoint compromise, PINs, backup keys, and social engineering.
The practical advice is not “stop using encrypted messaging.” It is: know what devices are linked to your account, be suspicious of support messages asking for codes or recovery material, keep recovery information somewhere safer than screenshots or browser autofill, and think carefully before assuming encryption protects every part of the workflow.
Also worth your attention this week
Facial recognition in UK shops is expanding into police alerts. The Guardian reported on retail facial-recognition deployments that can identify shoppers and trigger police notifications, raising the usual but still important questions about consent, accuracy, retention, and whether “shoplifting prevention” becomes a broader surveillance layer. Source: https://www.theguardian.com/technology/2026/jul/10/facewatch-facial-recognition-uk-shops-instantly-alerts-police-civil-liberties
Meta killed Instagram’s Muse AI after privacy backlash. This is another reminder that “AI features” often arrive wrapped in vague data-use assumptions, and the public pushback can become the only real product review process. Source: https://thenextweb.com/news/meta-muse-image-instagram-privacy-backlash-pulled
A study of 281 free Android VPN apps found leaks and tracking. Free VPNs keep proving the same point: if the business model is unclear, the privacy story probably is too. This is useful listener-facing material because VPNs are still marketed as one-click privacy tools. Source: https://thehackernews.com/2026/07/study-of-281-free-android-vpn-apps.html
Listen / Watch
🎧 Audio Podcast: https://sharedsecurity.net/2026/07/13/signal-phishing-and-russian-intelligence-targeting-messaging-apps/
▶️ YouTube Version: https://youtu.be/fxFfY_e_MOI
We’d love your feedback
Have a secure messaging habit or recovery-key lesson learned the hard way? Reply and tell us what changed your process.
Thank you to our sponsors!
Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.
🎁 Get 10% off your order of high quality faraday products built to protect your privacy from SLNT! Visit: https://slnt.com and use discount code "sharedsecurity" at checkout.
Closing
If this episode was useful, please support Shared Security by subscribing on YouTube, becoming a YouTube channel member, and following the show on your preferred podcast app.
Stay safe, stay secure, and stay private.
Tom Eston
Founder and Host, Shared Security Podcast

