Signal Launches Verified In-App Chat to Fight Rising Phishing Scams


Signal has introduced a verified Official Chat feature on iPhone, giving users a single authenticated communication channel from the company as it steps up efforts to combat phishing attacks that have targeted politicians, journalists and government officials.

The feature, included with Signal version 8.17, displays a chat simply named “Signal”, marked with a blue verification check and an Official Chat badge. Previously available on Android and desktop, it is now rolling out to iOS users.

Signal Launches Verified Official Chat to Protect Users From Phishing
Signal Launches Verified Official Chat to Protect Users From Phishing

The welcome message makes the purpose of the feature clear: this is the only official chat operated by Signal, and users should ignore or report any conversations claiming to represent Signal support. The chat is muted by default and can also be blocked.

Response to sophisticated phishing attacks

The rollout follows a series of high-profile phishing campaigns in which attackers impersonated Signal support staff to gain access to users’ accounts.

Earlier this year, Germany’s domestic intelligence agency and national cybersecurity office warned that a suspected state-backed group targeted senior politicians, military officials, diplomats and journalists by posing as “Signal Support” or a fake “Signal Security ChatBot.”

Victims were tricked into scanning malicious QR codes or providing verification codes, allowing attackers to link their Signal accounts to another device and gain access to messages and contacts.

German authorities later launched an espionage investigation after reports that around 300 accounts connected to political figures had been compromised. While officials said Russia was suspected, no formal attribution has been made, and Moscow has denied involvement.

Global warnings issued

The campaign extended beyond Germany.

In March, the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) warned that actors linked to Russian intelligence services were targeting users of commercial messaging platforms worldwide.

According to the agencies, current and former government officials, military personnel, political figures and journalists were among those targeted, with thousands of accounts reportedly compromised through phishing rather than technical vulnerabilities.

Authorities in France and the Netherlands also issued similar alerts.

Encryption remains secure

Signal stressed that the attacks did not compromise the platform’s end-to-end encryption.

Instead, attackers relied on social engineering, convincing victims to voluntarily provide access to their accounts by pretending to be legitimate Signal representatives.

To strengthen user protection, Signal has introduced several new security measures this year, including:

  • Verified Official Chat for company announcements.
  • Warnings that profile names do not confirm a person’s identity.
  • Additional confirmation prompts for message requests.
  • In-app reminders that Signal will never ask for registration codes, PINs or recovery keys.

The new Official Chat is designed to help users distinguish genuine company communications from increasingly sophisticated phishing attempts.

Tags:
CISA, cybercrime, cybersecurity, encryption, FBI, Germany, Greek, Ios, iPhone, messaging apps, Online Security, Phishing, privacy, Signal, technology



Source link

Leave a Comment