Washington: FBI Director Kash Patel announced that the bureau has identified a Russian intelligence campaign targeting users of commercial messaging applications to access high-value accounts. The campaign has led to unauthorized access to thousands of individual accounts globally, with targets including current and former US government officials, military personnel, political figures, and journalists.
According to Anadolu Agency, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory stating that Russian intelligence actors had compromised individual accounts without breaking the encryption of the applications themselves. The attack utilizes phishing messages disguised as automated support notifications from the platforms. These messages trick targets into clicking links or handing over verification codes or account PINs, allowing the attacker's device to be added as a linked device or giving them full control of the account.
After gaining access, the actors can view messages and contact lists, send messages as the victim, and conduct additional phishing from a trusted identity, said Patel. He emphasized that the vulnerability lies with users rather than the apps, urging the public to take protective action.
The FBI and CISA advised users to pause and disengage if a message feels suspicious, never share verification codes or PINs for actions they did not initiate, and scrutinize links before clicking. They also recommended regularly checking group chat participant lists for duplicate or fake accounts, enabling message expiration features, and reporting suspected phishing to the FBI.