Signal remains strongly encrypted, but recent phishing attacks show that social engineering can still compromise accounts. Western officials say Moscow-linked groups targeted senior German politicians, and similar campaigns were reported in the Netherlands and the United States. The incidents underline that robust cryptography must be paired with user vigilance and account protections to stay secure.
Is Signal Still Secure? What the Recent Phishing Attacks Reveal

Signal, long praised as one of the world's most secure messaging apps, has recently been targeted by phishing campaigns that Western officials say are linked to Russia-backed groups. The incidents — reported in Germany, the Netherlands and the United States — have renewed discussion about how even highly secure apps can be compromised through social engineering and account takeover.
How Signal Protects Your Messages
End-to-end encryption: Signal encrypts messages so that only the intended recipient holds the decryption keys. Intermediaries — including Signal itself, internet providers or eavesdroppers — cannot read message content without those keys.
Minimal metadata: Signal is designed to collect far less metadata than many competitors. Certain delivery- and recipient-related details are intentionally limited to reduce what the company can access or disclose.
Independent non-profit governance: Unlike apps owned by large tech corporations, Signal is operated by the Signal Foundation, a nonprofit that says it is funded mainly by grants and donations rather than advertising-driven data business models. That independence has helped build trust among privacy-conscious users.
Who Runs Signal?
Signal was founded in 2012 and is run by the Signal Foundation, based in Mountain View, California. The app’s core encryption protocol was developed by cryptographer Moxie Marlinspike. WhatsApp co-founder Brian Acton provided early funding (reported at around $50 million) to help launch the project. While Signal and WhatsApp share lineage in the protocol, their governance and data practices differ.
Signal’s leadership has included prominent privacy advocates. The foundation emphasizes it cannot be acquired by major tech companies and that its operations prioritize user privacy over monetization through data extraction.
Were Signal’s Encryption Systems Broken?
No — the cryptography appears intact. Investigators say the recent incidents did not involve breaking Signal’s end-to-end encryption. Instead, attackers used phishing and social-engineering techniques to gain control of individual accounts.
Phishing messages may pose as Signal support (fake security alerts, group-chat invitations, etc.). When users click malicious links or reveal verification codes or account details, attackers can take over the account and read conversations or impersonate the user.
Account takeover can expose messages visible on the compromised device or allow attackers to join or create groups under the victim’s identity. These risks show that strong cryptography is only one part of security; user practices and account protections also matter.
Practical Takeaways
- Signal’s encryption remains a gold standard for private messaging, but no app can prevent users from being tricked into handing over access.
- Be wary of unsolicited messages that ask you to click links, supply verification codes, or enter account details — even if they appear to come from support.
- Enable available account protections such as registration locks, use verified contact methods, and keep software up to date.
Signal did not immediately respond to requests for comment about the recent incidents.
Help us improve.























