U.S. Announces $10 Million Reward in Hunt for Hackers Targeting WhatsApp, Signal
The U.S. Department of State is offering a reward of up to $10 million for information that can help identify or locate members of the UNC5792 and UNC4221 cyber threat groups, which are linked to Russian intelligence and military organizations.
The reward is part of the State Department’s Rewards for Justice (RFJ) program, which focuses on foreign state-sponsored actors involved in cyberattacks against U.S. critical infrastructure.
According to the announcement, “RFJ is seeking information on UNC5792, a malicious cyber group associated with the Russian Federal Security Service (FSB) Border Guards, and UNC4221, a malicious group of cyber actors working on behalf of Russian military services.”
UNC5792 has been responsible for large-scale phishing campaigns targeting Signal and WhatsApp accounts belonging to U.S. government officials, military leadership, and allied personnel.
The U.S. government is seeking details on both groups, including:
* Identities, locations, biographies, and affiliations of individuals involved in UNC5792 and supporting networks
* Connections to Russian intelligence agencies, contractors, and third-party service providers
* Operational infrastructure such as domains, servers, hosting services, data storage, tools, frameworks, and software
* Financial information including funding sources, bank accounts, payment channels, and related transactions
* Cryptocurrency wallets, blockchain activity, and other digital financial networks supporting their operations
Recent updates from the FBI and CISA to a March 2026 advisory highlight new tactics observed in these campaigns, including attempts to steal Signal Backup Recovery Keys.
Authorities report that attackers have been impersonating Signal support staff in direct messages, instructing targets to complete a supposed mandatory two-factor authentication process.
This tactic is designed to trick users into revealing backup recovery keys, which can then be used to access previous messages and sensitive communications on the platform.
U.S. officials emphasize that messaging platforms and their encryption have not been compromised; however, these social engineering techniques can still successfully extract sensitive data from users.
The RFJ program notes that thousands of accounts across commercial messaging platforms have been compromised using these methods.
Typical targets include U.S. and NATO government officials, diplomats, defense and intelligence personnel, policy analysts, journalists covering Russia and Ukraine, NGOs supporting Ukraine, and researchers focused on security and Russian affairs.
Authorities remind users that legitimate support teams never request verification codes, recovery keys, or account credentials via chat messages, nor do they send links asking for account verification or restoration.
Signal users are advised to treat such messages as malicious and rely only on official communication channels for support.