The Fake “Security Team” Message That’s Actually a Login Heist
Someone on your team gets a message inside a work messaging app. It looks like it is from the app’s own security team, warning of suspicious login activity and asking for a verification code to confirm the account is really theirs. It feels routine, the kind of thing a legitimate support team asks for all the time. Sharing that code does not confirm anything. It hands a stranger full access to the account, without ever breaking the app’s actual encryption.
Security researchers have a name for this one too: a verification code phishing scam, built to make handing over your account feel like the responsible thing to do.
A Request That Feels Routine
Verification codes feel safe to share because, in plenty of other contexts, sharing one is exactly the right move. A bank calls to confirm a transaction, a retailer texts a code to verify a password reset, and handing that code over closes the loop. That habit is precisely what this scam borrows. A message shows up wearing the shape of routine account security, using the same language real support teams use, and the instinct built by every legitimate version of this request kicks in before a second thought does.
The messages themselves are built to look bureaucratic and procedural rather than urgent or threatening, which makes them easier to trust, not harder. One version circulating right now claims to be from the messaging app itself, referencing a security update and mandatory two-factor verification, then walks the user step by step through locating their backup recovery key and copying it into the chat. Another version frames it as a data recovery emergency, warning that messages and media are at risk of being lost unless the user backs up their account and pastes the recovery key into the conversation. Both read like something a cautious person would want to comply with, not resist.
None of this is limited to personal use, either. Plenty of small businesses now run at least part of their day-to-day communication through apps like Signal, WhatsApp, or similar messaging platforms, whether for quick coordination with a vendor, a remote team member, or a client who prefers texting over email. Any account used for business purposes carries business contacts, business conversations, and sometimes business-sensitive details, which makes it worth exactly the same caution as a work email inbox.
How the Verification Code Phishing Scam Works
The Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency issued a joint update on June 26, 2026 describing exactly this pattern. Threat actors linked to Russian Intelligence Services have been running an ongoing phishing campaign against messaging app accounts, posing as automated support services inside the app itself. The specific individuals named as targets in the alert are current and former government officials, military personnel, political figures, and journalists, not small businesses. That distinction matters for accuracy, and it does not make the underlying technique any less relevant to everyone else.
Here is what makes this campaign notable from a technical standpoint. The attackers never actually broke the messaging app’s encryption. They did not need to. Instead, they convinced targets to voluntarily hand over a verification code, a PIN, or a backup recovery key, and that single action granted full access to the account’s message history and contact list. Once documented in a public federal alert, a technique like this does not stay confined to its original targets. Scammers copy what works, and a method that fools people trained to be cautious works just as well against anyone else who has not seen the pattern before.
The agencies were direct about what a legitimate request looks like, and what one does not. A real support service for a messaging app communicates through official company email, not a message inside the app itself. It will not ask for a verification code within the app. It will not send a link asking someone to verify or restore an account. Any message that does one of those three things is not coming from the platform it claims to represent, regardless of how official the wording sounds.
What This Means for Your Team
Never share a verification code, PIN, or recovery key with anyone, no exceptions. A legitimate support team already has what it needs to help you without asking you to hand over a code. If a message asks for one, that request alone is the reveal.
Know that real support does not reach out inside the app itself. Official communication from a messaging platform comes through the company’s real email address, not a chat message posing as an automated security alert.
Treat any request to back up an account and share the recovery key as a stop sign. This is the exact mechanism the current campaign uses. A real platform never needs you to copy a recovery key into a conversation with anyone.
Verify through a separate channel before acting on any security warning. If a message claims your account is at risk, open the app’s actual settings yourself or check the company’s official website directly, rather than following instructions inside the suspicious message.
Assume a procedural, calm tone does not make a message safer. These scams work specifically because they avoid urgency and panic. Boring and official-sounding is not the same as legitimate.
Questions to Ask Your Team
- Would our team recognize that a request for a verification code is always the red flag, no matter how official the message looks?
- Do we have a clear, simple policy for what to do if someone receives a message like this on a work device or work account?
- Are our messaging apps for business communication set up with the strongest available account protections already in place?
- Who should an employee tell if they already responded to a message like this before realizing something was off?
The Takeaway
This is not a scam that requires special technical skill to defend against. It requires one habit: never share a verification code, PIN, or recovery key with anyone, regardless of how the request is worded or where it appears. The attackers in this specific campaign are after high-value targets, but the tactic they are using is now public, documented, and copyable by anyone. A business that builds this one habit into how its team operates is protected against this scam and the next several versions of it that will inevitably follow.
It is also worth remembering that this campaign was significant enough for two federal agencies to jointly update their public warning about it within a few months of the original alert. That update cycle is a signal on its own. The people running this campaign are actively refining it, which means the businesses reading about it now have a real head start, provided that head start turns into an actual habit rather than something read once and forgotten.
As always, remember that your Paradigm team is just a call, email, or text away for any questions or concerns that may arise.
If you would like a second set of eyes on how your team handles security prompts inside the messaging apps you use for work, we’re here to help. No pressure, no sales pitch, just an honest conversation about where you stand.
Your Paradigm Team
P.S. If messages that ask you to hand over something you should never share are on your radar, our blog on the fake FBI recovery scam covers a different version of the same idea, a message that looks official enough to trust, right up until it costs you something.