Lead story
Fake "Support" Texts, Real Credential Theft: Russia's FSB Was Reading Your Messages
The Security Service of Ukraine and the FBI have jointly disclosed a long-running Russian intelligence operation that used fake technical-support SMS messages to steal messaging credentials from government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States. The campaign is attributed to Russian intelligence services — and the operational detail in the joint disclosure makes it one of the more instructive espionage write-ups of the year.
The mechanics are straightforward, which is precisely what makes them effective. Targets received text messages impersonating legitimate platform support teams — think "your account has been flagged for suspicious activity, click here to verify." Once a target clicked through and entered credentials, attackers had access not just to current messages but to archived conversation history. For intelligence services, that archive is the prize.
What's notable here is the targeting profile. This wasn't a spray-and-pray phishing run after banking credentials. The victims were specifically people who matter: military officers coordinating defence, politicians shaping policy, activists whose communications could expose networks. That specificity tells you this was a patient, resourced operation — not opportunistic crime dressed up as espionage.
The campaign also illustrates a persistent problem with SMS-based authentication and verification flows. Even users who are generally phishing-aware can be caught off-guard by a well-timed message that mimics a platform they actually use. The fake support pretext is particularly nasty because it creates urgency ("your account is at risk") while appearing to come from a trusted source.
What defenders should take from this is less about the specific lure and more about the attack surface. Messaging platforms that offer SMS-based verification flows are inherently vulnerable to this kind of impersonation. Hardware security keys or app-based authentication — anything that can't be intercepted or spoofed over SMS — dramatically reduces the exposure.
The joint SSU/FBI disclosure is also a signal worth reading carefully. Joint attributions at this level of detail are relatively rare and typically indicate that both agencies have high confidence in the attribution and want to establish a public record. The timing — mid-2026, with Russia's war in Ukraine still active — suggests this is partly operational (warning targeted communities) and partly political (naming Russia publicly in a period of diplomatic flux).
For Australian readers, the targeting profile is directly relevant. Australian defence personnel, politicians, and civil society figures are routine targets of foreign intelligence services — including Russia, but especially China and Iran. The ACSC has previously warned about SMS-based phishing against Australian government users, and the broader pattern here maps cleanly onto techniques documented in Australian threat advisories. If your organisation issues mobile devices to staff in sensitive roles and those devices still rely on SMS for any authentication flow, this disclosure is a useful prompt to review that.
The full technical indicators from the joint SSU/FBI advisory are worth pulling into your threat intel platform. The lure templates, infrastructure patterns, and targeting criteria are all documented — and this kind of nation-state technique tends to be recycled across campaigns.
