Signal completed a cross-platform rollout of encrypted backup enhancements with iOS version 8.30, adding on-device backups to iPhone and desktop clients on Linux, macOS, and Windows. Android now uses the same backup format, enabling restoration and migration of message history across Android, iOS, and desktop devices; encrypted local Wi-Fi transfers also streamline device migrations. Signal-hosted Secure Backups retain text and the latest 45 days of media for free, while a paid tier provides up to 100 GB of media storage. Disappearing messages set to expire within 24 hours are excluded from backups.
Both hosted and local backups are protected by recovery keys, but local backups rely solely on that key, which can decrypt every historical backup created with it. Signal said threat actors began targeting recovery keys following the feature’s initial release. Hosted backups add a daily rotating supplemental key retained in a Trusted Execution Environment. Separately, Signal introduced optional phone-number-free Android registration for a one-time US$3 fee, issuing users a 32-character account identifier and recovery key; users must create a username to remain discoverable without a phone number.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Signal released version 8.30, completing the first phase of its backup rollout across Android, iOS, Linux, macOS, and Windows. The release added on-device backups to iOS and desktop clients and moved Android to a unified cross-platform backup format.
Signal introduced its optional end-to-end encrypted Secure Backups service, providing hosted backup capability protected by recovery keys.
Signal stated that threat actors began targeting on-device backup recovery keys shortly after the backup feature's initial introduction. A local-backup recovery key can decrypt all previous backups encrypted with that key.
Signal introduced optional Android account registration without a phone number for a one-time US$3 fee intended to deter mass spam registrations. These accounts receive an account identifier and recovery key, and users are advised to create a username so others can find them.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceheise.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.