Signal phishing, Pay Tel breach
Signal users are being targeted with phishing attacks that harvest their backup recovery keys, potentially exposing their encrypted online backups.
Phishing for Signal backups
A hacking campaign is tricking Signal users into giving up their secret recovery key, which decrypts every message stored in the backup. Attackers send emails that mimic Signal’s branding and request the key under the pretext of ‘account verification.’ Security researchers say the phishing pages capture the key and forward it to a remote server. The technique bypasses Signal’s end-to-end encryption because the key itself is the sole decryption credential.
The phishing campaign highlights a critical vulnerability in Signal’s backup system. If attackers obtain the recovery key, they can access all the messages stored in the backup, which may include sensitive information. This attack is particularly effective because it targets users who are likely to have sensitive conversations on Signal. For instance, users who rely on Signal for work-related discussions or personal matters may have their confidential information compromised.
Pay Tel data exposure
Pay Tel, a prison phone service provider, left driver’s license images and inmate call logs in a publicly reachable bucket. Security analysts discovered the bucket on a public cloud platform and reported that over 300,000 caller records were exposed. Each record contained the caller’s name, address, and a scanned copy of the driver’s license. The leak also included fragments of recorded inmate communications.
The exposed data may put callers and inmates at risk of identity theft and other malicious activities. The breach also raises questions about Pay Tel’s data handling practices and whether the company took adequate measures to secure sensitive information. Pay Tel’s incident highlights the challenges of managing sensitive data in industries with complex regulatory requirements.
Google insider betting on Polymarket
A Google software engineer used internal ‘Year in Search’ data to place bets on Polymarket, earning $1.2 million. The engineer was arrested and faces charges of securities fraud and money-laundering. The FBI’s statement underscores that internal data can constitute material non-public information when used for market speculation.
The engineer likely exploited the internal data to gain an unfair advantage in the prediction market. This case highlights the importance of protecting sensitive information within organizations and the potential consequences of insider trading. The use of internal data for personal gain raises concerns about the integrity of prediction markets and the need for robust safeguards.
History of data breaches and phishing attacks
Phishing campaigns targeting messaging apps and data breaches in industries with sensitive information are not new. Previous incidents have shown that even with robust security measures, data can still be compromised. For example, in 2020, a phishing campaign targeted WhatsApp users, resulting in the exposure of sensitive information.
The Pay Tel breach is also not an isolated incident. Other companies in the prison phone service industry have experienced data breaches, highlighting the need for improved data handling practices. The Google insider betting case demonstrates that even with strict controls in place, internal data can still be misused.
Technical mechanics: How phishing campaigns work
Phishing campaigns like the one targeting Signal users typically involve creating fake websites or emails that mimic the branding of the targeted service. The goal is to trick users into divulging sensitive information, such as login credentials or recovery keys. In the case of Signal, the phishing campaign targeted users who had enabled backup encryption, which stores messages in a recoverable format.
The phishing pages used in the campaign captured the recovery key and forwarded it to a remote server, allowing attackers to access the encrypted backups. This technique highlights the importance of user education and awareness in preventing phishing attacks.
Downstream implications: Who benefits and who is squeezed?
The incidents involving Signal, Pay Tel, and Google have significant implications for data stewardship and user education. Organizations must prioritize data security and user education to prevent similar breaches. The use of encryption and secure communication protocols is crucial, but it is equally important to educate users about the risks associated with sharing sensitive information.
The Google insider betting case also raises questions about the integrity of prediction markets and the need for robust safeguards to prevent insider trading. Regulators must balance the benefits of prediction markets with the need to prevent illicit activities.
Industry context: Secure communication and prediction markets
The incidents involving Signal, Pay Tel, and Google highlight the growing importance of secure communication and data protection. As more people rely on digital services for sensitive conversations and transactions, companies must prioritize data security and user education.
Prediction markets like Polymarket have gained popularity in recent years, but they also raise concerns about insider trading and market manipulation. Regulators must balance the benefits of prediction markets with the need to prevent illicit activities.
Implications for data stewardship
All three incidents share a common failure: privileged data escaped its intended boundary. Organizations must pair encryption with user-education programs that explain the irreversible risk of sharing recovery credentials.
The Google engineer was arrested on February 20, 2025, and faces charges. The Pay Tel breach was discovered and secured in early February. Signal’s phishing campaign was first reported in late January.
The Department of Justice is expected to release a detailed indictment in the Google case. As these incidents demonstrate, data security is a critical concern for organizations and individuals alike. Companies must take proactive measures to protect sensitive information and prevent data breaches.
Updates
- 2026-06-03 — Persona 5 Royal is one of many additions to Xbox Game Pass for June (source)
- 2026-06-03 — The Humanoid Robot of the Future Is a 6-Foot-Tall Beefcake With a Chinese Body and an American Brain (source)
- 2026-06-01 — MagSafe Monday: Why the PISEN 5000mAh battery pack is great for everyday carry (source)
Related Articles
Google Employee Charged with $1M Insider Trading on Polymarket
Google employee accused of insider trading on prediction market Polymarket using non-public search term data.
Google Engineer Charged with Fraud Over $1.2M Polymarket Bets
Google security engineer charged with fraud
US Bets on AI to Catch Insider Trading
The Commodity Futures Trading Commission is using AI to detect insider trading in prediction markets. The move aims to prevent market manipulation.