Signal’s new security warnings are a practical response to a growing reality: encryption protects messages in transit, but it cannot protect users from being socially engineered into handing over access themselves. Attacks abusing Signal’s linked-device feature, QR codes, and fake “Signal Support” messages show how threat actors increasingly target trust, urgency, and user behavior rather than only technical flaws.

Adding warnings such as “Name not verified,” “No groups in common,” reminders that Signal will never ask for registration codes, PINs, or recovery keys, and richer safety prompts introduces useful friction at the exact point where users may be manipulated. Users should remain alert to unknown contacts, never share verification codes, and regularly review linked devices. Apparently even secure messaging apps now need to protect people from confidently scanning the wrong QR code, because attackers understand human psychology far too well.


Signal has introduced new in-app confirmations and warning messages as additional safeguards against phishing and social engineering attempts that could lead to various forms of fraud. [...]

Source: Signal adds security warnings for social engineering, phishing attacks via Bleeping Computer — published 12 May 2026.