Skip to main content
LiMP VPN
All news

German Police Read WhatsApp and Signal Without Hacking

German Police Read WhatsApp and Signal Without Hacking

In short: Germany's Customs Criminal Office (ZKA) has officially been reading WhatsApp, Signal and Telegram conversations since 1 August 2025 — without breaking end-to-end encryption. A classified ZKA directive published by netzpolitik.org in September 2026 revealed the technical details. The core finding: end-to-end encryption protects messages in transit, but it cannot stop a second device from being secretly added to your account.

What happened and why it matters

In early September 2026, netzpolitik.org — a German outlet specialising in digital civil rights — published a classified internal directive from the Zollkriminalamt (ZKA), Germany's Customs Criminal Office. The document confirmed: account cloning was moved from a pilot programme to a permanent investigative tool on 1 August 2025.

The pilot began in late 2023. After two years of testing, the technique proved reliable enough for ZKA to embed it in standard practice for investigating serious and organised crime. The actual scale of use remains classified — the agency cited state secrecy.

It is important to understand what this is not: a flaw in Signal or WhatsApp encryption. Modern end-to-end messengers protect data reliably in transit — our privacy and security blog covers these protections in detail. The vulnerability is not in the encryption — it is in the fact that messengers natively support multiple linked devices, and that feature creates the opening.

How the linked-device method works

WhatsApp Web, Telegram Web and Signal Desktop are mainstream features used by millions every day to access their chats from a computer. The mechanism is simple: scan a QR code or enter a confirmation code, and your computer becomes a "trusted device" that receives decrypted messages.

ZKA exploits exactly this. Investigators add their work computer as a second trusted device — the messenger server treats it as a legitimate client and starts delivering all messages in plaintext. All that is needed is the QR code or confirmation code, obtainable in three ways:

  • Physical access to an unlocked phone — during a search or arrest;
  • SMS interception of the confirmation code via lawful-intercept systems or SS7 vulnerabilities;
  • A phishing page that mimics the standard device-linking flow.

Once linked, the investigator receives all incoming and outgoing messages in real time. For Signal, up to 45 days of message history become accessible. Most users would never notice a rogue linked device unless they specifically check their settings.

What this means for your privacy

Germany's Federal Court of Justice ruled in 2026 that secretly accessing a messenger account constitutes a "serious interference with an IT system" and cannot be treated as routine telecommunications surveillance. Higher legal hurdles apply — at least in Germany.

From a personal security perspective, the critical point is different. German law enforcement has documented and formalised the practice — meaning the technique demonstrably works. The same approach is available to state actors in other countries, and to criminals via phishing or momentary physical access to a device. The risk is not limited to being under investigation in Germany — it applies to anyone who values the confidentiality of their conversations.

The essential conclusion: a messenger with end-to-end encryption is not equivalent to secure communication if your account is linked to an unknown device. Comprehensive digital security requires multiple protection layers working together.

How to check and remove unknown devices right now

Auditing your linked devices takes under a minute in any major messenger:

  • WhatsApp: Settings → Linked Devices. Tap any unfamiliar device → Log Out.
  • Signal: Settings → Linked Devices. Tap a device → Remove.
  • Telegram: Settings → Devices. Tap a session → Terminate Session.

Make this check at least once a month, and immediately after any situation where your phone was out of your control: sent in for repair, left unattended, or inspected at a border crossing.

Additional steps to harden your messenger accounts:

  • Enable Signal's Registration Lock PIN (Settings → Privacy → Advanced → Registration Lock). Without it, re-registering your number on a new device is significantly easier for an attacker.
  • Enable WhatsApp Two-Step Verification (Settings → Account → Two-Step Verification).
  • Use a VPN to encrypt network-level traffic — it hides from your ISP the fact that you use messengers and masks your broader online activity, even though it does not directly prevent account-level compromise.

Sources

German Police Read WhatsApp and Signal Without Hacking