Friday , October 2 2026
German

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their encryption or installing spyware on their phones. New documents published by German digital rights outlet Netzpolitik show the country’s Customs Office began testing the technique, known as “messenger monitoring,” in late 2023.

Although the customs agency warned that details of the method should be handled with “extreme sensitivity” to avoid jeopardizing its use, the technique isn’t rocket science. Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers.

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account. Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them.

How police gain access to encrypted messages legally

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance.

In the case of Signal, German security authorities warn that someone who successfully links another device can gain access to messages from the previous 45 days.

For Telegram, Netzpolitik cites a case involving a suspected dope dealer in Lower Saxony. Police secretly connected to his Telegram account in March 2022. The suspect discovered the access a few hours later, but by this time, the police had already copied his message archive.

According to official papers seen by Netzpolitik ,these techniques became an official practice in August 2025, after officials said they had produced “significant investigative successes” in serious and organized crime cases.

However, Netzpolitik questions the legality of this method, the extent of its usage, and its choice of targets.

Federal police monitor innocent couple’s WhatsApp messages

Netzpolitik cites a 2020 court case involving a married couple, who were not suspects, to highlight how physical access was used to monitor the phones of innocent people.

The couple voluntarily handed their phones to German police while being questioned as witnesses about their daughter, allowing officers to inspect and photograph messages she had sent them.

While the police had the phones, officers secretly activated WhatsApp Web and connected the accounts to a computer operated by the Bundeskriminalamt , or Federal Criminal Police Office (BKA).

Once that connection was made, the police could potentially:

Read new WhatsApp messages after the phone was returned
See existing conversations that were synced with the linked computer
See WhatsApp contacts
Send WhatsApp messages as the couple

Police were unable to monitor WhatsApp voice calls or access other features on the phone, such as the camera, microphone, standard SMS messages, or apps outside WhatsApp. The legality of such methods has now been called into question by the German legal system.

Legal grey area

In January, Germany’s Federal Court of Justice ruled that secretly connecting to Telegram chats in this way amounted to a form of surveillance, rejecting an earlier interpretation of the law that the Customs Criminal Investigations was still referring to as late as February this year.

Check Also

Nightmare Eclipse

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called …