Saturday , September 12 2026
German

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their encryption or installing spyware on their phones. New documents published by German digital rights outlet Netzpolitik show the country’s Customs Office began testing the technique, known as “messenger monitoring,” in late 2023.

Although the customs agency warned that details of the method should be handled with “extreme sensitivity” to avoid jeopardizing its use, the technique isn’t rocket science. Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers.

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account. Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them.

How police gain access to encrypted messages legally

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance.

In the case of Signal, German security authorities warn that someone who successfully links another device can gain access to messages from the previous 45 days.

For Telegram, Netzpolitik cites a case involving a suspected dope dealer in Lower Saxony. Police secretly connected to his Telegram account in March 2022. The suspect discovered the access a few hours later, but by this time, the police had already copied his message archive.

According to official papers seen by Netzpolitik ,these techniques became an official practice in August 2025, after officials said they had produced “significant investigative successes” in serious and organized crime cases.

However, Netzpolitik questions the legality of this method, the extent of its usage, and its choice of targets.

Federal police monitor innocent couple’s WhatsApp messages

Netzpolitik cites a 2020 court case involving a married couple, who were not suspects, to highlight how physical access was used to monitor the phones of innocent people.

The couple voluntarily handed their phones to German police while being questioned as witnesses about their daughter, allowing officers to inspect and photograph messages she had sent them.

While the police had the phones, officers secretly activated WhatsApp Web and connected the accounts to a computer operated by the Bundeskriminalamt , or Federal Criminal Police Office (BKA).

Once that connection was made, the police could potentially:

Read new WhatsApp messages after the phone was returned
See existing conversations that were synced with the linked computer
See WhatsApp contacts
Send WhatsApp messages as the couple

Police were unable to monitor WhatsApp voice calls or access other features on the phone, such as the camera, microphone, standard SMS messages, or apps outside WhatsApp. The legality of such methods has now been called into question by the German legal system.

Legal grey area

In January, Germany’s Federal Court of Justice ruled that secretly connecting to Telegram chats in this way amounted to a form of surveillance, rejecting an earlier interpretation of the law that the Customs Criminal Investigations was still referring to as late as February this year.

Check Also

SafeMind

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike …