No, German Police Haven’t Broken WhatsApp or Signal Encryption — Here’s What They’re Actually Doing

Reports that German law enforcement agencies can “intercept WhatsApp, Signal and Telegram despite end-to-end encryption” have generated exactly the kind of headline that makes cryptographers reach for the nearest aspirin.

No, Germany has not cracked Signal.

No, WhatsApp’s end-to-end encryption has not suddenly become useless.

And there is no evidence in this story that Meta or Signal secretly handed the German government a universal encryption backdoor.

What German investigators have been using is simultaneously much simpler and, from a security perspective, much more interesting.

Instead of breaking the encryption, they can potentially turn a police-controlled computer into an authorized device belonging to the target’s messaging account.

The encryption continues working perfectly.

The problem is that the police computer has now become one of the endpoints allowed to decrypt the messages.

And according to documents published by German digital-rights outlet Netzpolitik, this is not merely theoretical.

What German authorities are actually doing

On September 2, 2026, Netzpolitik published an internal document from Germany’s Customs Criminal Police Office (Zollkriminalamt, or ZKA) describing what the agency calls “Messengerüberwachung” — messenger surveillance.

According to the document, the technique had been tested since the end of 2023 and was permanently introduced into the customs investigative structure in August 2025 after authorities said it had produced significant results in investigations into serious and organized crime.

Crucially, the document describes a method for recording data exchanged through instant messengers without infiltrating the target’s computer or smartphone with surveillance software.

That distinction matters.

Traditional “source telecommunications surveillance” — usually called Quellen-TKÜ in Germany — can involve compromising the endpoint so communications can be captured before encryption or after decryption.

Messengerüberwachung can take another route entirely.

Applications including WhatsApp and Signal already allow users to connect additional devices.

WhatsApp has WhatsApp Web and its multi-device architecture.

Signal has linked devices and Signal Desktop.

If investigators can successfully authorize their own machine as one of those devices, the messaging service itself begins delivering messages to it.

There is no need to calculate an encryption key.

There is no need to intercept encrypted packets and decrypt them.

The police-controlled machine has effectively become an authorized endpoint.

End-to-end encryption hasn’t failed

This is the most important point.

End-to-end encryption protects information between endpoints.

Imagine Alice sends a message to Bob.

Normally:

Alice → encrypted communication → Bob

An attacker sitting somewhere between them should not be able to read the message.

But modern messaging accounts often have several legitimate endpoints.

Bob might have:

  • his smartphone;
  • his laptop;
  • WhatsApp Web;
  • another linked computer.

WhatsApp’s multi-device architecture actually creates cryptographic sessions for the different devices associated with an account. Meta explains that each companion device has its own identity key and that messages are encrypted separately for the recipient’s devices.

If another device is successfully added to Bob’s account, the situation effectively becomes:

Alice → encrypted communication → Bob’s phone

and

Alice → encrypted communication → Bob’s authorized computer

and potentially:

Alice → encrypted communication → police-controlled linked device

The third connection can still be end-to-end encrypted.

The encryption is doing exactly what it was designed to do: delivering the encrypted message to an endpoint that the account has told the system to trust.

The security failure therefore occurs before the encryption layer becomes relevant: during endpoint authorization.

We have already seen this happen

This isn’t merely a hypothetical attack.

Netzpolitik describes a remarkable German investigation dating back to January 2020.

Two witnesses voluntarily handed their smartphones to police officers for a short period so investigators could inspect messages exchanged with their daughter.

But during that access, according to the case record, investigators secretly activated WhatsApp Web using a BKA system.

The police computer consequently became capable of accessing WhatsApp communications.

The important technical detail is that investigators did not install a Trojan on the phones.

They used WhatsApp’s own device-linking functionality.

The case eventually became particularly important because Germany’s Federal Court of Justice (Bundesgerichtshof) had to consider the legal nature of this kind of surveillance.

In a January 2026 ruling involving Telegram surveillance, the court rejected the idea that secretly connecting to a messenger account in this manner could simply be treated as ordinary telecommunications interception. According to the decision as reported and documented by Netzpolitik, such monitoring without involvement of the provider or user constitutes a form of source telecommunications surveillance.

That distinction has major consequences for what investigators are legally permitted to collect.

What about Signal?

Signal deserves special attention because it is frequently described as having been “broken” whenever authorities manage to obtain Signal messages.

That conclusion is wrong.

Signal explicitly supports linked devices.

Its current documentation explains that a desktop, tablet or other supported device can be linked to the primary Signal device. During setup, the primary device authorizes the new endpoint by scanning its QR code.

Signal also requires device authentication during this process — biometrics or the device’s unlock code — before opening the linking interface.

Even more importantly, Signal now allows the user to choose whether to transfer message history when adding the linked device. Signal says chats and up to the last 45 days of media can be synchronized during the initial setup.

Once authorized, the linked device independently participates in Signal communications.

So again:

Signal’s cryptography does not need to be broken.

The attacker needs to convince the account that another device belongs to the user.

Phishing can accomplish something similar

Physical possession of the phone isn’t necessarily the only path.

German authorities themselves have warned about attacks designed to trick users into authorizing additional Signal devices.

Netzpolitik cites warnings from Germany’s Federal Office for Information Security (BSI) and domestic intelligence authorities concerning phishing operations targeting messenger accounts.

This is conceptually similar to many account-takeover scams.

The attacker does not attack AES, the Signal Protocol or another cryptographic primitive.

They attack the authorization process surrounding the cryptography.

It is an important security lesson:

Strong cryptography cannot protect an endpoint that the user — knowingly or unknowingly — has authorized.

But Telegram is different

This is where many reports become technically inaccurate.

It is misleading to describe Telegram, WhatsApp and Signal as three equivalent end-to-end encrypted messengers.

They aren’t.

Telegram itself states that its normal Cloud Chats use client-server encryption, with messages stored in the Telegram Cloud.

Only Secret Chats use end-to-end encryption.

Secret Chats are also device-specific and aren’t synchronized through Telegram’s cloud to additional devices.

Therefore, a story claiming that German authorities somehow “defeated Telegram end-to-end encryption” simply because they obtained access to a Telegram account would be technically incorrect without knowing what kind of conversation was involved.

Can investigators obtain old messages too?

Potentially, and this is where the story becomes even more controversial.

A newly authorized messaging client isn’t necessarily restricted to messages received after surveillance begins.

Modern multi-device systems synchronize parts of the account state and conversation history.

Meta’s technical explanation of WhatsApp multi-device, for example, describes how the primary device can encrypt a bundle containing messages from recent chats and transfer it to a newly linked companion device.

Signal currently allows message-history synchronization during linked-device setup and explicitly documents synchronization of recent media.

This creates a serious legal distinction between:

intercepting future communications

and

searching an existing archive of communications.

Technically, consumer messaging applications don’t necessarily care about that distinction.

Criminal-procedure law certainly does.

The forensic problem nobody should ignore

There is another issue that may be even more interesting than the encryption debate.

WhatsApp Web and Signal Desktop weren’t designed as forensic acquisition tools.

They’re messaging clients.

An authorized client isn’t necessarily read-only.

It may be capable of sending messages, changing account state or otherwise interacting with the account.

That produces an uncomfortable forensic question:

How do investigators prove that evidence collected through such a system hasn’t been altered by the acquisition mechanism itself?

German law contains explicit technical safeguards for source telecommunications surveillance.

Section 100a of Germany’s Code of Criminal Procedure requires, among other things, technical measures ensuring that only permitted communications are collected and that changes made to the target information system are limited to what is indispensable for collecting the data.

It also requires logging information about the technical means used and the changes performed.

A normal messaging client wasn’t built around those constraints.

This is precisely why the German debate isn’t simply about privacy.

It is also about evidentiary integrity.

If an investigative endpoint is technically capable of sending messages as the suspect, deleting or modifying information, accessing contacts or collecting communications outside the authorized period, authorities need mechanisms capable of demonstrating exactly what the system did — and what it did not do.

German courts are already questioning the method

This is perhaps the most important part of the entire story.

The controversy isn’t merely coming from privacy activists arguing that the technique feels invasive.

There is a genuine legal dispute over whether existing German surveillance laws adequately authorize this particular implementation.

Netzpolitik reports that the Zollkriminalamt’s February 2026 internal document still relied on an earlier interpretation of Section 100a StPO.

But Germany’s Federal Court of Justice had issued a decision on January 20, 2026 rejecting that interpretation in the context of secretly connecting to Telegram chats.

Netzpolitik cites IT criminal-law professor Christian Rückert as arguing that using ordinary provider applications in this manner is extremely problematic because investigators cannot necessarily technically guarantee that only legally authorized information will be collected.

That is a much more consequential debate than “Germany broke WhatsApp.”

FACT CHECK: what is true and what isn’t?

“German police broke WhatsApp encryption.” — FALSE

There is no evidence in this case that WhatsApp’s end-to-end encryption was cryptographically defeated.

“German police broke Signal.” — FALSE

The reported technique exploits account/device authorization rather than breaking the Signal Protocol.

“WhatsApp or Signal gave Germany a secret backdoor.” — NO EVIDENCE

The technique described by the German documents relies on functionality available in ordinary messenger clients.

“End-to-end encryption is therefore useless.” — FALSE

E2EE continues protecting communications against interception between authorized endpoints. It cannot protect against an attacker becoming an authorized endpoint.

“Police necessarily need spyware installed on the target’s smartphone.” — FALSE

The entire point of this technique is that surveillance may be possible without installing a traditional state Trojan.

“Physical access to an unlocked or unlockable device can be extremely dangerous.” — TRUE

Temporary access may provide opportunities to authorize additional devices, depending on the messenger and the security configuration of the phone.

“Telegram works exactly like Signal and WhatsApp.” — FALSE

Telegram’s ordinary Cloud Chats are not end-to-end encrypted. Only Secret Chats provide E2EE, and those chats are device-specific.

“A linked device may expose more than future messages.” — TRUE

Depending on the application and configuration, synchronization can expose existing conversation history and other account data.

The real weakness isn’t encryption. It’s endpoint trust.

The German case illustrates one of the oldest principles in information security:

Encryption protects data in transit. It does not magically make trusted endpoints trustworthy.

An attacker doesn’t necessarily need to break the strongest lock in the building if they can convince the security system to issue them another key.

That is effectively what happens when an unauthorized device becomes an authorized companion device.

And it explains why sensational claims that “Germany has cracked WhatsApp and Signal” completely miss the technical significance of this story.

The cryptography survived.

The trust model was attacked.

What users should actually do

The practical response isn’t to abandon encrypted messengers.

It’s to protect their endpoints.

Users should periodically inspect the devices and active sessions associated with their messaging accounts and immediately remove anything they don’t recognize.

Signal explicitly provides a Linked Devices section for this purpose. WhatsApp similarly allows users to review linked devices, while Telegram provides controls for active sessions.

Also treat unexpected QR codes, device-link requests and authentication prompts with the same suspicion you would apply to a password-reset email.

Because in a multi-device messaging architecture, authorizing the wrong device can be almost as damaging as handing someone your unlocked phone.

And that is the real lesson from Germany’s messenger-surveillance controversy:

Nobody needed to break the encryption. They just needed to get themselves invited inside it.

Visited 7 times, 2 visit(s) today
share this recipe:
Facebook
X
WhatsApp
Telegram
Email
Reddit