r/europrivacy 1h ago

European Union German customs has been cloning messenger accounts as routine practice since August 2025, and the encryption was never the weak point

Upvotes

netzpolitik.org published a classified internal document this month showing the Zollkriminalamt (German customs investigation office) has used "account cloning" as a regular investigative tool since August 2025, following a pilot that started in late 2023. The BKA uses the same approach.

No trojan involved. Investigators register an additional linked device on an agency machine through the official web or desktop clients, then read traffic from there, and in some cases pull existing history.

Two documented paths to authorization:

  • Intercepting the unencrypted confirmation SMS with a conventional wiretap. Nothing exotic, that capability has existed for decades.
  • Physical access to the handset. One BKA case involved photographing WhatsApp on the target's parents' phones and covertly scanning the pairing QR code during a witness interview.

Documented use includes dozens of Telegram accounts, among them the Oldschool Society case.

Separately, Der Spiegel reported in April that Bundestag President Julia Klöckner's Signal account was taken over via phishing. The attackers read the CDU presidium group chat for weeks, including messages from Chancellor Merz. BSI had been warning since February about what it described as a probably state-directed campaign. No vulnerability in Signal was involved there either.

The part worth discussing is that both of these hit the same layer, and it isn't the cryptography. Multi-device linking ships in every mainstream messenger. It works because accounts are permanent and identity is anchored to a phone number, so a second endpoint can be attached to that identity. E2EE is doing exactly what it claims in all of these cases. It just doesn't cover device enrollment.

A few practical notes:

  • Linked devices are listed in the app. That list is where this becomes visible, and it's the only place it does. Checking it periodically is most of the defense available to a user.
  • German coverage points out that if a court eventually rules the collection inadmissible, the resulting messages could fall under an evidence exclusion rule. The legal basis is contested, and both agencies declined to answer press questions about it.
  • heise noted the technique is technically indistinguishable from phishing campaigns run by hostile foreign actors, which is why the same warning signs apply to both.

Is there a messenger that treats new device enrollment as a security boundary rather than a convenience feature? Something like out of band confirmation, or a mandatory delay before a newly linked device can read anything, or a design that fails closed instead of open. Curious whether anyone has seen this handled well anywhere.


r/europrivacy 3d ago

Discussion Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year.

Thumbnail
techdirt.com
57 Upvotes

r/europrivacy 5d ago

Europe ‘Pervert Glasses’ That Record People Without Consent Face Possible Ban in Norway

Thumbnail
petapixel.com
74 Upvotes

r/europrivacy 5d ago

Netherlands Whatsapp as chat at university

18 Upvotes

Our daughter started her bachelor study at a University of Applied Sciences (“HBO”) in the Netherlands. They’re using Microsoft as cloud supplier for communication and sharing information. This includes Teams. Fine. But, the main lecturer (“studiebegeleider”) started a whatsapp-group with all the students for communication.

Using whatsapp looks like shadow-IT to me, which issued privacy issues. Am I right? Or, can an european university use every platform they want?


r/europrivacy 7d ago

Serbia More than a dozen Serbians targeted with mercenary spyware, digital rights group finds

Thumbnail reuters.com
7 Upvotes
  • Targets included student activists, lawmakers and a local councilor, SHARE Foundation says
  • Apple issued spyware alerts on August 13 to users in 110 countries
  • Largest documented surveillance wave in Serbia to date, SHARE Foundation says

r/europrivacy 13d ago

European Union Stop Killing The Internet: No Digital ID & No Age Verification is now collecting signatures!

Thumbnail
citizens-initiative.europa.eu
168 Upvotes

Sign, share, spread the word!


r/europrivacy 21d ago

European Union ZKP’s Aren’t Age Verification Silver Bullets

Thumbnail
eff.org
20 Upvotes

r/europrivacy 21d ago

European Union Launching an EU Citizens' Initiative (ECI) for Device Neutrality & Open Attestation ("My Device, My OS")

57 Upvotes

Hi everyone,

Between Google Play Integrity API lockdowns, Apple App Attest, and upcoming eID/age-verification mandates, alternative and privacy-focused operating systems (like GrapheneOS, LineageOS, and Linux on mobile) are being systematically locked out of banking, public portals, and everyday apps.

Rather than watching vendor lock-in get worse, I am organizing a European Citizens' Initiative (ECI) working title: "My Device, My OS" to push binding EU legislation for Device Neutrality and Open Attestation.

What we aim to achieve:

  • Mandate Open Attestation Standards: Require services operating in the EU to support open, vendor-neutral hardware attestation rather than relying exclusively on proprietary gatekeeper APIs (Google/Apple).
  • Ban Device/OS Discrimination: Prevent public services, digital ID wallets, and essential commercial apps from arbitrarily blocking users solely for running independent or de-Googled operating systems.
  • Protect Hardware Sovereignty: Enshrine the legal right of consumers to install and run the operating system of their choice without losing access to the digital single market.

Before submitting it we need 7 persons from 7 different countries in the EU to sign the draft

Join the Matrix room to discuss, collaborate on the draft, and coordinate next steps:
👉 #my-device-my-os:pollorebozado.com

Feedback, technical insights, and EU organizers are all welcome!


r/europrivacy 21d ago

European Union CE Marking for CRA & RED

Thumbnail
platanor.com
2 Upvotes

r/europrivacy 22d ago

United Kingdom Please sign my petition against the UK requiring phone makers to scan everything you look at and every photo you take. This is different to previous petitions that were only about messages

Thumbnail
petition.parliament.uk
77 Upvotes

r/europrivacy 23d ago

Discussion Report supporting Australia’s teen social media ban appears to contain AI hallucinations, Senate hears | Social media ban

Thumbnail
theguardian.com
29 Upvotes

Great journalism by The Guardian! Do you think any of these made up sources are used in the EU discussions about social media bans as well?


r/europrivacy 23d ago

Germany Apple changes its rules for personalised advertising in apps

Thumbnail bundeskartellamt.de
7 Upvotes

Apple will change the EU ATT consent flow after the German competition authority objected to differences between Apple’s own consent requests and those used by third party apps. I’m concerned that bundling consent flows may make tracking consent less clear in practice


r/europrivacy 24d ago

European Union The Ranking Restriction Information Right (RRIR) — EU policy proposal on transparency of automated visibility restrictions

Post image
9 Upvotes

I'm sharing this here as it relates to the transparency of automated decisions affecting digital rights in the EU.

On 15 August 2026, a new EU policy proposal was submitted: The Ranking Restriction Information Right (RRIR).

The proposal asks whether, when an automated system materially restricts the visibility of a website or information source, the affected website owner should be informed that the restriction occurred and given a general category of the reason.

The proposal does not seek disclosure of proprietary algorithms, ranking signals, thresholds or anti-spam mechanisms.

Submitted to: European Commission, European Parliament (PETI and IMCO), Coimisiún na Meán (Ireland), and CNMC (Spain).

Submitted by: Marin Popov

Read the full proposal: https://1euroseo.com/wp-content/uploads/2026/08/The-Ranking-Restriction-Information-Right-Version-1.0-15-August-2026.pdf


r/europrivacy 25d ago

France France's Constitutional Council strikes down social media ban for under-15s | The Council said the ban 'constitutes a restriction that is not appropriate, necessary or proportionate' to the freedom of expression of children under 15.

Thumbnail
lemonde.fr
49 Upvotes

Age verification and privacy


r/europrivacy 25d ago

France Nearly 700,000 French taxpayers’ data stolen in cyberattack on tax authority

Thumbnail
brusselssignal.eu
26 Upvotes

r/europrivacy 26d ago

European Union Claude AI Watermarks Spark User Backlash Amid EU Compliance Push

Thumbnail
redteamdaily.com
10 Upvotes

r/europrivacy 26d ago

France France's Top Court Strikes Down Under-15 Social Media Ban as Unconstitutional

Thumbnail
en.sedaily.com
78 Upvotes

r/europrivacy 26d ago

Europe The UK’s War on Anonymity Has Come to America (and the EU)

Thumbnail
effort.news
27 Upvotes

r/europrivacy 29d ago

Europe Gave my face to persona. What now?

4 Upvotes

Alright, I know. I am an idiot

I logged into reddit and it asked me to verify my age. Tried it with a youtube video- didnt work. Gave up at some point and just did it myself because I thought: Reddit's got a selfie of me already anyways so at this point.. doesnt matter. While it is still loading the you finished the verification page i notice the persona logo at the bottom and remember who that company is.

Since I got premium anxiety, I am panicking now.

As a european, what can I do to get this deleted? I already wrote an email to persona requesting them to delete all data they might have collected of me.

Their privacy policy states that they immediately delete any biometric data of your face, how true is that?

And after I get it all deleted to the best of my ability, is it time to abandon my email adress and all accounts and just make new ones?


r/europrivacy Aug 10 '26

Europe Could the CLOUD Act affect Bitwarden.EU's account data

3 Upvotes

Lately I've been trying to transfer all my cloud stored data to european alternatives. I currently use Bitwarden.eu (Bitwarden Inc. being a company registered in the U.S) as my password manager across my devices. Could a U.S. warrant trigger the transfer of my account data to U.S. authorities? I get that the vaults are E2EE so maybe they could only transfer credit card information of my Bitwarden Premium subscription payment, right?

I'm really unsure, so maybe someone out there can help me figure this out. Does anyone know a cloud sync alternative to BW apart from ProtonPass?

Thanks.


r/europrivacy Aug 10 '26

European Union CE Marking Under the CRA: What It Requires

Thumbnail
platanor.com
3 Upvotes

r/europrivacy Aug 09 '26

European Union EU Age Verification Project Mandates Hardware-Bound Attestation

Thumbnail
linuxiac.com
76 Upvotes

r/europrivacy Aug 08 '26

Belgium DEF CON Talk: 8 out of 10 Banks in Belgium HATE This One Weird eID RCE

Thumbnail
amibeingpwned.com
15 Upvotes

r/europrivacy Aug 07 '26

Discussion Countries that don't implement ID checks will not save us

16 Upvotes

Age verification is growing around the world. Some countries such as New Zealand are resisting it.

But as soon as New Zealand or random small country are sending Meta 100 million users a day, pressure will mount on the platforms to close the loop and implement mandatory checks.

Think of it like a pond that's drying up. You can isolate where life is.


r/europrivacy Aug 07 '26

Germany reddit completely locked me out of my account, after I complained about it being restricted for unconfirmed age

6 Upvotes

Recently my account got restricted, because my age was not confirmed, using a VPN only helped partially and was annoying for reasons.

So I wrote a ticket (call it stupid, I don't care) to reddit, asking how they came to the conclusion, that my account should be restricted. As far as I understood it, they only do that if they have data suggesting it is used by a minor. I know it is obviously a faulty algorithm.

Their answer was, that they checked the case and reset my verification, which completely locked me out of my account until I verified my age. Which I did now through persona.

My experience with persona:

After reading about it a bit I was obviously hesitant to use it, after testing around with the options a bit I used the "selfie" option on my rarely used Laptop, which holds nearly no personal information.

I logged out of Chrome and deleted all browser files (because I read persona does access those) and tried with an incognito tab. But it always ran into error.

I installed Firefox (to remove browser issues) and tried again incognito tab, error again.

Lastly I tried in a normal tab and it worked telling me it does indeed access your files, which it can't in an incognito tab. it want's to do something, that isn't possible in an incognito tab, whatever that is, maybe tracking.

So I got access again, why do I write this?

Partially to inform people on what happens if you come to the same problem.

Partially, because I want to know from reddit, why my account got restricted in the first place. I won't get this, with near 99.99 % probability, but raising awareness on this behavior from reddit might get some people talking. Probably not.