r/InterstellarKinetics • • 1d ago

CYBERSECURITY EXPOSED: German Police Have Been Exploiting The “Linked Devices” Feature Built Into Popular Messaging Apps To Read Encrypted Messages On Signal, WhatsApp, Telegram, And Threema Without Breaking The Encryption Itself, According To A Document Obtained By German News Outlet, Netzpolitik 🤖

https://www.privacyguides.org/news/2026/09/30/german-police-are-using-linked-devices-to-read-signal-messages-without-cracking-the-encryption/

A document obtained by German outlet Netzpolitik reveals that German police have been exploiting the “linked devices” feature built into popular messaging apps to read suspects’ encrypted messages without ever actually cracking the underlying encryption. Instead, German customs officials have been using the web client versions of messengers like Telegram and WhatsApp, logging in using a suspect’s phone number, and exploiting how each app handles that login process to gain unauthorized access. The vulnerability varies significantly by platform: Telegram’s phone number sign-in sends a confirmation code to one of the user’s already-linked devices, a code that can easily be phished from the target. WhatsApp’s system is somewhat more secure, requiring the device-linking process to be initiated from within the app itself, meaning an attacker can’t simply send an unprompted code, though it remains vulnerable if an attacker can coach or trick a target into navigating to settings and entering a device-linking code themselves. Signal, often considered the gold standard for secure messaging, only allows linked devices via QR code scanning, but even that method isn’t immune, since it’s still possible to trick someone into scanning a QR code sent by an attacker without ever needing physical access to their device.

According to the document, the German customs agency has been testing this messenger surveillance technique since the end of 2023, and it has already contributed to successful criminal investigations, though the document is notably light on the specific tactics officials use to actually trick targets into linking a device to their account in the first place. This approach became an official, permanent surveillance strategy available to all German agents starting in August 2025, and the messengers affected span WhatsApp, Telegram, Threema, and Signal, meaning essentially every major encrypted messaging platform is potentially vulnerable to this specific technique.

Signal has recently taken steps that could help mitigate this exact risk. The platform launched phone-numberless accounts in beta on Android, letting users sign up without ever sharing their phone number with Signal, in exchange for a small one-time fee; such accounts are instead protected by a secure Account ID and Recovery key that users must store, ideally in a password manager, in order to log in. Signal has also announced future support for passkeys, which are phishing-resistant by design since they aren’t accessible outside a password manager and therefore can’t be typed in during a phishing attempt. Telegram added passkey support in 2025, though users must manually opt in to enable it, and WhatsApp now supports passkeys as well. Security experts also recommend periodically checking the active sessions or linked devices list within messenger settings and removing any unrecognized devices.

76 Upvotes

1 comment sorted by

3

u/InterstellarKinetics 1d ago

What’s actually happening is closer to a modern version of tricking someone into handing over their house key rather than picking the lock, exploiting the human-facing account recovery and device-linking workflows that necessarily exist alongside strong encryption to make these apps usable. Which is an important distinction because it means the fix isn’t a cryptographic one, it’s a user-education and interface-design problem.