The German customs authority, Zollkriminalamt, has been using a method to read messages from WhatsApp, Signal, and Telegram by connecting a computer to a target's account, according to an internal classified report obtained by Netzpolitik. This technique, which has been used since late 2023, involves scanning a QR code to link a computer to the target's account, similar to how WhatsApp Web or Signal Desktop work. This allows investigators to receive messages in real time without the need for spyware or other intrusive software.
For this method to work, the target must confirm the device link. This can be achieved by inviting individuals to act as witnesses and asking them to hand over their phones to take screenshots on unrelated topics, or through phishing campaigns that trick users into approving the connection. In the case of Telegram, connection codes can be obtained through phone interception. The technique has been used on dozens of accounts, including that of a drug trafficker from Lower Saxony, who only discovered the unauthorized access after it was too late—his messages from the past six months had already been copied.
Once the link is established, all message history is retrieved, and web clients usually receive the full archive of messages. Signal, for example, offers to transfer conversations and 45 days of media when linking devices. Officials from the Federal Office for the Protection of the Constitution (BfV) and the Federal Office for Information Security (BSI) have noted that targets often take time to realize their accounts have been accessed without permission. Additionally, German customs authorities have the ability to send messages on behalf of the target, which adds a layer of complexity to the situation.
The legality of this method was examined by the German Federal Court of Justice, which ruled that secretly connecting to an account constitutes source surveillance. According to the court, only messages received after a judge issues an order can be legally read. Messages received before the order are not admissible in court, as they lack the legal justification of a serious enough offense to warrant an online search. Professor Christian Rückert, a legal expert in computer crime, argues that the method is problematic because the apps allow authorities to send messages on behalf of the target, which goes beyond the legal requirement of merely retrieving messages.
Users are encouraged to regularly check the list of devices linked to their accounts and remove any unrecognized devices immediately. It is also recommended to enable two-step verification using an application-based two-factor authentication system, rather than relying on SMS codes, to enhance account security.
German Customs Use Linked Devices to Monitor Encrypted Messaging Apps
AI-rewritten from original reportingHow it works
surveillanceencryptionprivacywhatsappsignaltelegram
Original sources:
- 🇫🇷Korben



