Back to Blog
Mobile & Messaging Security

Device Linking as Wiretap: German Customs Reads WhatsApp and Signal

German customs investigators are reportedly reading suspects' WhatsApp and Signal chats by linking a second device to the account. The encryption is never broken, because the linking feature delivers the messages to the new device by design.

PyramidLedger Research3 min read
Share

Key Takeaways

  • Authorities are reportedly reading messages by linking a second device to the target's account, not by breaking end-to-end encryption.
  • The method relies on the account holder approving a link, whether through physical access to the phone, a phished verification code, or an intercepted SMS code.
  • The Zollkriminalamt reportedly piloted the method from late 2023 and has had it permanently available to customs investigation units since August 2025.
  • Linked-device lists are a security control. Review them regularly, and treat any verification code you did not request as an attack.

What was reported

Schneier on Security highlights reporting by netzpolitik.org, which published a document from Germany's Zollkriminalamt (customs criminal office). According to that reporting, investigators use the companion-device features that messaging apps ship for ordinary users: WhatsApp Web, Signal Desktop, and the web clients offered by Telegram and Threema. They register a police-controlled computer as an additional device on the suspect's account. Messages are then delivered to that computer as they would be to a legitimate laptop, so there is no need to crack the encryption.

Per the reporting, the Zollkriminalamt tested the approach in a pilot project starting at the end of 2023. Since August 2025 it has been permanently available to customs investigation units. A professor of IT criminal law quoted in coverage considers the practice unlawful, and the legal questions are separate from the technical ones. We cover only the technical side here.

Why this is not an encryption break

End-to-end encryption protects messages in transit and at rest on the provider's servers. It cannot tell a legitimate endpoint from an illegitimate one that the account holder was tricked or coerced into authorising. A linked device is a fully trusted endpoint, so the attack moves from cryptography to enrollment.

The reporting describes three routes to enrolment. Each one targets the approval step rather than the cipher:

  • Physical access to an unlocked phone, so the link can be approved directly.
  • Verification-code interception through what coverage describes as state-sanctioned phishing.
  • SMS interception, where the code arrives by text and can be captured on the telephone network.

Why it matters beyond law enforcement

Nothing in this technique is exclusive to a state actor. Any adversary who can briefly hold an unlocked phone, or who can socially engineer a user into approving a link prompt, gets the same read access. Criminals and stalkers already abuse linked-device features this way. For security teams, the point is that a messaging account is only as strong as its enrolment flow and the device-management hygiene around it.

For high-risk staff such as executives, journalists, incident responders and anyone handling sensitive negotiations, a linked-device audit should be a routine control, not something done after a suspected compromise.

Practical mitigations

  1. 1Review Settings → Linked devices in WhatsApp and Signal (Telegram: Settings → Devices). Remove anything you do not recognise.
  2. 2Never approve a link prompt or share a verification code you did not initiate yourself.
  3. 3Prefer app-based or passkey-style verification over SMS wherever the app offers it, since SMS codes can be intercepted on the network.
  4. 4Keep phones locked with a short auto-lock, and do not hand over an unlocked device.
  5. 5Include messaging apps in mobile device management and security awareness programmes for high-risk roles.

Limits of what is known

This is reporting based on a leaked internal document and secondary coverage. We have not independently verified how often the method is used or against whom. The defensive advice holds regardless, because the enrolment weakness is a general property of the design.

Frequently Asked Questions

Does device linking break end-to-end encryption in WhatsApp or Signal?

No. The encryption is not defeated. The linked device becomes an authorised endpoint on the account, so messages are delivered to it as designed. The weakness is in how the link gets approved.

How can I tell whether someone has linked a device to my messaging account?

Open the linked-devices list in WhatsApp or Signal (Settings → Linked devices) or the devices list in Telegram (Settings → Devices). Log out any entry you do not recognise. Also treat any unexpected verification code or link prompt as a warning sign.

Who is at risk from this technique?

Anyone whose phone can be briefly accessed, or who can be tricked into approving a link or sharing a verification code. Executives, journalists and incident responders are especially exposed, because their messages are worth a targeted attempt.

Sources

  1. 1Using Device Linking to Eavesdrop on WhatsApp and Signal — Schneier on Security
  2. 2Messenger-Überwachung: Immer mehr Polizei überwacht Messenger wie WhatsApp — netzpolitik.org
  3. 3Surveillance without trojans: How authorities read WhatsApp and Signal — heise online
Share

Read next