WhatsApp and Telegram encryption is supposed to be a fortress. It is meant to keep anyone from reading along between sender and recipient. Germany’s Customs Criminal Investigation Office leaves the encryption intact and simply goes around it. Instead of attacking the code itself, it targets the part every person uses directly. A police computer is secretly linked to the account as another device, and from that moment on the service treats it as legitimate and sends the messages to it already decrypted. Our reporting is based on a classified internal directive in which the agency itself describes the method.
To link the device, all it takes is the account holder’s approval, a QR code, or a verification code. Approval directly inside the app can also work. Investigators can get that approval in several ways. Phones that have been seized or voluntarily handed over can provide it, and intercepted SMS verification codes can help. Even fake login pages may be used. The decisive breach is not a technical one. It comes down to who an account believes it can trust. Just how casually this can happen is shown by a case from 2020. A married couple handed their own phones to police so officers could take screenshots of messages from their daughter. The 2 were witnesses. Nobody had accused them of anything. While they were sitting at the police station, officers activated WhatsApp Web on an official computer, linked both accounts to it, and kept reading after the couple had gone home. In certain setups, a linked device can even send messages in the account holder’s name. German security agencies warn people about this exact kind of unauthorized device linking whenever criminals or foreign intelligence services are behind it. The only difference is who is doing it.
Once linked, the view can also reach backward. German authorities had reportedly warned that after a successful cloning of a Signal account, messages from the previous 45 days could become accessible. The Customs Criminal Investigation Office began testing the method at the end of 2023. Since August 1, 2025, it has been permanently available to customs investigators. According to the directive, the trials produced significant operational successes in cases involving serious and organized crime. At the same time, the process requires trained personnel and a great deal of working time, which means requests have to be prioritized. Every connection must reportedly be approved by agency leadership and prosecutors. The agency would not say how often it has already used the method, citing secrecy. Germany’s Interior Ministry said that even disclosing what surveillance capabilities federal agencies have could expose tactical weaknesses and endanger national security. So even the scale of the operation remains hidden, while what began as a trial has long since become a permanent tool.
The legal ground underneath all of this has become shakier. The directive relies on a 2020 court ruling that still treated the secret addition of another device much like ordinary telecommunications surveillance. In January 2026, Germany’s Federal Court of Justice drew the line more tightly. Secretly attaching to a Telegram account without the involvement of the provider or the user was a deeper intrusion and could only be permitted under stricter conditions. Legally, the practice has since been treated as source telecommunications surveillance, meaning direct access at the source itself, which goes further than simply listening in on an ongoing communication. Messages created before a judicial order may no longer be collected retroactively. Parliament has never passed a law specifically tailored to this practice.
The date of the directive makes the whole thing particularly uncomfortable. It is dated February 20, 2026, just weeks after the Federal Court of Justice narrowed the old interpretation, yet it still relies on it. An agency is continuing to work with a legal justification whose footing Germany’s highest criminal court had just weakened. Technically, the process looks almost boring, and that is exactly where the danger lies. The encryption remains intact because the message reaches the additional device already readable. To the people being monitored, the access looks like just another phone connected to their own account. On WhatsApp, the “Linked Devices” section shows all connected devices, and Signal provides a similar overview. Both services recommend immediately removing any device you do not recognize. Verification codes should never end up in someone else’s hands, and neither should QR codes. The security technology can work perfectly while access still succeeds at the weakest point, the account’s trust in what it thinks is one of its own devices.
That leaves Germany’s surveillance debate hanging on an unassuming list buried in the settings. A foreign computer can appear there, treated by the service as one of your own devices, while someone on the other end is reading along. The Customs Criminal Investigation Office calls the method a successful part of its work against serious crime, while the Federal Court of Justice now requires stricter standards for that exact kind of access. Between those 2 statements sits the question of how deeply the state should be allowed to reach into a private account when it no longer has to break down the door because it has simply registered itself as an authorized device.
Updates – Kaizen News Brief
Alle aktuellen ausgesuchten Tagesmeldungen findet ihr in den Kaizen Kurznachrichten.
To the Kaizen News Brief In English