German Police Are Using Linked Devices to Read Signal Messages Without Cracking the Encryption

German Police Are Using Linked Devices to Read Signal Messages Without Cracking the Encryption

A document by Netzpolitik reveals that German police are sneakily abusing the linked devices feature in messengers to access the messages of suspects using encrypted messengers like Signal without needing to crack the encryption.

German customs officials have been using the web client of different messengers like Telegram and WhatsApp and logging in with the suspect's phone number. The unencrypted SMS code that's sent for authentication can then be intercepted by law enforcement to log in to the account.

Sometimes authorities need physical access to log in, which is a slightly higher barrier. But once they're able to authenticate, they can have access to your messages as long as you don't notice their sessions logged in to your account.

The document states that the German customs agency has been testing messenger surveillance since the end of 2023, and it has led to success in criminal investigations.

This type of surveillance became an official, permanent strategy available to all agents since August 2025.

The messengers affected include WhatsApp, Telegram, Threema, and Signal. Earlier this year, a Signal phishing attack was carried out by what is believed to be a state actor trying to gain access to Signal accounts.

The attack asked for you to respond with your Signal SMS message, which was triggered by the attacker trying to log in with your phone number. If you text them the code, all your messages from then on are now monitored.

Signal is often touted as a highly secure messenger. Indeed, it boasts some of the most robust encryption messengers have to offer, and other messengers like WhatsApp even use the Signal protocol for their encryption.

But their reliance on SMS for account authentication is clearly a massive security issue.

Signal recently launched phone numberless accounts in beta on Android, allowing you to sign up without ever giving your number to Signal while paying a small one-time fee.

Your account will be protected by a new secure Account ID and Recovery key that you can save in your password manager, which you will need in order to log in. They also announced future support for passkeys.

Passkeys are phishing-resistant by design and not available outside of your password manager, so you can't be tricked into typing it in during a phishing attempt.

Telegram added passkey support in 2025, although you have to go out of your way to enable it.

WhatsApp now supports passkeys as well, so you can secure your account that way.

It's also a good idea to occasionally check your active sessions/devices in the settings in your messenger of choice and remove any devices you don't recognize.

Community Discussion