German investigators found a clever way around encrypted chat apps. They do not break WhatsApp, Telegram, or Signal’s security. Instead, they connect a web or desktop version of the app to a suspect’s account. The app then treats the police computer like a second phone the suspect owns. This lets officers read messages as they arrive.
A report from Netzpolitik uncovered the practice. The outlet found that Germany’s federal police force, known as the BKA, has used this trick for years. Now legal experts are asking hard questions about where the line sits.
How police link into encrypted apps
Encryption normally blocks outsiders from reading private chats. Only the sender and the receiver hold the keys. That should stop police from listening in, even with a warrant. But messaging apps also let one account run on several devices at once.
A phone, a laptop, and a tablet can all show the same chat thread. Investigators found a gap in that setup. If they link their own computer to a suspect’s account, the account treats them as trusted. No password gets cracked. No code gets broken. The officer’s screen simply mirrors the suspect’s messages, one bubble at a time.
According to Netzpolitik’s findings, the method works because messaging platforms build in multi-device support by design. Police use that built-in feature against the very people it was meant to serve. The tactic avoids the technical fight altogether. Instead, it walks straight through a door the app has already left open.
Real cases show how far the tactic goes
The Netzpolitik investigation points to two clear examples. In 2020, police got physical access to a suspect’s phone during an operation. They opened WhatsApp Web using the phone’s QR code scanner. That single scan gave them lasting access to the account’s chats. Reports suggest the suspect never fully agreed to this step, raising early doubts about consent.
A second case in 2022 went even further. The BKA linked itself to a Telegram account under investigation. Once connected, officers pulled down four months of past conversations in one sweep. That went beyond a normal wiretap, which usually only catches messages sent after a warrant starts.
Germany’s Federal Court of Justice later reviewed the case. The court struck down part of the ruling. Judges found that the law only allows police to collect new messages after a court grants approval. Old chat history, stored before the warrant existed, falls outside that permission. In short, the court said reading someone’s past belongs to a different legal category than watching their future.
That ruling matters because it draws a line most people would expect already existed. A warrant to watch someone going forward should not double as a free pass into their entire message archive. Yet the tools police use do not naturally respect that line. Once an account gets linked, every stored message becomes visible, old and new alike.
A June 2026 U.S. Supreme Court ruling in Chatrie v. United States held that police generally need a warrant to access Google Location History. The decision extended privacy protections for location data stored by third-party companies.
Customs joins in, and legal questions remain
Germany’s customs agency, called the ZKA, started using the same method on a permanent basis in August 2025. The agency says the goal is to fight organized crime groups that rely on encrypted apps to plan and communicate. So far, the ZKA has not shared numbers showing how well the approach actually works. That leaves outside observers unable to judge whether the tactic catches real criminals or mostly sweeps up ordinary chat history.
The bigger legal problem has not gone away. Once police link a device to an account, that link can pull in years of stored contacts and conversations, not just what happens after a warrant begins. Courts have only started to define where those limits sit, and the 2022 Telegram ruling suggests judges are not fully comfortable with how wide the net currently reaches. Privacy advocates argue that this kind of access needs clearer rules written into law, rather than being decided case by case after the fact.
It is worth stressing what this method is not. Police have not found a way to crack WhatsApp, Telegram, or Signal’s encryption. The math behind these apps remains intact. What investigators found instead is a workaround built into how multi-device support functions.
That distinction matters for anyone weighing how safe their messages really are. The content in transit stays scrambled and unreadable to outsiders. But if someone can quietly attach a second screen to your account, encryption alone will not stop them from reading everything that appears there.
For now, the debate sits between two German institutions. Police and customs officials defend the tactic as a needed tool against serious crime. Courts, meanwhile, are signaling that the tool cannot be used however investigators please, especially when it comes to digging through months of history that predates any warrant. How that tension resolves will likely shape how encrypted apps get treated by law enforcement well beyond Germany’s borders.