
German customs investigators have been reading WhatsApp, Signal, and Telegram messages since 1 August 2025 without breaking any encryption, using the messengers' own web and desktop clients. A classified Zollkriminalamt (ZKA) directive published by netzpolitik on 2 September 2026 shows the technique, called account cloning, moved from pilot project to permanent investigative tool after trials that began in late 2023.
The method adds a second authorised device to the target's account. WhatsApp, Telegram, and Threema offer web clients, and Signal offers a desktop app. Once the account approves the new device, the service treats the investigator's computer as a legitimate endpoint and delivers everything to it.
Investigators get that approval three ways: intercepting an unencrypted SMS confirmation code through a conventional phone tap, scanning a QR code while physically holding the phone, or phishing. Germany's Bundeskriminalamt (BKA) used the SMS route to reach Telegram accounts in dozens of cases.
A Witness Interview That Became Permanent Surveillance
On 12 January 2020, a married couple attended a police interview as witnesses and voluntarily handed over their phones so officers could photograph messages from their daughter. While holding the handsets, officers covertly activated WhatsApp Web through a page the BKA had put online, according to the investigating judge's decision. Both accounts were mirrored on a police computer. Neither witness was told.
How Much History a Linked Device Gets
The amount of past conversation a new device receives varies by service, and that is the legally decisive detail.
| Service | History exposed to a newly linked device |
|---|---|
| Up to one year of chat history, per WhatsApp's Help Centre | |
| Signal | The last 45 days of message content, per the BfV and BSI advisory of 6 February 2026 |
| Telegram | Full cloud chat history, as Telegram stores cloud chats server-side. Secret Chats do not sync |
The Court Has Already Rejected the Legal Basis
On 20 January 2026, Germany's Federal Court of Justice ruled in case 3 StR 495/25 that covertly linking to a messenger account is a source of telecommunications interception rather than ordinary interception. Source interception may only capture communication sent after a judge's order, and § 100a(5) StPO requires investigators to technically ensure that limit. Standard web clients synchronise the archive automatically.
Christian Rückert, chair for IT criminal law at the University of Bayreuth, argues in the Münchener Kommentar zur Strafprozessordnung that no provision covers the practice as carried out, because a linked client can also send messages in the account holder's name. The ZKA directive, dated 20 February 2026, still cites the superseded 2020 ruling.
The same feature was described very differently by other German agencies. On 6 February 2026, the BfV and BSI warned that a probable state-controlled actor was abusing messenger device-linking against politicians, diplomats, and journalists. Around 300 victims are known in Germany, including Bundestag President Julia Klöckner.
The ZKA told netzpolitik.org the details are classified. The BKA said it does not comment on IT surveillance. Users can audit their own accounts under Settings, Linked devices in WhatsApp and Signal, or Settings, Devices in Telegram, and log out of anything they do not recognise.