German law enforcement agencies have been monitoring end-to-end encrypted messaging services such as WhatsApp, Signal, and Telegram far more extensively and with greater ease than previously known, according to a classified document obtained by Netzpolitik.org. The document reveals that police and customs authorities can often access the entire communication history of suspects, and sometimes even unrelated third parties, without using advanced state-sponsored malware or infiltrating smartphones. This method, referred to as "account cloning," has become a standard investigative tool since August 2025, following a successful pilot program, as outlined in internal directives from the Customs Criminal Police Office (ZKA). The technique relies on standard features offered by messaging platforms, which allow users to synchronize their accounts across multiple devices via official web clients and desktop applications. Investigators from the customs service or the Federal Criminal Police Office (BKA) create a secondary account through a government computer, effectively mirroring the target's account. To gain authorization, they intercept unencrypted confirmation SMS messages through traditional phone surveillance or scan a QR code during interrogations, often unnoticed by witnesses. This approach mirrors tactics used by hostile cyber actors in phishing campaigns. A recent incident involving the hijacking of the Signal account of Bundestag President Julia Klöckner (CDU) sparked public concern, initially leading to speculation about a sophisticated hack. However, it was later revealed that Klöckner had fallen victim to a phishing message, allowing attackers to authorize a linked device and eavesdrop on parliamentary chat groups. Despite the apparent vulnerability of the multi-device architecture used by messaging apps, there exists a double standard in how this method is perceived. When foreign intelligence agencies exploit phishing links to obtain verification codes, official guidelines emphasize the need to carefully verify connected sessions. Yet, when domestic customs or the BKA employ the same tactic, it is considered a proven method. The enthusiasm within German authorities for cloning messenger accounts stems from the relatively low technical barriers compared to the error-prone state trojan. However, legal experts classify the method as unconstitutional. Authorities justify their actions based on outdated legal rulings, despite the Federal Court of Justice having clarified earlier this year that secretly accessing a messaging account constitutes a serious intrusion into an information technology system. Legally, this does not fall under simple telecommunications surveillance (TKÜ), but rather requires the highest level of judicial oversight. Christian Rückert, a criminal law expert from Bayreuth specializing in IT-related crimes, has criticized the use of regular provider tools by authorities in a commentary on the Criminal Procedure Code. He argues that classifying this form of surveillance as a source-based TKÜ fails due to legal constraints. According to Rückert, investigators are only permitted to record ongoing communications starting from the time of judicial approval, not past messages. This distinction raises concerns regarding the admissibility of evidence collected through such methods, given existing legal prohibitions against the use of unlawfully obtained data in court proceedings.
★
Mantengamos las noticias honestas.
ObjectiveNews se financia con los lectores y no tiene anuncios: te mostramos el sesgo en lugar de ocultarlo. Apoya el periodismo independiente por 4 €/mes.
Hazte suscriptor