started · updated
German security agencies use account cloning to monitor encrypted messengers
German security authorities are utilizing methods to monitor encrypted messaging services like WhatsApp and Signal without traditional state Trojans. Investigations reveal that agencies use built-in features to link additional devices, such as WhatsApp Web, to a target's account. This technique, referred to as ‘account cloning’, was tested by the Customs Investigation Bureau (Zollkriminalamt) in late 2023 and became a permanent investigative tool in August 2025.
This practice creates a contradiction in security guidance, as the Federal Office for Information Security (BSI) and the Federal Office for the Protection of the Constitution (BfV) warn citizens against unauthorized device linking and phishing, even as law enforcement employs the same method. The legal implications of such surveillance were addressed by the Federal Court of Justice (BGH) in January 2026.
Separately, the BSI has issued warnings regarding the long-term viability of current encryption standards. Due to the potential for quantum computers to break classical public-key cryptography, such as RSA, the agency recommends that central encryption techniques be transitioned to quantum-secure methods by 2031. This is to mitigate the ‘harvest now, decrypt later’ risk, where attackers intercept and store encrypted data today to decrypt it once quantum technology matures.
Entities
Bundesamt für Sicherheit in der Informationstechnik · Bundesamt für Verfassungsschutz · Bundeskriminalamt · Zollkriminalamt