TL;DR: Germany's Zollkriminalamt (ZKA, the customs investigation bureau) has been running "messenger surveillance" against criminal suspects since late 2023. The mechanism is what netzpolitik.org reporter Andre Meister calls Account-Cloning: police pair a second device to a suspect's WhatsApp, Signal, Telegram, or Threema account using the same desktop and web clients ordinary people use. End-to-end encryption stays intact. The second device just gets every message the suspect sends and receives, including up to 45 days of past Signal messages. A February 20, 2026 internal ZKA order, classified Verschlusssache, made the technique a routine investigative tool. The technique was confirmed by a leaked order, a 2020 family-law case in which officers activated WhatsApp Web on a witness's phone during a "voluntary" visit, a 2022 Lower Saxony Telegram surveillance, and a BGH ruling on January 20, 2026 that reclassified the practice as source telecommunications interception (Quellen-TKÜ) [1][2][3].

The Mechanism: A Second Device Paired to Your Account

The way Signal, WhatsApp, Telegram, and Threema all add a laptop or desktop client is the same: scan a QR code shown on the new device with the phone that already holds the account. Once scanned, the new device is a fully authenticated endpoint. New messages are pushed to it. Past messages are typically cached on it. The service runs end-to-end encryption between endpoints. Adding a second endpoint does not break that promise; it just adds another reader.

That is the surveillance technique the ZKA has been using. Andre Meister reported in netzpolitik.org on September 2, 2026 that the ZKA's internal term for the practice is "Messengerüberwachung," abbreviated MÜ, and that the bureau has used it as an investigative tool since late 2023 and made it permanently available to Zoll investigation units on August 1, 2025. The technique is documented in a February 20, 2026 internal order Meister obtained and described as classified "Verschlusssache - nur für den Dienstgebrauch" (restricted use, intended for official use only) [1].

The BKA, Germany's federal criminal police, has used the same technique in dozens of cases including the prosecution of the Oldschool Society neo-Nazi group, per a Welt am Sonntag report linked in Meister's piece [1]. The technique is therefore not a ZKA curiosity. It is a tool shared across German federal law enforcement.

How Police Get the Second Device On

The hard part of the technique is not running a second WhatsApp or Signal client. It is getting the verification that links that second client to the user's account. Bruce Schneier summarized the three routes in a September 29, 2026 post on Schneier on Security. Police, Schneier wrote, are able to gain access "either through physical access to someone's phone or by intercepting verification codes via a state-sanctioned phishing attack or intercepting SMS messages via telephone surveillance" [2].

The "Ehepaar P." case from January 12, 2020, described in the ZKA documents Meister published, is the textbook version of physical access. Officers obtained a couple's phones "freiwillig für einen kurzen Zeitraum," or "voluntarily for a short period," while visiting them as witnesses in a case about their daughter's messages. During that window, officers covertly activated WhatsApp Web via the BKA's web client [1]. The "voluntary" visit was the pretext. The pairing was the point.

The March 30, 2022 Lower Saxony Telegram case shows the alternative path. Officers connected to a doping dealer's Telegram account at night. According to the case file cited by netzpolitik, the suspect noticed the link was active and cut it a few hours later [1]. The technique works. It just works quietly only when the suspect does not check the linked-devices list on their phone.

What the Second Device Receives

A 2026 joint cybersecurity advisory from BSI, the federal cybersecurity agency, and BfV, the domestic intelligence service, describes what a successful Signal account takeover yields. The advisory is dated February 2026 and is linked in Meister's article. Per the advisory, "Die Angreifer ... bekommen zusätzlichen Zugriff auf die Nachrichteninhalte der letzten 45 Tage." Some configurations also let the second device send messages in the target's name: "im Namen der Zielperson Nachrichten verschicken" [1].

Those two properties matter. Past-message access up to 45 days back turns a current surveillance operation into a forensic one: even if the account is compromised for a single evening, the police-controlled client pulls a month and a half of prior conversation. And the ability to send messages in the suspect's name turns the technique into an influence-pursuit tool, not just a surveillance one.

Signal's own linked-device surface, the Settings → Linked devices menu on Android and iOS, is what the BSI warning recommends users check. WhatsApp, Telegram, and Threema expose the same list under similar names [1]. Schneier summarized the engineering request: "What we want is a feature that displays connected devices, so users could notice if a new device gets connected to their account" [2]. The feature exists. The notification that fires when a new device is added is what users actually miss.

What to Watch

Signal's linked-device notification. Schneier's September 29 column treats the existing settings menu as the practical defense, and points out the user-visible gap is the alert a new pairing generates [2]. Watch whether Signal, WhatsApp, Telegram, or Threema change the alert UX so an unexpected pairing cannot happen without the user noticing.

The Rückert/§100b argument. The January 20, 2026 BGH ruling kept messenger interception in the §100a Quellen-TKÜ bucket. Watch for further appellate decisions that test the doctrinal limit, especially as stored-content yields become part of the prosecution's case [1].

Cross-border diffusion. The ZKA technique works because the linked-device surface is the same in every jurisdiction. Watch whether U.S., U.K., and EU agencies face their own disclosures on whether they are running account cloning against suspects in their jurisdictions.

Sources

  1. Andre Meister, netzpolitik.org: "Messenger-Überwachung: Immer mehr Polizei überwacht Messenger wie WhatsApp," September 2, 2026. https://netzpolitik.org/2026/messenger-ueberwachung-immer-mehr-polizei-ueberwacht-messenger-wie-whatsapp/
  2. Bruce Schneier, Schneier on Security: "Using Device Linking to Eavesdrop on WhatsApp and Signal," September 29, 2026. https://www.schneier.com/blog/archives/2026/09/using-device-linking-to-eavesdrop-on-whatsapp-and-signal.html
  3. International Cyber Digest: "German police read encrypted chats by adding themselves as a second device," September 12, 2026. https://www.internationalcyberdigest.com/german-police-read-encrypted-chats-by-adding-themselves-as-a-second-device/