September 7, 2026, 4:03 pm | Read time: 3 minutes
Many people use messengers like WhatsApp or Signal for private messages, photos, or voice messages. Many rely on the services’ end-to-end encryption, which is supposed to prevent unauthorized parties from reading messages. However, internal documents from the Customs Criminal Office now show that investigators can still access messenger communications under certain conditions.
According to the tech magazine “Netzpolitik,” the agency has been testing the so-called messenger surveillance since the end of 2023. As of August 1, 2025, the method was permanently implemented and is available to the customs investigation units.
How Investigators Access the Messages
For surveillance, investigators do not need to overcome the encryption. Instead, they use existing web or desktop access to the respective messengers. This way, they set up an additional access to an existing account.
For WhatsApp, this can be done, for example, by confirming a QR code with the smartphone. Some messengers send confirmation codes via SMS, which can be intercepted as part of phone surveillance. In other cases, investigators need direct access to the affected person’s smartphone.
Once the additional access is set up, new messages can be read in plain text. Depending on the messenger, older chat histories are also transferred to the linked device. The end-to-end encryption remains intact. The messenger recognizes the additional device as an authorized account access.
New Dispute Over Internet Surveillance Ignites
Social Media Use to Require Real Names?
Federal Court of Justice Sees Stricter Requirements
Legally, the method is controversial. The Federal Court of Justice decided on January 20, 2026, in a case concerning Telegram, that such covert access is not to be classified as normal telecommunications surveillance. Instead, the court views it as a so-called source telecommunications surveillance (Quellen-TKÜ).
Also interesting: One billion users already protect WhatsApp with this feature
In this process, investigators do not intercept the encrypted transmission itself but instead target the device or the messenger account of the target person. This form of surveillance is subject to stricter legal requirements. Following the decision, it must be technically ensured that only legally permissible data is captured.
Provider Tools Under Criticism
According to the Federal Court of Justice, the usual web and desktop access do not automatically meet this requirement. Through such connections, older messages or contact lists can also be transferred. Additionally, it would be technically possible to send messages in the name of the monitored person.
Bayreuth IT criminal law expert Prof. Dr. Christian Rückert therefore considers the use of such provider tools to be inadmissible. Another particularly sensitive point: As recently as February 20, 2026, the Customs Criminal Office referred to a decision by a BGH investigating judge from 2020. However, the Federal Court of Justice had explicitly decided a month earlier that this legal opinion should not be followed. How often the method has been used so far is unknown.