ThreatPaper
Verified

Linking a device to a Signal account exposes the previous 45 days of messages

Assessment

The joint BSI and BfV warning of April 2026, issued about a "presumably state-controlled" phishing campaign that tricks users into scanning QR codes, states that attackers who link a device "gain additional access to the message contents of the last 45 days." Netzpolitik quotes the same passage. The warning concerns a hostile campaign rather than German police, but the mechanism, a linked device receiving synced history, is the same one the ZKA directive describes, which is why the figure matters for the legal analysis: a vendor client cannot be configured to receive nothing.

Where this claim appeared

BSI / Bundesamt für Verfassungsschutz via Winfuture · 2026-04-20

https://winfuture.de/news,158229.html

What “Verified” means

Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.

5 of 5 · rating scale

Assessed in

Messenger Monitoring: How German Police Read WhatsApp, Signal and Telegram Without a Trojan

Think this assessment is wrong? Report an error.