Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Law Enforcement Exploits Device Linking to Eavesdrop on WhatsApp and Signal

WhatsApp Web and Signal Desktop allow account linking via a verification code. German authorities have shown that, by obtaining that code through phishing or SMS interception, they can attach a police‑controlled computer and read messages without breaking encryption. This highlights the need for stronger device‑access controls and continuous monitoring for compliance readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 schneier.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
schneier.com

Law Enforcement Exploits Device Linking to Eavesdrop on WhatsApp and Signal

What Happened — WhatsApp Web and Signal Desktop let users link a phone account to a computer. German customs officials have demonstrated that, by obtaining physical access to a phone or intercepting the verification code (often via state‑sanctioned phishing or SMS interception), they can link a police‑controlled computer to a suspect’s account and read messages in real time without breaking end‑to‑end encryption.

Why It Matters for Trust & Control Assurance

  • Demonstrates a gap in device‑access controls: the platform trusts a newly linked device once the verification code is presented, without independent verification that the user initiated the link.
  • Highlights the need for continuous monitoring and logging of linked devices so that any unexpected addition can be detected and investigated promptly.
  • Underscores the importance of user awareness and verification policies (e.g., multi‑factor confirmation, notification of new device links) as a control that mitigates credential‑based attacks.

Who Is Affected – Messaging service providers (WhatsApp, Signal, and similar SaaS platforms), their enterprise customers, and any end‑users who rely on device‑linking for convenience.

Recommended Actions

  • Implement a policy that requires out‑of‑band confirmation (e.g., push notification, secondary factor) for every new device link.
  • Deploy real‑time alerts and audit logs for device‑link events; integrate these logs into a continuous control‑assurance dashboard.
  • Educate users on the risks of phishing and SMS interception, and enforce secure verification code delivery (e.g., in‑app push rather than SMS).

Technical Notes – The technique leverages phishing or SMS interception to capture the one‑time verification code required for device linking. No cryptographic break is needed; the attacker simply becomes an authorized device. Source: Schneier on Security

📰 Original Source
https://www.schneier.com/blog/archives/2026/09/using-device-linking-to-eavesdrop-on-whatsapp-and-signal.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →