Contents

WhatsApp Signal Telegram and What Eight Messaging Apps Know About You

 

Ethical Hacking Complete Course Zero to Expert

Hack like black hat hackers. Penetration testing, Kali Linux, WiFi and web hacking, and the hacker mindset behind it.

→ Take the full course
 

Eight Messaging Apps and What Each One Knows About You

Your messages are encrypted and that is the smallest part of it. Who you talk to, when, how often and for how long sits outside the encryption. 8 apps give 8 different answers about what is left.

People have put the same thing to me for years, in one form or another. My messages are end to end encrypted, so there is nothing left to know about me. That is the belief, and it is wrong. The reason is not a scandal and not a leak. It sits in documents these companies publish themselves, in plain language, and those documents are barely read.

In August 2026 Meta announced that more than 1 billion people sign in to WhatsApp with a passkey instead of a password. Good change, worth switching on, and a passkey cannot be phished the way an SMS code can. But a passkey protects the door. It says nothing about the record that gets kept once somebody is inside.

So I read the documents for eight apps. Privacy policies, transparency reports, court filings, protocol specifications, security advisories, and the papers written by the researchers who attacked them. Not only what the companies say about themselves.

Content is only part of the record

Encryption hides the words. It does not hide that you spoke, who with, how long for, or how often. That gap is where this whole article lives.

WhatsApp is the one that writes it down plainly. It sits on more phones than the other seven put together, and its privacy policy is the most direct of the eight about what gets kept.

Under a heading called Automatically Collected Information it lists “the time, frequency, and duration of your activities”. Then how one account interacts with another, whether somebody is online, and the timestamp of their last use. Then “the times you send and receive calls and messages”. From there it carries on into hardware model, operating system, mobile operator, IP address, battery level and signal strength.

Then one line does more damage than the rest put together. They collect identifiers that are “unique to Meta Company Products associated with the same device or account”. Plain words: the phone running WhatsApp, the phone running Instagram and the browser logged into Facebook get stapled together into one person.

None of that is encrypted, because none of it is the message. It is the record of the message existing. Spies worked this out long before messaging apps existed. What you said is content. Who you said it to, when, and how often, is metadata.

Content is a sentence. Metadata is a life.

Somebody messages the same number for forty minutes at a time, three evenings a week. Always after eleven. Always from a cell tower that is not the one their phone sleeps next to. Not one word of it was readable, and you already know exactly what is going on.

How much of that trail exists at all is where the eight apps below part company.

Safe from whom

Somebody asks me which messaging app is safe, and I ask them a question back. It is the only question here that gets anywhere.

Safe from whom.

No app is safe on its own. Four different people might want to read your messages, and they want four different things. An app that stops one of them can be useless against the next, so work out which one is yours before you install anything.

The first is the person who picks your phone up off the table. No app helps there. A screen lock does, and so does hiding message previews.

The second is a thief with the phone, or somebody who gets into the cloud account behind it. Here the encrypted backup is close to everything and the choice of app is close to nothing. Most readers of this article sit at exactly this level, and it is the cheapest one to fix.

Third is the company itself, quietly building a file on you over the years. No setting fixes this one. The collecting is the business, so the only thing that helps is leaving.

The fourth is a state with a court order. Only one thing counts then, which is what is still there to hand over. That is not a matter of opinion, because several of these companies publish exactly what happened.

The four questions I asked of all eight

Each app below answers the same four questions in the same order. That keeps the comparison fair, and it makes it easy to skip ahead to the one that matters.

  • โ†’ What it asks for before a conversation can start
  • โ†’ What it hands over when a court asks
  • โ†’ What has been broken, and whether it was fixed
  • โ†’ What the trade is

That third question is the one these comparisons leave out. It separates a company that gets attacked and repairs itself from one that looks clean because the researchers went elsewhere.

WhatsApp

Registration. A phone number, which becomes the identity on the service. Owned by Meta.

On a court order. In January 2021 the FBI wrote an internal guide to what investigators could obtain from encrypted messaging apps. It became public through a freedom of information request by a transparency group called Property of the People. WhatsApp is one of the useful ones on that list. Investigators can get a live feed of who is talking to who, refreshed at fifteen minute intervals. The legal name for it is a pen register.

Not the messages. Just the pattern, while it is still happening.

What has been broken. WhatsApp keeps your phone and your laptop in step, so a message read on one shows as read on the other. In August 2025 a flaw in that syncing was chained to a flaw in the way Apple opens image files. The two are CVE-2025-55177 and CVE-2025-43300. Both companies describe what followed as a sophisticated attack against specific targeted people. WhatsApp closed its half in v2.25.21.73 for iOS. Apple closed the other half in iOS 18.6.2 on 20 August 2025. Earlier, on 31 January 2025, WhatsApp notified around 90 accounts, journalists and civil society members among them, that they had been targeted by the spyware company Paragon with an attack that needed nothing from them at all. They did not tap anything, click anything or download anything. The trade calls that a zero click. Citizen Lab published the analysis on 19 March 2025.

The one that should worry you more took no exploit at all. They just asked politely, 100 million times an hour.

In November 2025 researchers from the University of Vienna and SBA Research published a study on the feature that checks your address book against WhatsApp to see who is already on it. Contact discovery, in the manual. They fired questions at it at over 100 million phone numbers an hour and nothing slowed them down. They came away with 3.5 billion accounts, along with numbers, public keys and timestamps. Two details in that paper stand out. The same encryption key turned up on different devices under different numbers. And close to half the numbers in the 2021 Facebook leak were still active. Meta has since put a cap on how fast those questions can be fired, which is what was missing.

Regulators have had their turn too. The Irish Data Protection Commission fined WhatsApp 225 million euro on 2 September 2021 over transparency failures. A second fine of 5.5 million euro followed in January 2023, over the legal basis the company relied on.

The trade. The messages are genuinely out of Meta’s reach. Everything around them is not, and it links across to the rest of Meta through that shared identifier. Staying has a decent argument behind it, because it is where the family group chat lives. The encrypted backup then becomes the thing that matters.

Signal

Registration. A phone number, still, and that part has not changed. Since February 2024 the number can stay hidden. One setting controls who can look up an account by its number, and a username works as the thing to hand out instead. Registering without a number remains impossible.

On a court order. In March 2026 Signal published a set of court documents that I think is the clearest thing written on this subject. Their own summary of the position is one sentence: “Signal end-to-end encrypts both content and metadata by default far beyond most of our peers.” Content and metadata. That second word is the one the other seven cannot put in writing.

A grand jury in the United States District Court for the District of Columbia demanded account information for 37 phone numbers. Account creation date and time, last connection date and time. Those two things were the request. Signal points out that this is itself telling, because prosecutors have learned there is no point asking for more. Of the 37 accounts, 7 did not exist. For 24 of them Signal held nothing covering the period. For the remaining 6 it produced two timestamps each.

Contacts, group memberships, message history, call logs, profile information. Signal cannot produce any of it, because it never held it in the first place.

The order arrived with a gag attached that ran for a year. The American Civil Liberties Union got that modified, which is why the documents can be read at all.

What has been broken. Plenty. In March 2026 researchers at ETH Zurich published two ways to slide a message into your chat that the other person never sent. The first abused the way Signal looks somebody up by username instead of by phone number, and worked on Android and Desktop.

The second was worse, and it needs one word of background. Signal has a feature called Sealed Sender, which hides from Signal itself who sent a message, so their own servers see a delivery without a sender attached. Two mistakes in how that was built on Android let a hostile server drop any message it liked into a one to one chat or a group chat, with nothing showing on your screen. The hole had been open since Sealed Sender arrived in 2018.

Then look at what happened next. The first was reported on 22 September 2025, patched on Desktop the same day and on Android two days later. The second was reported on 20 January 2026 and closed on 28 January. iOS was not affected by either.

Same day, two days, eight days. That is the part these comparisons never get to.

In August 2022 somebody phished their way into a support desk at Twilio, the company sending Signal’s text messages at the time. For around 1,900 users that exposed either the fact that a number was on Signal, or the login code itself. One account got taken over on another phone. Signal logged all 1,900 out and made them register again, inside two days.

And for years Signal Desktop left the key to its own message database lying in plain sight on the hard drive. Signal argued that guarding against somebody already sitting at your computer was never the point of the desktop app. Then they fixed it anyway, in July 2024.

One thing stays open. Academic work going back to 2021 shows Sealed Sender does not hold up across a whole conversation. Those little delivery ticks give away the timing, and after a handful of messages the two ends can be tied back together. Delivery receipts are still on by default.

The trade. The phone number. Your identity is attached to the account, even though almost nothing gets written against it.

Threema

Registration. Nothing that has to be proved. A Threema ID is generated for the account, and a phone number or email address can be linked to it to become findable, or left off entirely. The app is paid for once, and the company sits in Switzerland under Swiss law.

On a court order. The date the Threema ID was created, without the time, and the date of its most recent login, without the time. Where a number or address was linked, a hash of it. Where a third party push service is in use and the ID has been active in the last three months, a push token. That is the list.

That list is short for a legal reason. Swiss surveillance law sets a revenue threshold above which a provider has to retain communication metadata, and Threema stays under it, so the obligation does not apply. They still hand over whatever they happen to hold when a Swiss court orders it. They have simply arranged the service so that what they happen to hold is two dates.

Their table runs from 2014 and reads better as a trend than as a number. Requests from authorities: 28 in 2018, 80 in 2021, 306 in 2024, 423 in 2025, and 444 in 2026 with the table only running to the end of June. In 2025 those requests covered 1,505 Threema IDs across 402 cases. The number of authorities asking a service that has almost nothing to give has gone up in each of the last five years, from 80 to 444.

What has been broken. In January 2023 the Applied Cryptography Group at ETH Zurich published seven attacks on Threema, having handed them over the previous October.

They could pretend to be you to the server, and keep doing it. They could forge the token that proves an identity to that server, which gets them the same thing by another door. They could shuffle your messages around or drop them. They could replay old ones at somebody who had just reinstalled. They could trick your app into encrypting the attacker’s words and sending them to a friend under your name. Given a minute with an unlocked phone, they could clone your Threema ID. And through a trick with the backup routine, they could pull out your private key.

Seven, from one team, in one paper.

Most were closed in Threema 5.0 for Android and 4.8.5 for iOS. The reordering and replay problems were dealt with by a new protocol called Ibex, which shipped in November 2022 and was given a formal security proof by cryptographers at the University of Erlangen-Nuremberg in August 2023, at which point forward secrecy became the default. The cloning one Threema calls behaviour by design and answers with the app PIN.

On 8 January 2023, one day before the agreed disclosure date, Threema published a statement calling the findings interesting in theory, saying none of them had considerable impact in practice, and that most assumed unrealistic conditions. They took criticism for it, and rightly. How a company answers researchers says something about the next report that lands on their desk.

The trade. Money, and a smaller network. The paying is also what keeps the company under that Swiss threshold, so the cost and the protection turn out to be the same thing.

SimpleX

Registration. Nothing at all, and that is the design rather than a feature. Not a phone number, not an email address, not a username, and no account identifier is generated either. A conversation starts from a one time link or a QR code, and the two directions run through separate queues on separate servers. There is no account to look up.

On a court order. Their transparency page runs to a few sentences. In 2025 they received 12 requests from law enforcement in various countries. “No responsive information was identified/provided.”

What has been broken. Trail of Bits reviewed the code in November 2022 and found a mistake in the handshake that sets up the keys at the start of a conversation, a step known as X3DH. Medium severity, which SimpleX fixed in v4.2 while telling users with security critical contacts to build new connections. The same review found encryption keys sitting in memory that could be swapped out to disk, and I could not establish at any source whether that has been addressed since.

A second Trail of Bits review in July 2024 found three medium and one low severity issue. One was fixed in v6.1 by adding another layer of encryption inside the TLS connection. Three of them SimpleX deliberately did not fix, and said so in public: an attacker controlling a network node can correlate delays to confirm two people are talking, an attacker can tell from packet counts whether a message is waiting for an iOS user, and an attacker able to modify the app database on a device can become an undetectable man in the middle. On that last one SimpleX states plainly that it does not believe a defence exists.

A third assessment was scheduled for June 2026. As of August 2026 no report had appeared.

The trade. Setting it up asks more work, and the contacts are not there. SimpleX Chat Ltd is registered in London and its terms sit under the law of England and Wales, which matters to some people and not to others.

Session

Registration. Nothing at signup, and messages route through its own onion network so no single server learns both ends of a conversation. Stewardship moved from an Australian non-profit to a Swiss foundation on 15 October 2024, and Session’s own announcement gives the reason as the regulatory environment in Australia around encrypted messaging.

On a court order. No phone number and no email address exist to hand over, and no published court response comparable to Signal’s exists either.

What has been broken. First, what forward secrecy is, because everything here hangs on it. A good messenger gives each message its own key and throws it away afterwards. Steal the key from today and yesterday stays shut. That is forward secrecy.

Session has no forward secrecy. Not “not yet”, not “coming in the next release”. Since December 2020, when it moved off the Signal Protocol to a design of its own, each message has gone out locked with the same key, and that key never changes unless you throw the account away and start again. One key, one lock, all of it.

That is not my reading of it. It is Session’s own text. In their protocol announcement of December 2025 they set out three consequences themselves. A node that keeps messages past their expiry, combined with a later compromise of the long term key, exposes old messages. Anything captured today can be stored against a future quantum computer. And an attacker holding the key can link a new device to the account invisibly.

Version 2 of the protocol is meant to fix this by rotating the keys, and by adding encryption built to survive the quantum computers that do not exist yet. Their development update of 2 August 2026 says that work is on hold while the team finishes other things, and that the plan is a separate invite only app for direct messages between two people who both run it. Development of Session was paused entirely earlier in 2026 for lack of money and restarted later that year with three developers.

An audit by Quarkslab in 2021 covered all three clients and found sixteen issues, and Quarkslab states the important ones were patched during the audit itself. One disagreement was left standing. Session generates its identity keys from 128 bits of randomness padded out to 256, so that the recovery phrase can be 13 words instead of 24. Quarkslab flagged the tradeoff and it is still how the app works.

The trade. No forward secrecy, and a project that has had a hard year. The privacy design is genuinely good and the engineering behind it is thin at the moment.

Telegram

Registration. A phone number.

On a court order. Section 8.3 of the privacy policy: on a valid order from judicial authorities, where the account holder is a suspect in a criminal case, Telegram may disclose their IP address and phone number, and it reports these cases quarterly. Section 5.2 says it may hold the IP address, the devices and Telegram apps used, and the history of username changes, for up to twelve months.

Section 8.3 has a date on it. It changed on 23 September 2024. Pavel Durov, Telegram’s founder, was arrested at an airport near Paris on 24 August 2024 and put under formal investigation four days later. The policy changed one month after the arrest. Before that, disclosure was framed around terrorism cases.

What has been broken. Nothing needed breaking here, because the thing you assume is switched on was never switched on. Ordinary Telegram chats are not end to end encrypted. Section 3.3.1 of the policy says they are stored on Telegram’s servers so they can be reached from any device, encrypted in storage and in transit, with the keys held by Telegram across several jurisdictions. Only Secret Chats are end to end encrypted, and one has to be started deliberately, for each conversation, on each device. They do not sync, and existing chats are not converted.

That is not a technicality. It is the difference between a company that cannot read the messages and a company that has chosen not to.

Telegram built its own encryption rather than using one of the standard ones, and called it MTProto. In July 2021 researchers at Royal Holloway and ETH Zurich published four attacks on it. Somebody on the network could shuffle the order of your messages. A timing trick could leak pieces of what you wrote. And during the very first handshake, an attacker could pose as Telegram itself.

All four were closed in Android 7.8.1, iOS 7.8.3 and Desktop 2.8.8.

What did not get closed is the design. MTProto checks the message before locking it rather than after, which is the reverse of what the rest of the field settled on years ago. And there was one more thing in that paper. The researchers say Telegram told them it does not do security releases, does not publish advisories when it patches, and would not promise a date.

In July 2024 a flaw tracked as CVE-2024-7014 let a crafted file appear in Telegram for Android as a video with a thumbnail and a play button, and prompt an app install when tapped. Closed in 10.14.5 on 11 July 2024.

The trade. It is good at public channels and groups, which is what it was built for. It is not a private messenger unless a Secret Chat is started each time, and it will give a judge an IP address and a number.

XMPP with OMEMO

Registration. An account on a server. Somebody else’s, or one run at home. That one choice decides almost everything that follows.

On a court order. Whatever the person running the server has, and whatever a court can make them hand over.

The encryption here scrambles the words in your message and it is called OMEMO. It does not hide who sent it, who received it, or when. The spec says so itself, in plain writing.

It also says an app should never start a new conversation before you have compared fingerprints with the other person. Skip that and somebody can add a fake device to your account and quietly collect a copy of everything. Comparing fingerprints is the step people skip.

What has been broken. In October 2023 an investigator published an account of what had been happening to jabber.ru, one of the older public XMPP servers. Somebody had got hold of valid certificates for the domain from Let’s Encrypt and parked a machine in front of the actual server. That machine unwrapped the encryption, read what went past, wrapped it back up and passed it along. Neither side noticed a thing. The rogue certificates were first issued in April 2023, and the interception is confirmed in place from at least 21 July 2023 to 19 October 2023.

It came to light because one of the fake certificates expired and was not renewed, so users started seeing certificate warnings from a server that was serving a perfectly valid certificate of its own.

The servers themselves were clean. Memory, processes, routing and firewall rules all checked out. The redirection was configured inside the networks of the two hosting providers, on servers in Germany. The investigator’s assessment is lawful interception carried out at a police request. Neither hosting company gave a substantive answer, and no official statement has appeared since.

What the operator of that proxy could do while it lasted, in the investigator’s own words, is act as any authorised account: pull the contact list, read the server side message history, send messages as somebody else, or alter them in transit. And then the sentence that runs straight back to the top of this article. End to end encryption protects against this only where both sides have actually verified each other’s keys, and verifying keys is the step that gets skipped.

The trade. The server operator is the security. Run one and this is the only entry here where the infrastructure belongs to the user. Use somebody else’s and the question of trust has moved onto whoever runs that server.

Matrix

Registration. An account on a homeserver, the same trade as XMPP.

On a court order. Whatever the homeserver holds, and that is more than it first appears. Matrix encrypts message content but not room state, so who is in a room, when they joined, display names and timestamps all sit in the clear.

What has been broken. In September 2022 researchers from Royal Holloway, Brave and the University of Sheffield published six practical attacks on Matrix’s end to end encryption. A malicious homeserver could add a device to an account and quietly receive the keys to its encrypted rooms. Emoji verification could be broken through a confusion between two kinds of identifier. Messages could be forged to look as though somebody else had sent them. Most were fixed on the day of disclosure, 28 September 2022. One was not. Room membership messages are still not authenticated in the Matrix specification, and Matrix said at the time that signing them was future work.

On 11 August 2025 Matrix shipped a coordinated security release for two high severity flaws in the protocol itself, affecting Matrix server implementations in federated rooms. One is CVE-2025-49090. The fixes only apply to rooms upgraded to the newest room version, so an old room with members on untrusted servers stays exposed.

The trade. Same deal as XMPP. Your words are safe, the record around them is not, and at least they say so out loud.

Two more, off the list

That is the eight. Two more belong here, though not on the same list, because they never get the four questions treatment above, and switching to them is a big step.

Ask somebody who does this for a living what they would use if the stakes were high, and these two names come back.

Briar runs without servers of any kind. Messages go straight from one phone to another over Tor, and when the internet is down they travel over Bluetooth, over local wifi, or on a memory card carried across a room. The account lives on your device and the project does not hold it. Cure53 audited the Android app in March 2017, found twelve issues, and wrote that it can be recommended for use.

That audit is nine years old, and something else happened since. On 9 July 2026 the project announced it is in maintenance mode. They had decided to shut down in 2025, changed their minds, and now ship only essential security fixes, unfunded, in spare time. They are open about the rest too: it eats battery, it struggles to stay running in the background on Android, and there is no backup.

Cwtch takes the other road. Everything over Tor, servers treated as throwaway and untrusted, and no central list of names anywhere. Their own risk model is blunt about the cost of that. With no name registry, somebody can spin up thousands of accounts until one resembles your contact, and Cwtch writes that the only defence is checking the public key, while admitting that in practice this will not happen.

I could not find a published independent audit of Cwtch, and the newest release in their own changelog is from October 2025.

So the two tools the professionals name are a project in maintenance mode and a project without an audit. That is where metadata resistant messaging stands in August 2026, and it is worth saying plainly rather than selling either one as the answer.

The backup is a separate problem

None of them says anything about the copy sitting somewhere else, and that copy is where most conversations actually leak.

WhatsApp offers an end to end encrypted backup protected by a password or a 64 digit key held only by the account holder. It exists, it works, and it is very good. It is also something that has to be switched on. Without it, the chat history sits in iCloud or Google Drive protected by a cloud account, and a cloud account is reachable with a password reset.

1
Settings > Chats > Chat Backup > End to End Encrypted Backup

Menus move between versions, so if that route does not match the phone in hand, search the settings for the words backup and encrypted. Given the choice between a password and the 64 digit key, take the key and write it on paper. Losing it means losing the backup, and there is no reset. That is the point of it.

One detail from WhatsApp’s own help page has not appeared anywhere else that I could find. On an iPhone, switching on the encrypted WhatsApp backup pulls the WhatsApp history out of the full device backup. The two do not stack.

On an iPhone the problem is bigger than WhatsApp anyway. In that FBI document from January 2021, iMessage sits on the productive side of the list, and the reason given is iCloud backups. Apple’s Advanced Data Protection closes that gap, and Apple’s own support page describes it as an optional setting that has to be turned on. In the United Kingdom it stopped being available to new users on 21 February 2025, and Apple’s page still said so in August 2026.

One more thing worth doing

WhatsApp will send a report of what it holds on an account.

1
Settings > Account > Request account info > Request report

It arrives in about three days as a ZIP of HTML and JSON.

Read the small print on that page while waiting. The report covers account information and settings, and it does not include the messages. That is the encryption doing its job. What it does show is the shape of the other file, the one made of settings, devices and connections, and seeing a personal copy of it lands differently than reading about mine.

The same works elsewhere. Plenty of countries give people the right to ask a company for the data it holds on them. Europe, the United Kingdom, Brazil, California and a long list of others. Ask, and the ones holding almost nothing will send back almost nothing. That answer is worth as much as a long report.

Where I would start

Not a list of demands. This is the order I would go in, and the first three take about a minute each.

  • โ†’ Hide message previews on the lock screen and make the screen lock a code rather than a swipe.
  • โ†’ Find the backup setting in whichever app holds your history, and switch on the encrypted version. In WhatsApp that means taking the 64 digit key rather than a password, and writing it on paper. This is the single biggest change available to most readers.
  • โ†’ In Signal, set who can find the account by phone number, take a username, and turn on Registration Lock with a PIN so a number alone is not enough to move the account to another handset.
  • โ†’ In Threema, send the word info to *MY3DATA from inside the app. It sends back what is stored against that ID. It comes back very short, and that is exactly the point.
  • โ†’ Then move one conversation. The one that happens most often, with the person it happens with. Not the contact list, one conversation. That is how these things stick.

And the thing that outranks all of the above: the person on the other end. The most private app in the world does nothing about the message sitting on somebody else’s phone.

The apps the underworld trusted

One more thing, because it settles the argument better than anything above it.

Organised crime does not run on WhatsApp. It buys purpose built encrypted phones, at around a thousand euro a handset and fifteen hundred for six months of service, from companies that sell nothing else. Look at what happened to five of them.

EncroChat, 2020. Around 60,000 users. French investigators got past the encryption by placing a technical device on the servers, which sat in France. Police read 115 million messages. The tally by 2023: 6,558 arrests, 197 high value targets, and 739.7 million euro in cash seized.

Sky ECC, 2021. About 170,000 users sending three million messages a day. Belgian, French and Dutch investigators unlocked it and were watching the traffic of roughly 70,000 users from mid February, three weeks before the raids.

Exclu, 2023. Roughly 3,000 users. Dutch and German police followed the conversations for five months before they moved. 45 arrests.

Ghost, 2024. Servers in France and Iceland, administered from Australia and Canada. 51 arrests.

And then ANOM.

In 2018 the FBI dismantled an encrypted phone company called Phantom Secure. That left a hole in the market, and the FBI filled it themselves. ANOM was not a company that got infiltrated later. The FBI built it, ran it, and let criminal middlemen sell it, who advertised it as designed by criminals for criminals.

Each message left the phone with a copy going to a server in a third country, and from there to the FBI. The Department of Justice compared it to a blind carbon copy in an email. More than 12,000 devices reached over 300 criminal groups in more than 100 countries. Agents read 27 million messages. When EncroChat fell in 2020 and Sky Global in March 2021, demand for ANOM climbed, which means the FBI was selling the replacement for the networks it had helped take down.

It ended on 8 June 2021 with 800 arrests, 8 tons of cocaine, 250 firearms and 48 million dollars in various currencies. Along the way the FBI says it headed off more than 150 threats to somebody’s life.

The prosecutor put it better than I can. “The supreme irony here is that the very devices that these criminals were using to hide from law enforcement were actually beacons for law enforcement.”

Look at that list again. Cracked, cracked, read for five months, taken down, and one of them built by the police from the first day.

Not a single one of those networks failed because the encryption was weak. They failed because somebody else owned the infrastructure. Which is the same lesson as the apps above, only louder.

When I checked this

Everything above was verified against primary sources on 26 August 2026. Privacy policies, transparency reports, court filings, security advisories and the researchers’ own papers, rather than news coverage of them.

Transparency numbers grow, protocols get replaced, menus move and court cases finish. Read a long way from that date, the facts still hold as of the dates written next to them, and the ones with an open ending are worth checking again. I update this page.

You can watch the rest of it happen on your own network. Run Wireshark and send yourself a few messages. The content stays unreadable. The destinations, the timings and the sizes do not. My Ethical Hacking Complete Course Zero to Expert takes you there step by step: reconnaissance, scanning, exploitation and traffic analysis, hands-on, from your first day with no Linux or hacking background.

โ†’ Join my complete ethical hacking course

Hacking is not a hobby but a way of life.

Sources:

WhatsApp Privacy Policy | Signal Transparency and Government Requests | US Department of Justice on Operation Trojan Shield

 
NEWSLETTER

Stay updated

Get the latest posts in your inbox every week. Ethical hacking, security news, tutorials, and everything that catches my attention. If that sounds useful, drop your email below.

By Bulls Eye

Jolanda de koff โ€ข email โ€ข donate

My name is Jolanda de Koff and on the internet, I'm also known as Bulls Eye. Ethical Hacker, Penetration tester, Researcher, Programmer, Self Learner, and forever n00b. Not necessarily in that order. Like to make my own hacking tools and I sometimes share them with you. "You can create art & beauty with a computer and Hacking is not a hobby but a way of life ...

I โ™ฅ open-source and Linux