German law enforcement agencies, specifically the Zollkriminalamt, have integrated a method for monitoring encrypted messenger accounts by utilizing standard web and desktop client interfaces to establish secondary sessions, according to reporting by Netzpolitik.org. The technique bypasses the underlying end-to-end encryption by pairing authorized devices through methods such as QR code verification or intercepted SMS confirmation codes.
Implementation by the Zollkriminalamt
Internal documents from the Zollkriminalamt show that the federal agency tested the messenger surveillance technique beginning in late 2023. According to Netzpolitik.org, the authority permanently implemented the monitoring method on August 1, 2025. The operational units deploy this capability primarily during investigations targeting organized crime.
The monitoring process does not involve cracking encryption protocols. Instead, investigators configure secondary web or desktop access points for applications such as WhatsApp or Signal. For WhatsApp, agents scan a QR code using a target smartphone, while other platforms require confirmation codes sent via text message, which can be acquired through concurrent telecommunication surveillance. Once the secondary session is active, investigators can read incoming and outgoing messages in plain text and synchronize historical chat logs depending on the platform’s architecture. The messaging applications treat the linked client as an authorized device, leaving the core end-to-end encryption intact.
Legal Scrutiny and Federal Court Rulings
The deployment of companion desktop clients for covert surveillance faces significant legal barriers in Germany. On January 20, 2026, the Federal Court of Justice (Bundesgerichtshof or BGH) issued a ruling regarding a Telegram investigation, determining that covert account mirroring constitutes a source-based telecommunication surveillance measure (Quellen-TKÜ) rather than standard communication interception. Under German law, source-based surveillance requires stricter procedural safeguards to ensure that authorities collect only data specifically authorized by statute.

Standard web and desktop interfaces provided by messenger companies cannot restrict data collection to legally mandated parameters. These companion links automatically sync older messages and complete contact lists, and they possess the technical capability to transmit messages on behalf of the account holder. Prof. Dr. Christian Rückert, an IT criminal law professor at the University of Bayreuth, stated that utilizing commercial vendor tools for these investigations is legally impermissible due to these overreach capabilities. Despite the January 2026 ruling, internal records indicate the Zollkriminalamt relied on an earlier 2020 decision by a BGH investigative judge on February 20, 2026, to justify aspects of its operational framework.
Related reading