A Real-World Law-Enforcement Hack: The Case of Encrochat
EncroChat was a secure communications platform used primarily by criminals. Law enforcement agencies infiltrated it by deploying a malware implant that intercepted messages before encryption. This operation led to thousands of arrests across Europe, but also sparked legal debates about the admissibility of such bulk-harvested evidence in court.
Background
- **EncroChat** was a secure messaging platform popular among European criminals, offering encrypted phones with a monthly subscription ($1,000+). Users believed the devices were virtually unhackable.
- In 2020, French and Dutch police secretly infiltrated EncroChat's infrastructure and deployed a "malware" implant (a remote data capture tool) that intercepted millions of messages in real time, across thousands of users.
- This was one of the largest law-enforcement hacks ever; it led to over 6,500 arrests and the seizure of hundreds of tons of drugs, cash, and firearms.
- The author, **Martin R. Albrecht**, is a professor of cryptography at King's College London. He provides a technical deep-dive into how the implant worked (it intercepted keystrokes, took screenshots, and exfiltrated data before the phone's encryption could protect it).
- The case sparked fierce legal and ethical debate: courts in different countries have ruled differently on whether this mass hacking was admissible evidence or a violation of defendants' rights — and the article explores those tensions.