Paper 2026/1319

A Real-World Law-Enforcement Hack: The Case of Encrochat

Martin R. Albrecht, King's College London
Sunoo Park, New York University
Michael A. Specter, Georgia Institute of Technology
Douglas Stebila, University of Waterloo
Abstract

In 2020, a coordinated law-enforcement effort infiltrated Encrochat, an end-to-end encrypted service provider, exfiltrating historical and real-time data and metadata over months. Encrochat was used extensively by organised crime, and the data from the operation was used as supporting evidence in over 6,000 arrests and related prosecutions across Europe. Encrochat's architecture was vertically integrated, with the company acting as both a device vendor and service provider; Encrochat sold modified Android smartphones with its own PKI and custom applications, including encrypted messaging based on the Signal protocol. In this work, we give the most detailed public account to date of Encrochat's infrastructure and how it was compromised.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
A major revision of an IACR publication in CRYPTO 2026
Keywords
encrypted messagingEncrochat
Contact author(s)
martin albrecht @ kcl ac uk
sunoo park @ nyu edu
specter @ gatech edu
dstebila @ uwaterloo ca
History
2026-06-29: approved
2026-06-25: received
See all versions
Short URL
https://ia.cr/2026/1319
License
Creative Commons Attribution-NonCommercial
CC BY-NC

BibTeX

@misc{cryptoeprint:2026/1319,
      author = {Martin R. Albrecht and Sunoo Park and Michael A. Specter and Douglas Stebila},
      title = {A Real-World Law-Enforcement Hack: The Case of Encrochat},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1319},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1319}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.