Three things a spyware expert learned from the forensic investigation of the EncroChat hack

Photo: Souro Souvik/Unsplash

28 August 2026

Would you prefer to access this content in video form? Watch James explain on LinkedIn or YouTube. For more video-based cyber learning, head over to VIRO Learning, the new on-demand education platform from Virtual Routes. 

EncroChat was once Europe’s premier secure messaging system for organised crime: a network of dedicated devices with fake normal apps, and a hidden layer with an end-to-end encrypted messaging service, like you now find on WhatsApp or Signal. EncroChat was first developed in 2014 and was hacked by French police in 2020, providing crucial evidence for thousands of arrests and prosecutions of violent crime, narcotics smuggling, and other organised criminal activities across Europe.

While the results of the EncroChat hack have been reported on extensively, the French have been cagey on the details of how it happened – even to their own law enforcement partners in other states. Now, Bill Goodwin at Computer Weekly, who has followed EncroChat developments for many years, and the renowned investigative reporter Duncan Campbell, have published a detailed investigation of the hack, based on a forensic report that they managed to obtain. 

The report, ordered by a UK judge, details the technical analysis of an infected EncroChat device seized as part of a trial. While they didn’t release the full report, their article is illuminating – and worth reading in full. But if you’re short on time, here are three things I learned:

Spyware companies are involved in several ways

Spyware companies appear at both ends of the story. In the UK trials, judges were concerned about the reliability of evidence from the device; one ordered the UK National Crime Agency (NCA) to find an independent third party to show the hack preserved messages in a consistent and reliable form, suitable for entry into the evidence chain of custody. 

UK authorities chose a Czech company called Invasys, which, according to the article, ‘sells malware to governments for intelligence gathering’ – ie, spyware. The NCA reasoning is sound: find a thief to catch a thief, and find a private company that builds their own spyware to work out whether spyware developed by a government really worked as intended. There was some impressive hardware engineering involved, laid out in detail in the Computer Weekly investigation.

But more infamous spyware companies also played a role right at the start of the story. It turns out that the EncroChat hack relied on an Android vulnerability, nicknamed Bad Binder, which was exploited by Israeli company NSO Group for its notorious Pegasus spyware, then discovered and published – for legitimate defensive reasons – by Google in 2019. Even though Google patched the vulnerability quickly, EncroChat devices used an older Android version that was still vulnerable. 

Developing good spyware is hard 

Goodwin and Campbell are pretty unforgiving regarding the French hackers, citing ‘delays, errors, and false starts’, and ‘multiple mistakes… forcing back the planned date by three weeks’. One expert cited in the investigation said the code, with exploits copied from the internet, looks like a student project (a central part of the hack relied on an open-source Android monitoring toolkit called Frida). 

Now I don’t have access to either the code or the report, so I am inclined to trust this assessment. But one note of caution: it’s a well-established tactic for intelligence agencies not to develop their own sophisticated code, but rather to use what is publicly available and legitimately repurposable – this is faster, easier, and more difficult to detect and attribute. And intelligence agencies were probably involved here – the French police tasked a joint team to develop the exploit. More generally, it’s a mistake to associate the use of openly available malware components with a lack of care or technical knowledge in the development process.

Nonetheless, the fact that the French government used exploits developed and publicly released by private companies is striking: people mainly talk about European governments as the starting point, not the endpoint, of a proliferation dynamic.

This doesn’t just matter for criminals

Finally, this may seem like a pretty niche issue, only a concern for people with something to hide or their lawyers. But it matters for everyone, in a few important ways. 

First, it has implications for the right to a fair trial. The UK, unusually, doesn’t admit intercept as evidence in court, so UK lawyers have a special interest in determining how the hack happened: whether it was ‘in transit’ (on a server) or ‘at rest’ (on a device). Across Europe, the question of whether data from hacked devices is admissible in court – and, if so, what kind of hacks are allowed – has massive implications for police intelligence gathering more generally.

Second, what does organised crime do next? EncroChat was one of several purpose-built systems that offered a level of additional security that very few non-criminals would ever want – or would want to put up with. But developing such a system also paints a massive target on your back; you essentially hold a sign up to law enforcement agencies saying ‘Hack me, please!’ 

Unfortunately, if organised crime groups choose instead to hide in the noise and move to mainstream apps like WhatsApp or Signal, this increases the pressure on governments to crack down on end-to-end encryption overall. The UK and EU are already taking steps in that direction, which is bad for everyone’s privacy.

One final note: the authors say this is the first of two major articles, so I am excited to see what they release next.