According to a leaked document, the FBI has real-time access to data from instant messaging services such as WhatsApp, iMessage, Signal, and Telegram. Dated Jan. 7, 2021, the internal FBI document specifies what types of data law enforcement agencies are allowed to request from the messaging apps listed.
Although a warrant or subpoena is required to obtain the data, iMessage and WhatsApp appear to provide the most information.
What Data is Provided to the FBI: WhatsApp and iMessage
According to the document, the FBI can obtain basic WhatsApp subscriber information with a subpoena. With a search warrant, the FBI can gain access to their target’s contact list and any contact list they are part of. Additionally, the FBI can receive real-time updates from WhatsApp when they raise a special request called the “Pen Register.” These updates are provided in 15-minute increments. Based on the document, the updates only provide metadata and not the actual messages. However, iPhones with iCloud backups active may return message data.
The FBI does not have as much access to iMessage, but the popular messaging app still provides an extensive level of private personal data. Like WhatsApp, iMessage will provide the FBI with subscriber information upon request with a subpoena. Per Title 18 USC 2703, iMessage has to provide up to 25 days of lookups to and from the target in the subpoena. With a warrant, the FBI can obtain a backup of the user’s device, including encryption keys of an iPhone with iCloud backups. If iMessages are backed up on iCloud, those must be provided as well.
Other Messaging Apps Providing Data to the FBI
The other messaging apps listed on the leaked document are Line, Signal, Telegram, Threema, Viber, WeChat, and Wickr. The most secure of these messaging apps is Signal. A breakdown of which information the FBI may have access to is listed below.
| Messaging App | Message content | Target’s registered information | Information on usage | Other information |
|---|---|---|---|---|
| Line | Limited, Subpoena required | Yes | Warrant required | – |
| Signal | None | Date and time a user registered only | The last date of a user’s connectivity to the service only | – |
| Telegram | None | Disclosure of IP and phone number to relevant authorities for confirmed terrorist investigations only | – | – |
| Threema | None | Phone number, email address, push token (if applicable), and Public Key | Date of Threema ID creation and of the last login | – |
| Viber | None | Account registration data such as a phone number and IP address at the time of the creation | Time, date, source number, and destination number | – |
| None | Only for non-China related accounts: phone number, email address, and IP address | – | – | |
| Wickr | None | Date and time of creation and the types of device(s) the app is installed on | Date of last use, number of messages, limited records of recent changes to settings | The number of external IDs (email addresses and phone numbers) connected to the account, but not the external IDs themselves; the Wickr version being used |
What Does This Mean for Messaging App Users?
You might be thinking that this report proves that messaging apps provide less protection than we previously thought. In some cases, that is true. However, what this leaked document really showcases is the importance of due diligence when choosing apps. For example, apps like Signal and Telegram still hold their own against the prying eyes of big governments. Meanwhile, Facebook-owned WhatsApp provides more details to requesting authorities, albeit with court intervention.
Therefore, it is important to really research a mobile app before you download it, so you can make sure your information is safe. You might also consider using a VPN for added protection. If you want a detailed comparison of WhatsApp and Signal, checkout Signal vs. WhatsApp – 6 Key Privacy Differences.
