The Wiretap: How The FBI Digs Up Deleted WhatsApp Messages (2024)

This is the web version of this week’s edition of The Wiretap newsletter, which every Tuesday brings exclusives and other news about surveillance, privacy and cybercrime, straight to your inbox. Click here to get on the newsletter list!

If your iPhone is ever obtained by the police, and they have the legal authority to search it, law enforcement can sometimes find information you believe you deleted — even from encrypted chat apps like WhatsApp.

In a recently unsealed case, cops in Eastern California seized the phone of a suspect in a drug trafficking investigation, tracking shipments of meth and fentanyl from Mexico to the state. In a search warrant, an FBI agent in Sacramento detailed how some of the WhatsApp messages between the suspect and an alleged co-conspirator were “scrambled.” The reason? “When the extraction software recovered the messages, the words appear out of order, or ‘scrambled,’ due to encryption features of the WhatsApp messages,” the investigator noted.

Such “extraction” software - typically forensics tools created by the likes of Israel’s Cellebrite and Atlanta-based Grayshift - will look for remnants of files in different smartphone databases. Online records indicate the technology to get deleted WhatsApp messages from an Apple iOS database has been available to law enforcement and private organizations that own a Cellebrite Physical Analyzer tool for at least the last two years.

According to a 2021 post from a Discord user claiming to be a Cellebrite employee in a group for forensics professionals, when WhatsApp messages were deleted on an iPhone, rather than disappear entirely, they were fragmented yet remained stored in an iOS database called “chatsearch,” designed to make searching conversations quicker. Cellebrite’s technology could recover these but returned them in a fragmented format and labeled them “scrambled.” The technology appears to continue to work in the same way today; in March this year, another Discord user claiming to be a Cellebrite staffer pointed users to the 2021 post when queries about deleted WhatsApp messages were raised.

WhatsApp owner Meta said it couldn’t comment without more knowledge of the criminal cases and the phones involved. Apple had not provided comment at the time of publication.

Though they can acquire a lot of useful evidence from a phone, Cellebrite devices and competing products aren’t always effective. Often, their capabilities vary from one phone model to the next. In another search warrant reviewed by Forbes, in October 2022, the DEA noted that their Cellebrite tool couldn’t retrieve WhatsApp messages from an iPhone 11 because of “limitations with respect to this particular device model.” They had to manually go through the phone to gather data.

“Cellebrite is able to legally and lawfully extract WhatsApp data for law enforcement investigations, recognizing that it depends on OS and phone model,” a Cellebrite spokesperson said.

Google phones, meanwhile, may not be susceptible either. The “chatsearch” database doesn’t exist on Android, meaning the same technique doesn’t apply, according to Russian digital forensics expert and Elcomsoft founder Vladimir Katalov. He said there may be other techniques that can acquire deleted WhatsApp messages on Android, however. Google declined to comment.

As in the case above, such searches can be invaluable in gathering data on a criminal conspiracy. However, if the same tools were applied to an innocent party or someone breaking a controversial law (an abortion ban, for instance), they suddenly become a lot more contentious.

THE BIG STORY

Meta Fined Record $1.3 Billion For Violating EU Privacy Rules

The penalty against Meta - issued because of the ways in which it moves personal data from Europe to the U.S. - is the largest fine ever issued under the European Union’s data protection rules. It may threaten the future of Meta’s Facebook, Instagram and WhatsApp across Europe.

STORIES YOU HAVE TO READ TODAY

TikTok has been banned in Montana, where the governor said the move was “to protect Montanans’ personal and private data from the Chinese Communist Party.” TikTok has already launched a legal challenge.

Public housing across the U.S. is being covered in surveillance cameras, powered with facial recognition and artificial intelligence, according to a Washington Post investigation. The residents have little say and there’s minimal oversight of the snooping, even when it singles out those with severe disabilities for eviction.

Customs and Border Protection acquired a tool - Babel X - that can link a person's Social Security number to their social media posts and location, according to Vice.

The FBI improperly searched a U.S. foreign intelligence database 278,000 times over several years, according to the Office of the Director of National Intelligence. Among the improper searches were those focused on the January 6 Capitol riots and the 2020 George Floyd protests.

WINNER OF THE WEEK

Digital sleuths Joe Stewart and Keegan Keplinger have been hunting a coder believed to be providing malware to two of Russia’s biggest cybercrime crews, Fin6 and Cobalt Group. They say they’ve identified him and handed his information to American police. In an exclusive for Forbes, they also uncovered photos showing the coder’s apparently comfortable life, vacationing in Mexico, London and Italy with his high-fashion wife.

LOSER OF THE WEEK

The Justice Department has filed charges against Russian national Mikhail Pavlovich Matveev for allegedly using three ransomware variants - LockBit, Babuk, and Hive - to hack into and extort a number of critical infrastructure organizations, including hospitals and government agencies. Amongst the alleged victims of his ransomware crew’s attacks was the Metropolitan Police Department in Washington D.C.

The Wiretap: How The FBI Digs Up Deleted WhatsApp Messages (2024)

FAQs

Can police find deleted WhatsApp messages? ›

We do not retain data for law enforcement purposes unless we receive a valid preservation request before a user has deleted that content from our service. In the ordinary course of providing our service, WhatsApp does not store messages once they are delivered or transaction logs of such delivered messages.

Can forensic recover deleted WhatsApp messages? ›

Forensic analysis: They use specialized software and techniques to extract data from the phone, including deleted messages. 3. Data recovery: Software like EnCase, XRY, or Cellebrite can recover deleted data, including chats, messages, and other content.

Can WhatsApp messages be traced once deleted? ›

WhatsApp messages can be traced after they've been deleted because WhatsApp stores their source codes and destination codes for a period of time. On your device itself, deleted messages may be recovered using certain tools if new data has not overwritten it, or if they are saved in a backup.

Can deleted WhatsApp messages be recovered? ›

If you have a chat backup enabled, you can recover your deleted messages from that backup. On Android: WhatsApp automatically backs up your chats to Google Drive by default, unless you've disabled it. On iPhone: WhatsApp backs up to iCloud, again, if enabled.

Does WhatsApp keep records of deleted messages? ›

As long as the phone allows to receive WhatsApp message notifications, whether it is iPhone or Android, you can receive the record of deleted messages and see the original message in your notification log.

Can WhatsApp disappearing messages be traced? ›

Disappearing messages are excluded from all backups and can't be restored by design. WhatsApp can't restore your disappearing messages for you, since we do not store your messages. Disappearing messages aren't available in certain countries for payment or order-related messages.

Can deleted WhatsApp messages be permanently deleted? ›

Note: Once you delete a chat, it can't be undone. WhatsApp is unable to recover deleted chats for you. You can only recover deleted chats if your latest backup occurred prior to deleting a chat.

How far back can you get deleted WhatsApp messages? ›

Deleted WhatsApp backups are permanently gone and cannot be recovered. WhatsApp backups that haven't been updated in more than a year are automatically removed from Google Drive and cannot be recovered. No files, photos, videos, backups, or data of any kind can be recovered from this help forum.

Can WhatsApp be wiretapped? ›

The content of all messages sent using WhatsApp are protected by the same Signal encryption protocol that secures messages before they leave your device, which ensures only you and the person you're communicating with can listen to or read what you're sending, and nobody in between, not even WhatsApp.

Can FBI recover deleted WhatsApp messages? ›

It is possible for police to recover deleted WhatsApp messages, but the success of these efforts will depend on a number of factors, including the type of device, the data retention policies of WhatsApp, and the encryption status of the messages.

Can police track WhatsApp chats? ›

Can the police access WhatsApp messages? WhatsApp, along with most other messaging services, uses end-to-end encryption, meaning that the police cannot easily intercept your messages. WhatsApp can, however, in certain circ*mstances be asked to share information with criminal enforcement agencies.

Are deleted WhatsApp messages really gone? ›

You can delete messages just for yourself or request that messages be deleted for everyone. If you want to edit a message instead, you can for up to 15 minutes after sending. When you delete a message, there's no way to get it back unless you've included the message in a backup.

Do deleted WhatsApp messages get stored? ›

WhatsApp messages that are deleted by the sender are typically stored on the recipient's device until they manually delete them. However, it's important to note that WhatsApp backup files, which are created either locally or on cloud services, may retain deleted messages for a longer period.

Can I recover permanently deleted WhatsApp messages without backup? ›

Yes, you can recover deleted WhatsApp messages without a backup by using third-party software like Dr. Fone, Tenorshare UltData, or EaseUS MobiSaver. These tools can scan your device for deleted data and help you retrieve lost messages.

How to delete WhatsApp chat backup permanently? ›

How to delete WhatsApp database files on your phone
  1. Open your file manager.
  2. Tap Main Storage or Internal Storage.
  3. Tap Android > media > com. whatsapp > WhatsApp > Databases.
  4. Tap and hold each database file > Delete.

Can someone find your deleted WhatsApp messages? ›

You can delete messages just for yourself or request that messages be deleted for everyone. If you want to edit a message instead, you can for up to 15 minutes after sending. When you delete a message, there's no way to get it back unless you've included the message in a backup.

Can my WhatsApp messages be traced by police? ›

Can the police access WhatsApp messages? WhatsApp, along with most other messaging services, uses end-to-end encryption, meaning that the police cannot easily intercept your messages. WhatsApp can, however, in certain circ*mstances be asked to share information with criminal enforcement agencies.

Can police recover permanently deleted messages? ›

Law enforcement may use specialized forensic tools to recover deleted texts from your phone. These tools can sometimes recover data that's been overwritten, but it's not always guaranteed.

Can the government see your WhatsApp messages? ›

Based on the circ*mstances, we may disclose information to law enforcement in response to an emergency disclosure request where we have a good faith reason to believe that the matter involves imminent risk of serious physical injury or death and that WhatsApp may have information to help avert the threat to life.

Top Articles
What are Swaps in Derivatives, What is Swap Trading - India Infoline
15 Facts You Don’t Know About Marie Kondo
Barstool Sports Gif
Truist Bank Near Here
My E Chart Elliot
Trevor Goodwin Obituary St Cloud
Skamania Lodge Groupon
Weeminuche Smoke Signal
Room Background For Zepeto
Western Union Mexico Rate
Don Wallence Auto Sales Vehicles
Math Playground Protractor
Kansas Craigslist Free Stuff
What happens if I deposit a bounced check?
Xm Tennis Channel
Alaska Bücher in der richtigen Reihenfolge
Johnston v. State, 2023 MT 20
Espn Horse Racing Results
8664751911
Dark Chocolate Cherry Vegan Cinnamon Rolls
Walgreens San Pedro And Hildebrand
Talbots.dayforce.com
Axe Throwing Milford Nh
Welcome to GradeBook
Zoe Mintz Adam Duritz
Bjerrum difference plots - Big Chemical Encyclopedia
Xfinity Outage Map Fredericksburg Va
A Man Called Otto Showtimes Near Cinemark University Mall
Urban Dictionary Fov
Walgreens On Bingle And Long Point
Leben in Japan – das muss man wissen - Lernen Sie Sprachen online bei italki
Biografie - Geertjan Lassche
Tracking every 2024 Trade Deadline deal
Publix Christmas Dinner 2022
Fastpitch Softball Pitching Tips for Beginners Part 1 | STACK
60 Second Burger Run Unblocked
Fridley Tsa Precheck
Green Bay Crime Reports Police Fire And Rescue
Tgh Imaging Powered By Tower Wesley Chapel Photos
Truckers Report Forums
Wildfangs Springfield
Mta Bus Forums
Viewfinder Mangabuddy
Is The Nun Based On a True Story?
Walmart Pharmacy Hours: What Time Does The Pharmacy Open and Close?
Thotsbook Com
Coffee County Tag Office Douglas Ga
116 Cubic Inches To Cc
Wild Fork Foods Login
Compete My Workforce
Varsity Competition Results 2022
Latest Posts
Article information

Author: Prof. An Powlowski

Last Updated:

Views: 6381

Rating: 4.3 / 5 (64 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Prof. An Powlowski

Birthday: 1992-09-29

Address: Apt. 994 8891 Orval Hill, Brittnyburgh, AZ 41023-0398

Phone: +26417467956738

Job: District Marketing Strategist

Hobby: Embroidery, Bodybuilding, Motor sports, Amateur radio, Wood carving, Whittling, Air sports

Introduction: My name is Prof. An Powlowski, I am a charming, helpful, attractive, good, graceful, thoughtful, vast person who loves writing and wants to share my knowledge and understanding with you.