Court documents reveal Canadian police have had BlackBerry's global encryption key since 2010
Exclusive: Canadian Police Obtained BlackBerry's Global Decryption Key — A high-level surveillance probe of Montreal's criminal underworld shows that Canada's federal policing agency …
Context & Ripple Effects
Two months before these court documents surfaced, BlackBerry publicly dismissed the suggestion that the Netherlands Forensic Institute had cracked its device encryption, blaming user error and third-party apps. The filings tell a different story: Canada's federal policing agency did not need a technical break at all — it obtained the company's global encryption key back in 2010.
The scale is what makes it significant — over a million decrypted messages between 2010 and 2012 in a surveillance probe of Montreal's criminal underworld. It also predates and foreshadows a decade of law-enforcement wins against criminal messaging platforms, from the FBI's Phantom Secure arrest to Belgium's Sky ECC infiltration, recasting those as parts of a standing playbook rather than isolated technical feats.
First-order effects
- BlackBerry's January denial is directly undermined: while it attributed forensic access to user error and third-party apps, its own government had held the global decryption key for six years, leaving the company defending an encryption reputation its home country's police had already compromised.
- Every prosecution built on the 2010–2012 Montreal intercepts is validated retroactively, while the source of that access — a vendor-controlled master key — is now public record.
Second-order effects
- Criminal users who paid a premium for BlackBerry's perceived impenetrability will migrate to bespoke hardened devices — exactly the market the FBI struck when it arrested the CEO of Phantom Secure, which stripped microphones and cameras from BlackBerrys and routed traffic through overseas servers.
- Police gain a reusable template they have since applied to successors: Belgian forces infiltrated Sky ECC and captured a billion messages, meaning each migration by criminals hands law enforcement a fresh target using the same platform-infiltration approach.
Third-order effects
- A vendor-held global key makes any 'secure' messaging brand a single point of failure; if the pattern holds, buyers of encrypted communications will judge products not on encryption claims but on whether any central party — company or state — possesses the keys.
- The disclosure hardens the exceptional-access debate already visible in the United States, where 2,000 law enforcement agencies including 49 of the 50 largest departments hold tools to open locked phones — pressure that will shape what regulators expect encryption vendors to disclose and retain.
The trend: Law enforcement is shifting from case-by-case code-breaking to systemic platform access — acquiring vendor keys and infiltrating whole networks — making centrally held encryption the recurring weak point in secure communications.