Dutch police say they decrypted 258,000+ messages sent using IronChat, which claims to have end-to-end encryption, as part of a money laundering probe
Weakness allowed cops to monitor encrypted messages for some time. — Police in the Netherlands said they decrypted …
Context & Ripple Effects
Dutch police exploiting a weakness in IronChat's claimed end-to-end encryption reads as the opening move in what became a sustained campaign against the encrypted-phone market criminal networks rely on. Two years later, French and Dutch forces ran the same playbook at far larger scale when they infiltrated EncroChat and read millions of messages for months, and Belgian and Dutch units repeated it against Sky ECC after infiltrating it in February 2021.
The throughline matters because these operations compound: by mid-2023, the ~115M communications cracked from EncroChat had been credited with 6,558 arrests, turning a single-service compromise into a multi-year intelligence asset. The 2018 IronChat decryption is where that method — targeting the service's infrastructure rather than breaking the cryptography mathematically — first surfaced publicly.
First-order effects
- IronChat customers, many presumably paying for privacy guarantees the product did not deliver, had their traffic readable by Dutch investigators for an extended period during the money-laundering probe.
- Dutch police demonstrated that a service marketing end-to-end encryption can be defeated at the implementation layer, giving them plaintext access without needing to break the underlying protocol.
Second-order effects
- Organized-crime users respond by migrating between rival encrypted-phone providers, which concentrates demand on services like EncroChat and Sky ECC — precisely the targets Dutch-led teams then infiltrated in subsequent years.
- Each successful compromise raises the operational bar for remaining providers, forcing them to compete on verifiable security rather than marketing claims of end-to-end encryption.
Third-order effects
- If the pattern holds, law enforcement treats niche encrypted-phone networks as standing infiltration targets rather than impenetrable obstacles, making 'criminal-grade' secure messaging a structurally unreliable product category.
- Repeated public failures of claimed end-to-end systems feed pressure on regulators and mainstream messaging vendors to distinguish audited implementations from unaudited ones, since trust in the label alone erodes.
The trend: Law enforcement has shifted from being locked out by end-to-end encryption to systematically compromising the encrypted-phone services organized crime depends on, with each breach compounding the last.