How to Check Linked Devices on WhatsApp, Signal and More in 30 Seconds

End-to-end encryption can't protect you from a device linked to your account. Here's how to check WhatsApp, Signal, Telegram, Messenger, Google and Apple.

Published 2026-09-11

The short version

  • End-to-end encryption protects messages in transit, not the devices at each end. A linked device receives your messages already decrypted.
  • German authorities have reportedly read WhatsApp and Signal chats by linking a desktop or web client to a suspect's account, without breaking any encryption.
  • Every major messaging app and account system has a list of linked devices or active sessions, and most people have never looked at theirs.
  • Checking takes about 30 seconds per app. Remove anything you don't recognise, then change your password and turn on multi-factor authentication.

How police read encrypted chats without breaking encryption

Reporting by netzpolitik, covered by heise online in September 2026, describes a technique that reads WhatsApp and Signal messages without cracking anything. Investigators link the desktop or web version of the app to a suspect's account. The police computer becomes, as far as the app is concerned, just another device the suspect owns. Messages arrive on it in plain text, exactly as they would on the suspect's own laptop.

According to those reports, Germany's federal criminal police have used the method for years, and the customs investigation service made it permanent in August 2025. The legal argument is about scope: linking a device can pull in years of stored contacts and chat history, not just messages sent after a warrant was issued. A senior German court has already pushed back in one case where four months of old chats were taken without proper approval.

The encryption worked perfectly the whole time. That's the point.

What end-to-end encryption does, and doesn't, protect

End-to-end encryption means a message is scrambled on the sender's device and only unscrambled on the recipient's devices. Nobody in between, not the app company, not your internet provider, not someone on the same café wi-fi, can read it along the way.

But "the recipient's devices" is doing a lot of work in that sentence. Most modern messaging apps let one account run on several devices at once: your phone, your laptop, a tablet, a browser tab at work. Each linked device gets its own keys and receives messages already decrypted. If someone else manages to add a device to your account, the app treats it as yours. Encryption is doing its job, and your conversations are fully readable anyway.

Police in Germany needed legal process to do this, and at least one court has checked their work. That oversight is the difference that matters. A controlling ex-partner, a nosy housemate or a scammer who talks you into scanning a QR code doesn't need a warrant, and nobody reviews what they read. For privacy-minded people, that's the realistic threat, and it's the one you can actually check for.

How does a stranger's device get linked to my account?

Usually, in one of a few ordinary ways.

Someone has your unlocked phone for a minute and scans a linking QR code from their own computer. It's quick and leaves little trace unless you go looking.

A scam message asks you to scan a code or enter a "verification" number, and you're really approving a new device.

You once logged in on a shared or work computer, a library PC, or an old laptop you've since sold, and never logged out.

Someone has your account password and there's no second factor to stop them.

None of these involve breaking encryption. All of them show up in your linked-devices list.

How to check linked devices in WhatsApp, Signal, Telegram and Messenger

Menu names shift a little between app versions and between iPhone and Android, but the lists live in roughly the same place in each app. For every entry, ask one question: do I recognise this device, and do I still use it? If not, remove it.

  1. WhatsApp: open Settings (on Android, tap the three-dot menu), then Linked devices. Tap any device you don't recognise or no longer use, and choose Log out.
  2. Signal: open Settings, then Linked devices. Check the names and the "last active" dates, and unlink anything that isn't yours.
  3. Telegram: open Settings, then Devices (sometimes shown as Active sessions). Terminate any session you don't recognise, or use the option to end all other sessions.
  4. Messenger: open the menu or your profile, go to Settings, then the account area (Accounts Centre), then Password and security, and look for "Where you're logged in". Log out of anything unfamiliar.
  5. Repeat on your partner's or teenager's phone together if they'd like a hand. It's a good habit to share.

How to check devices on your Google and Apple accounts

Your messaging apps are only as safe as the accounts behind them. Your Google or Apple account can back up chats, receive codes and reset other passwords, so check those device lists too.

  1. Google: sign in to your Google Account in a browser, open Security, then find "Your devices" and choose Manage all devices. Sign out of anything you don't recognise.
  2. Apple: on an iPhone or iPad, open Settings and tap your name, then scroll down to see the devices signed in with your Apple Account. Tap one to see details and remove it. You can also check the device list by signing in to your Apple Account on the web.
  3. For both, review "recent security activity" or similar alerts for sign-ins you didn't make.

If you find a device you don't recognise and you're worried about someone close to you, think about your safety before removing it, as they may notice. In Australia, 1800RESPECT can help you plan safely.

Found something odd? Lock the door behind you

Removing a device is step one. If an unfamiliar device was there, assume someone had your password or brief access to your phone, and close both gaps.

Change the password on that account and on your email account, since email is the reset button for almost everything else. Turn on multi-factor authentication, preferably with an authenticator app rather than SMS codes. In WhatsApp, turn on two-step verification with a PIN. In Signal, set a registration lock. And put a proper lock on your phone itself, because an unlocked phone is the fastest way to link a new device.

This is where a password manager earns its keep. It creates a long, unique password for every account, so one leak or one shoulder-surfed login doesn't unlock the rest. If you haven't picked one yet, we maintain a separate site, NoSpyPassword, that works through the password managers that hold up under that kind of scrutiny.

It's also worth running your email addresses through Have I Been Pwned, a free service that shows which breaches your details have appeared in. If a password you use turns up there, change it everywhere.

Make it a monthly 30-second habit

Most people have never opened their linked-devices list. Once you've done it, it takes half a minute to repeat. Put a reminder in your calendar for the first of the month, or do it whenever you get a new phone, sell an old laptop or come back from travel.

Encryption is a strong lock. It was never designed to notice a second key hanging on someone else's hook. Checking your devices is how you make sure every key is one you gave out.

Frequently asked questions

Can someone read my WhatsApp messages from another device?

Yes, if that device is linked to your account. Linked devices receive your messages already decrypted. Check Settings, then Linked devices, and log out of anything you don't recognise.

Does end-to-end encryption stop police from reading my messages?

It stops messages being read in transit, but not on a device linked to your account. German authorities have reportedly used linked desktop or web clients to read WhatsApp and Signal chats without breaking the encryption.

How do I see which devices are logged in to my Signal account?

Open Signal's Settings and tap Linked devices. You'll see each device's name and when it was last active, and you can unlink any you don't recognise.

What should I do if I find a device I don't recognise?

Remove it, then change your password, turn on multi-factor authentication or two-step verification, and lock your phone with a strong passcode. If you suspect someone close to you, think about your safety first.

Ready to act on this?

We've reviewed the tools so you don't have to.

Secure your accounts with a password manager →