Morning Overview

The NSA warns one messaging setting can clone your texts to a stranger

The National Security Agency rarely publishes advice aimed at ordinary smartphone owners, so when it flags a specific feature buried in popular messaging apps, it is worth understanding what the warning actually describes. The concern centers on a convenience option — the setting that lets a chat account run on more than one device at a time — and how attackers have quietly abused it to read private conversations from afar.

The danger is not that someone cracks the encryption. It is far simpler. An intruder tricks a target into attaching an extra, attacker-controlled device to the account, so every incoming and outgoing message is copied to a stranger in real time. Once that link is in place, end-to-end encryption offers no protection, because the eavesdropper has become just another authorized endpoint on the conversation.

How the linked-devices feature becomes a wiretap

Modern messaging apps let a single account operate across a phone, a tablet and a desktop through a feature usually called linked or paired devices. Google’s Threat Intelligence Group documented how Russia-aligned operatives exploited that design by planting malicious QR codes — hidden inside phishing pages, fake group invitations and even doctored app instructions — that, once scanned, silently bind a victim’s account to a device the attacker controls. From that moment the victim’s messages sync to both phones simultaneously. Nothing about the encryption is broken; the attacker is simply enrolled as a legitimate second recipient, which is exactly what makes the technique so hard for a target to notice.

What federal guidance actually recommends

Government cybersecurity agencies have folded that lesson into broader mobile advice. The Cybersecurity and Infrastructure Security Agency’s mobile communications best-practice guidance urges higher-risk users to rely only on end-to-end encrypted messaging and to review account and app settings regularly. The NSA’s own mobile device best-practices sheet warns against accepting unsolicited pairing requests and connecting a phone to unknown devices, precisely the behavior the linked-device attack depends on. The consistent message from both agencies is that any feature capable of adding a device is, in the wrong hands, capable of adding an eavesdropper.

Why encryption alone does not save the conversation

End-to-end encryption scrambles a message so that only the sender’s and recipient’s devices can unscramble it. The linked-device trick works because it does not attack that math at all. Instead it expands the set of devices the system treats as the rightful recipient, quietly adding the attacker’s hardware to the circle of trust. That is also why the warning applies broadly rather than to a single app. Signal was the platform named in the government-linked exploits, but the same multi-device architecture exists across mainstream chat services, which means the underlying weakness is a design pattern, not one company’s bug.

The telecom-spying backdrop that raised the stakes

The push toward encrypted apps and careful settings did not happen in isolation. It followed a wave of alarm over foreign surveillance of American communications, including a sprawling intrusion into United States phone networks that officials attributed to state-backed hackers. That episode is a large part of why agencies began urging the public to move sensitive conversations onto end-to-end encrypted apps in the first place. The linked-devices warning is the natural next step: once people adopt encrypted messaging, the remaining soft target is the feature that can silently duplicate an account.

Part of what makes the linked-device warning notable is that it targets a feature most users never think about. Many people set up messaging on a second device once, then never revisit the list, which is precisely the blind spot the technique exploits. Security specialists also point out that the approach scales poorly for defenders and well for attackers: a single successful phishing lure can yield a permanent, silent feed of a target’s conversations, with no malware left on the phone for antivirus tools to detect. That combination of low effort, high payoff and near-invisibility is why agencies elevated a seemingly minor toggle into a formal piece of public guidance.

Steps that close the door

The countermeasures are mundane, which is part of why officials keep repeating them. Users can open the linked-devices or paired-devices menu in their messaging app and remove anything they do not recognize, since a rogue device can otherwise sit unnoticed for weeks. They can treat unexpected QR codes and “verify account” or “link a new device” prompts with suspicion, especially when they arrive through a message or an unfamiliar link. Keeping both the app and the phone’s operating system updated closes known holes that attackers use to deliver those prompts. None of these steps require technical skill, and each one directly interrupts the chain the attackers rely on.

The headline risk is therefore real but preventable. A single setting that many people never open can, if abused, hand a copy of every message to someone else without breaking any code. Checking that list periodically, and staying skeptical of any prompt that asks to link a new device, shuts the door that the intruders have been quietly walking through.

This article was produced with AI assistance and reviewed by the Morning Overview editorial team.


More from Morning Overview