WhatsApp is facing a class-action lawsuit in a US federal court over allegations that its widely promoted end-to-end encryption does not work as advertised. The suit, filed in the US District Court for the Northern District of California, accuses Meta of misleading billions of users about the true privacy of their private messages. The case has drawn sharp responses from Telegram founder Pavel Durov, Tesla CEO Elon Musk, and WhatsApp’s own leadership, intensifying a global debate over digital privacy in 2026.
What the Lawsuit Claims
The complaint was filed on January 26, 2026, in San Francisco by an international group of plaintiffs from India, Brazil, Australia, Mexico, and South Africa. At its core, the lawsuit alleges that Meta “stores, analyzes, and can access virtually all of WhatsApp users’ purportedly private communications,” a direct contradiction of the platform’s central privacy promise.
The 51-page filing describes an internal process that Meta employees can allegedly use to bypass the encryption layer. According to the complaint, an engineer can submit a request through the company’s internal systems, and once approved, a widget becomes available that allows real-time viewing of a user’s messages based on their account ID. The plaintiffs cite unnamed whistleblowers as the source of these claims.
The lawsuit also alleges that Meta retains the ability to decrypt messages for data analysis and internal monitoring, and that deleted messages may still be accessible to company staff. However, the complaint does not include any independently verified technical evidence, code samples, or network logs to support these assertions.

Durov Calls WhatsApp Insecure, Cites “Multiple Attack Vectors”
Telegram CEO Pavel Durov responded to the lawsuit with pointed criticism of WhatsApp’s security model. Writing on X, he stated that believing WhatsApp is secure in 2026 would require being “braindead,” and claimed that Telegram’s own analysis of WhatsApp’s encryption implementation had revealed multiple attack vectors. He did not publicly disclose the specific technical details behind those claims.
Durov’s statements drew significant attention, given that Telegram competes directly with WhatsApp in the global messaging market. Critics noted that his remarks lacked the accompanying technical documentation needed for independent verification.
This is not the first time Durov has taken aim at WhatsApp. The Telegram founder has previously argued that the platform’s metadata collection poses privacy risks. This metadata includes IP addresses, device information, and usage patterns. These risks exist independent of whether message content itself is encrypted. You can read more about how Meta’s encryption dispute unfolded in our earlier coverage.
— Elon Musk (@elonmusk) January 27, 2026 Elon Musk Joins the Debate, Promotes X Chat
Elon Musk amplified the controversy when he posted on X shortly after the lawsuit became public. He wrote that WhatsApp is “not secure” and added that “even Signal is questionable.” He directed users to X Chat, the messaging product built into his own social media platform, as a more trustworthy alternative.
Musk’s intervention drew criticism from privacy researchers. They pointed out that X Chat has not undergone the independent security audits that have validated WhatsApp’s use of the Signal protocol. His comments nonetheless accelerated the public conversation around encryption transparency and corporate accountability.
Musk has previously used his platform to promote X-based products over rival services. His involvement in this dispute fits a broader pattern in which tech executives use high-profile security controversies to advance their own competing products. For context on how AI and data privacy concerns are increasingly intersecting, see our report on how artificial intelligence actually works and the data implications.
Meta Calls Lawsuit “Frivolous” and “A Work of Fiction”
WhatsApp moved quickly to reject the allegations. Will Cathcart, the head of WhatsApp at Meta, described the lawsuit as entirely false and “headline-seeking.” He emphasized that WhatsApp cannot read user messages because encryption keys stay on users’ devices. Meta has no access to them under normal operating conditions.
Cathcart also noted that the same law firm filed the suit. This firm previously represented NSO Group, the Israeli surveillance company. Its Pegasus spyware targeted journalists, lawyers, and government officials. He characterized the legal action as lacking merit.
Meta spokesperson Andy Stone issued a formal statement to Bloomberg, calling any claim that WhatsApp messages are unencrypted “categorically false and absurd.” Stone confirmed that WhatsApp has used the Signal protocol for end-to-end encryption for over a decade, and that the company plans to seek legal sanctions against the plaintiffs’ counsel.
What Encryption Experts Say
Independent cryptographers have largely pushed back on the technical framing of the lawsuit. Matthew Green, a widely respected cryptography professor, analyzed the case publicly. He noted that the complaint relies on insider assertions rather than any documented technical vulnerability. The lawsuit does not reference known exploits, published research, or security audit failures.
Independent auditors have reviewed WhatsApp’s implementation of the Signal protocol. As a result, the security research community broadly accepts it as cryptographically sound for protecting message content. However, what the platform does collect, and what has drawn legitimate criticism in the past, is metadata. Specifically, this includes device identifiers, IP addresses, contact lists, and usage behavior. Notably, end-to-end encryption protects none of that. Moreover, the platform routinely shares this data with Meta’s advertising and analytics infrastructure.
The distinction matters. Critics of WhatsApp’s privacy model have a legitimate case on metadata grounds. The lawsuit claims that Meta can actively read the content of encrypted messages. However, this claim remains technically unsubstantiated as of the time of publication.
A Pivotal Moment for Messaging Privacy
The lawsuit arrives at a sensitive time for WhatsApp. In August 2025, Russia’s telecommunications regulator restricted voice calls on both WhatsApp and Telegram. The regulator cited concerns about misuse by bad actors. Russian state media subsequently reported in January 2026 that authorities expect a full ban on WhatsApp before the end of the year.
At the European level, the EU has classified WhatsApp as a “very large online platform” under its Digital Services Act. This designation places it under the bloc’s most stringent content governance standards. The classification applies to its public channels, not to private messages.
The case remains in its earliest stages and has not yet reached a court test. No party has made public any technical findings supporting the plaintiffs’ central claims. Nevertheless, it has prompted fresh questions about encryption guarantees. Platforms offer these guarantees while simultaneously operating large advertising businesses.
For users concerned about messaging security, independent experts continue to recommend manually enabling encrypted backups in WhatsApp. The app does not enable them by default. Those requiring stronger metadata protections may consider platforms that collect less usage data by design. The ongoing debate around data privacy in messaging apps is closely tied to broader questions about AI training and surveillance issues we have covered in depth in our analysis of which AI models best respect user privacy in 2026 and in our reporting on AI accountability in public discourse.
The case will proceed through the courts over the coming months. Meta has signaled an aggressive legal defense.