A new class-action lawsuit filed in the U.S. District Court for the Northern District of California alleges Meta misled WhatsApp users by marketing “unbreakable” end-to-end encryption while allegedly retaining and analyzing message content and enabling employee access via internal tools. The complaint—brought by plaintiffs from multiple countries and seeking global class certification—cites unnamed whistleblowers but reportedly provides no technical proof (e.g., logs or code) to substantiate claims that Meta can decrypt or read message contents; Meta spokesperson Andy Stone denied the allegations as “categorically false,” reiterating WhatsApp’s use of the Signal Protocol for end-to-end encryption.
Separately, Google agreed to pay $68 million to settle a class-action lawsuit alleging Google Assistant unlawfully recorded users’ private conversations when inadvertently triggered (e.g., via “Hey Google” misfires) and shared recordings with third parties for advertising-related purposes. The preliminary settlement, also filed in Northern California federal court, still requires judicial approval and applies to purchasers of Google devices dating back to May 2016; Google reportedly settled without admitting wrongdoing. Together, the cases underscore ongoing legal and regulatory exposure tied to consumer privacy representations, data handling, and the gap between product claims and alleged internal access/collection practices.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
After the lawsuit became public, Meta and WhatsApp spokesperson Andy Stone denied the claims, stating WhatsApp uses the audited Signal Protocol and that Meta cannot access users' plaintext messages or encryption keys. The company called the suit frivolous and said it would seek sanctions against plaintiffs' counsel.
Google agreed to pay $68 million to settle a class-action lawsuit alleging Google Assistant illegally recorded users' private conversations and shared them with third parties without consent. The preliminary settlement was filed in federal court in Northern California and still requires judicial approval, with no admission of wrongdoing by Google.
On January 23, 2026, plaintiffs filed a class-action lawsuit in the U.S. District Court for the Northern District of California alleging Meta misled WhatsApp users by claiming messages were protected by unbreakable end-to-end encryption while allegedly storing and analyzing message contents internally.
A Bureau of Industry and Security internal inquiry, reportedly called 'Operation Sourced Encryption,' examined whether Meta could access WhatsApp message content despite its end-to-end encryption claims. The probe was reportedly halted after roughly 10 months, and the agency later said it was not investigating WhatsApp or Meta for export-law violations.
The proposed Google settlement covers people who purchased Google devices starting in May 2016, marking the beginning of the class period tied to allegations that Google Assistant recorded private conversations without consent.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.