Security1 distinct publisher3 min readUpdated
Computer Weekly says a Czech firm rehacked France's EncroChat implant and found GitHub exploit code for Bad Binder, an Android bug unpatched in 2.5 billion phones. Lawyers expect a stalled UK case to restart.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Computer Weekly, working with the Sussex Centre for Law and Technology, has published the first detailed account of how French state hackers broke into the EncroChat cryptophone network in 2020, based on a report by Czech security company Invasys that rehacked the French hack [1][2]. The finding that matters for every unresolved EncroChat case is this: the French malware, which France has insisted is a national security secret, was built on exploit code copied from the code-sharing site GitHub [2][3].
The vulnerability was Bad Binder, an Android flaw first spotted in 2017 and left unpatched for two years across an estimated 2.5 billion phones [4][5]. It gave an attacker complete control of an infected handset, including the ability to copy or alter a user's data, programs and files [6]. Felix Freiling, a computer forensics professor at Friedrich-Alexander-Universitaet in Germany, told Computer Weekly the bug code uncovered by Invasys "looks like a student project", apparently including exploit code copied from the internet [7]. He also called the Czech work "unique [and] an impressive breakthrough" that "answers a lot of questions" [8].
The report describes an implant that was poorly written, failed repeatedly, and lacked elementary countermeasures against detection [9]. Reverse engineering of the recovered code shows messages being "hooked" inside the targeted handset and copied almost immediately to police investigators [10]. The Czech rehack also produced digital fingerprints matching the French evidence distributed to police forces across Europe, which the investigation treats as proof of how messages were copied [11].
That is the point of legal contact. In Britain, thousands of cases have been judged and sentenced with no explanation of how the data was obtained, because the French authorities stipulated that the method was a matter of national security [12]. The Investigatory Powers Tribunal case testing the legality of the police tactics has been adjourned for more than two years, waiting for a finding on how the hack was actually carried out [13]. British lawyers told Computer Weekly the exposure of the method is likely to restart it [14], and that if the full facts had been available when trials began in 2020, it would be "open to question whether courts were properly informed" [15].
Matthew Ryder KC, lead counsel in the UK's first EncroChat trial, called the investigation a "landmark breakthrough" and said it "is bound to have consequences for the ongoing legal argument and on legal principles relating to interception and computer interference" [16]. The Dutch criminal lawyer Justus Reisinger, part of the European defence team contesting the evidence, said the material is "vital for EncroChat trials and appeals" and that defence teams have been asking for it for six years [17].
One arithmetic detail deserves scrutiny rather than assertion. If Bad Binder was spotted in 2017 and went unpatched for two years, the window of mass exposure closes around 2019, before the 2020 interception [18]. Which handsets in the EncroChat fleet were still carrying the unpatched flaw, and why, is not settled by the material published so far.
Watch whether the tribunal relists the adjourned case and on what disclosure terms, whether Invasys's findings are put before courts in the Netherlands as well as the UK, and whether French authorities maintain the national security stipulation now that the underlying exploit is documented as public code [3][12][13].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Felix Freiling, computer forensics and malware expert and professor at Friedrich-Alexander-Universitaet, said the bug code uncovered by Czech cyber security company Invasys 'looks like a student project', including apparently having copied exploit code from the internet.
Freiling described the report as 'unique [and] an impressive breakthrough' and said rehacking the French hack 'answers a lot of questions' and was 'a big step to better understanding'.
The Czech report, combined with expert analysis of intercepted material, revealed that the French implant relied on Bad Binder and that its code was poorly written, prone to repeated failure, and lacked elementary countermeasures to avoid detection.
Matthew Ryder KC, the leading lawyer in the UK's first EncroChat trial, called the investigation a 'landmark breakthrough' and said it 'suggests that after six years, we may finally know the details of the EncroChat interception by the French authorities' and 'is bound to have consequences for the ongoing legal argument and on legal principles relating to interception and computer interference'.
Computer Weekly reveals for the first time how French cyber spies hacked EncroChat phones, used by organised crime groups, in 2020; the investigation is by Computer Weekly and the Sussex Centre for Law and Technology (SCLT).
A Czech spyware company, Invasys, rehacked the French hack; its report was obtained by Computer Weekly.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-publisher, with the primary document unpublished
The technical account is specific (reverse-engineered implant code, hooking behaviour, fingerprint matching) and is backed by named on-record experts, which lifts it well above assertion. It is nonetheless one publisher's investigation; the Invasys report it rests on is not published, no adversarial or official response is included, and the patch-timeline arithmetic is left unreconciled.
Technique deployed at scale; legal consequences still pending
The underlying operation is not prospective: the implant was reportedly deployed against tens of thousands of phones, exploiting a bug present in about 2.5 billion handsets, and its output already underpins thousands of concluded UK prosecutions plus European appeals. What has not yet happened is uptake of the new disclosure by courts — the tribunal restart is an expectation, not an event.
Mildly overstated framing on an otherwise substantive finding
Headline framing ('national security secret was exploit code sitting on GitHub', 'landmark breakthrough', 'proving how messages had been copied') runs slightly ahead of what a reader can verify from one publisher with the source report withheld and no official response. The gap is small rather than large because the specifics, named-expert corroboration and documented procedural history are real and checkable in outline.
Visible interests on nearly every voice in the story
The disclosure chain carries stakes that the source names but does not interrogate: the reporting is a joint Computer Weekly/SCLT campaign-style investigation, the analysis originates with Invasys, a commercial spyware firm with reason to advertise that it can reverse a state implant, and the legal commentary comes from defence-side lawyers (Ryder KC, Reisinger) actively litigating EncroChat evidence. Only Freiling appears as a comparatively disinterested academic reviewer, and French and UK authorities are absent.
Moderate: coherent and named-source backed, but unreplicated
Confidence sits mid-range. The narrative is internally consistent, richly specific and anchored by identifiable experts and a documented tribunal history, which argues against fabrication. Against that: one publisher, one unpublished primary document, no rebuttal from the states involved, an unresolved timeline detail, and interested parties supplying most of the interpretation.
build
Grok 4.6 lands in Copilot two days after launch, and the model picker becomes a procurement problem1 distinct publisher
product
The AI-wrote-it claim died in eight hours. The Actions injection pattern did not.1 distinct publisher
build
Geofencing beats GPS polling on power, then loses to the OEM battery optimiser1 distinct publisher
security
Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026