HomeSecurityTexas Sues Meta Over WhatsApp Encryption Claims, but Experts Say the Evidence...

Texas Sues Meta Over WhatsApp Encryption Claims, but Experts Say the Evidence Looks Thin

Texas Attorney General Ken Paxton has sued Meta and WhatsApp, accusing the company of misleading users about whether WhatsApp messages are truly protected by end-to-end encryption.

The lawsuit, filed on May 21, 2026, centers on one of WhatsApp’s most important privacy promises: that messages are encrypted on the sender’s device and can be read only by the intended recipient. If that protection works as advertised, WhatsApp and Meta should not be able to read message contents while they move through the service.

Texas alleges that Meta’s public statements about WhatsApp privacy are false and that the company can access users’ communications despite years of claims that messages are private. Meta has rejected the allegations, calling them baseless and saying it will fight the case in court.

The dispute lands in a sensitive area for Meta. WhatsApp has more than 3 billion users, and its reputation depends heavily on the claim that message contents are shielded from the company itself. Meta has also spent years dealing with privacy criticism and regulatory scrutiny, which gives the lawsuit political and public-relations weight even before the technical claims are tested.

What Texas Is Claiming

The complaint says Meta and WhatsApp repeatedly told users that their conversations were private, encrypted, and inaccessible even to the company. Texas argues those promises were deceptive because, according to the state, Meta retained access to WhatsApp communications.

That is a serious allegation because WhatsApp’s encryption claims are not a minor product detail. Since 2016, WhatsApp has promoted end-to-end encryption as a default feature for personal messages. Meta executives have also described WhatsApp as a service where the company cannot see message content.

The lawsuit points to past public statements, including congressional testimony from Meta CEO Mark Zuckerberg in 2018, when he said WhatsApp content was fully encrypted and not visible to Facebook systems. Texas argues that those statements helped create a false impression that WhatsApp conversations were unavailable to Meta.

The case also refers to reporting about a U.S. Commerce Department investigation that was said to have examined whether Meta could view encrypted WhatsApp messages. According to that reporting, an internal email from an agent described preliminary findings that Meta had broad access to WhatsApp message types. The Texas complaint appears to lean heavily on that report rather than presenting a detailed technical demonstration of how WhatsApp encryption is supposedly bypassed.

That distinction matters. A lawsuit can make allegations, but proving that WhatsApp’s encryption is broken or intentionally circumvented would require more than pointing to broad claims about access. It would likely require documents, technical evidence, witness testimony, or analysis showing how Meta could read message contents before or after encryption in a way that contradicts its public promises.

Why Encryption Experts Are Skeptical

Several cryptography and security researchers have questioned the strength of the lawsuit’s factual support. Their skepticism does not amount to a defense of Meta’s broader privacy record. It is focused on a narrower technical question: whether there is concrete evidence that WhatsApp’s message encryption does not work as described.

WhatsApp uses the Signal Protocol, a widely studied encryption system also used by Signal. Security researchers have generally treated the protocol itself as strong. If WhatsApp were secretly bypassing that protection at scale, experts argue, there would likely need to be something visible in the app, its protocol behavior, its key handling, or its infrastructure interactions.

WhatsApp is not open source in the way Signal is, so outside researchers cannot fully audit every part of the application. But the apps can still be reverse-engineered, and researchers have previously studied how WhatsApp implements its cryptographic protocol.

A 2023 technical analysis of WhatsApp found that the service generally behaved consistently with WhatsApp’s encryption claims at the time of testing. The researchers did identify weaknesses, including a group-chat design issue that could let someone with access to Meta infrastructure add a member to a group without normal user approval. The available analysis indicated such a change would be visible to group participants, but that specific visibility claim should be treated cautiously unless independently verified in the current app.

The broader point from that research was not that WhatsApp was perfect. It was that the analysis did not show evidence of global, silent access to message contents. One of the researchers involved, Benjamin Dowling of King’s College London, has said the findings applied to the WhatsApp client available in May 2023 and would not automatically cover later versions.

That caveat is important. Closed-source software can change. A clean technical assessment from 2023 does not prove that every later WhatsApp version works the same way. But it does leave the Texas lawsuit with a burden: if the state is claiming Meta can read messages in full, it will need to show how that happens.

Reported Messages Are A Different Issue

One part of the complaint refers to Meta employees receiving plaintext WhatsApp messages when users report content. That point can be confusing because it sounds, at first, like proof that Meta can read encrypted messages.

It is not necessarily that. When a WhatsApp user reports a message, the reported content can be sent from that user’s device after it has already been decrypted for that user. In that scenario, Meta receiving the message is part of the reporting process, not evidence that Meta can silently intercept every encrypted conversation.

That does not mean users should ignore the privacy implications of reporting tools. It means the mechanism is different from breaking end-to-end encryption. A user choosing to report a message is not the same thing as Meta having routine access to all message contents before a user takes action.

This distinction is likely to matter if the case moves into deeper technical arguments. The state will need to separate ordinary safety and reporting workflows from the larger claim that WhatsApp’s encryption promises are false.

The Lawsuit Arrives In A Political Moment

Paxton filed the lawsuit while running in a Republican primary runoff for the U.S. Senate against incumbent John Cornyn. That timing does not determine whether the claims are true, but it gives the case a political backdrop.

Texas has previously taken aggressive action against Meta over privacy issues, including a major settlement involving facial recognition claims. Paxton has also positioned himself as a frequent legal opponent of large technology companies. The WhatsApp case fits that pattern, but its core allegation is unusually technical.

For users, the immediate takeaway is more limited than the lawsuit’s language may suggest. The complaint raises serious accusations, and Meta will have to answer them in court. At the same time, the public evidence described so far appears thin, and outside encryption experts have not pointed to a known technical finding showing that WhatsApp message contents are globally readable by Meta.

That leaves two separate truths in tension. Meta has a long and well-documented history of privacy controversies, which gives users plenty of reason to scrutinize its products. But skepticism about Meta is not the same as proof that WhatsApp’s end-to-end encryption is fake.

Until new evidence emerges, the lawsuit is best read as an allegation to watch, not as a confirmed technical finding that WhatsApp’s encryption has been defeated.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular

POPULAR TAGS

- Advertisment -