EncroChat was a Europe-based
communications network and
service provider that offered modified smartphones allowing encrypted communication among subscribers. It was used primarily by
organized crime
Organized crime (or organised crime) is a category of transnational, national, or local groupings of highly centralized enterprises run by criminals to engage in illegal activity, most commonly for profit. While organized crime is generally th ...
members to plan criminal activities. Police infiltrated the network between at least March and June 2020 during a Europe-wide investigation. An unidentified source associated with EncroChat announced on the night of 12–13 June 2020 that the company would cease operations because of the police operation.
The service had around 60,000 subscribers at the time of its closure.
As a result of police being able to read unencrypted EncroChat messages, at least 1,000 arrests had been made across Europe as of 22 December 2020.
Background
EncroChat handsets emerged in 2016 as a replacement for a previously disabled
end-to-end encrypted service. The company had revealed on 31 December 2015 the Version 115 of EncroChat OS, which appears to be the first public release of their
operating system
An operating system (OS) is system software that manages computer hardware, software resources, and provides common services for computer programs.
Time-sharing operating systems schedule tasks for efficient use of the system and may also in ...
. The earliest version of the company's website archived by the
Wayback Machine
The Wayback Machine is a digital archive of the World Wide Web founded by the Internet Archive, a nonprofit based in San Francisco, California. Created in 1996 and launched to the public in 2001, it allows the user to go "back in time" and see ...
dates to 23 September 2015.
According to a May 2019 report by the ''
Gloucester Citizen'', EncroChat was originally developed for "celebrities who feared their phone conversations were being hacked".
In the 2015 murder of English mobster
Paul Massey, the killers used a similar service providing encrypted
BlackBerry
The blackberry is an edible fruit produced by many species in the genus ''Rubus'' in the family Rosaceae, hybrids among these species within the subgenus ''Rubus'', and hybrids between the subgenera ''Rubus'' and ''Idaeobatus''. The taxonomy of ...
phones based on
PGP
PGP or Pgp may refer to:
Science and technology
* P-glycoprotein, a type of protein
* Pelvic girdle pain, a pregnancy discomfort
* Personal Genome Project, to sequence genomes and medical records
* Pretty Good Privacy, a computer program for the ...
. After the Dutch and Canadian police compromised their server in 2016, EncroChat turned into a popular alternative among criminals for its security-oriented services in 2017–2018.
The founders and owners of EncroChat are not known. According to Dutch journalist Jan Meeus, a Dutch organized crime gang was involved and financed the developers.
Through a marketing strategy of "relentless online advertising",
EncroChat rapidly expanded during its four and a half years of existence, benefiting from the closure of its competitors PGP Safe and
Ennetcom
Ennetcom was a Netherlands based communications network and service provider.
The company was based in the Netherlands as were most of its customers, but most of the company servers were based in Canada. Danny Manupassa, the company owner, was ar ...
.
The network eventually reached an estimated 60,000 total subscribers at the time of its closure in June 2020.
According to the French
National Gendarmerie, 90 percent of subscribers were criminals, and the British
National Crime Agency (NCA) said it found no evidence of non-criminals using it.
EncroChat first came to the attention of the media when it was revealed that high-profile criminals
Mark Fellows and Steven Boyle had been using the encrypted devices to communicate during the May 2018 gangland murder of
John Kinsella in
Rainhill
Rainhill is a village and civil parish within the Metropolitan Borough of St Helens, in Merseyside, England. The population of the civil parish taken at the 2011 census was 10,853.
Historically part of Lancashire, Rainhill was formerly a townsh ...
.
The service resurfaced in the media during the summer of 2020 after law enforcement announced that they had infiltrated the encrypted network and investigative journalist Joseph Cox, who had been reviewing EncroChat for months, published an exposé in ''
Vice Motherboard''.
Functionality and services
The EncroChat service was available for handsets called "carbon units", whose
GPS
The Global Positioning System (GPS), originally Navstar GPS, is a Radionavigation-satellite service, satellite-based radionavigation system owned by the United States government and operated by the United States Space Force. It is one of t ...
, camera and microphone functions were disabled by the company for privacy reasons.
Devices were sold with pre-installed applications, including EncroChat, an
OTR-based messaging app which routed conversations through a central server based in France, EncroTalk, a
ZRTP-based voice call service, and EncroNotes, which allowed users to write encrypted private notes.
They generally used modified
Android
Android may refer to:
Science and technology
* Android (robot), a humanoid robot or synthetic organism designed to imitate a human
* Android (operating system), Google's mobile operating system
** Bugdroid, a Google mascot sometimes referred to ...
devices, with some models based on the
BQ Aquaris X2
BQ (former name: Mundo Reader) was a Spanish company brand of user electronics devices, such as smartphones, tablets, e-readers and 3D printers among other products.
Among BQ's most notable products are the first AndroidOne mobile phone in Eur ...
phone hardware,
others on Samsung devices,
and sometimes on non-Android
BlackBerry
The blackberry is an edible fruit produced by many species in the genus ''Rubus'' in the family Rosaceae, hybrids among these species within the subgenus ''Rubus'', and hybrids between the subgenera ''Rubus'' and ''Idaeobatus''. The taxonomy of ...
mobile phones.
Devices with EncroChat were able to boot in two modes. When only the power button was pressed to turn the handset on, they booted into a dummy Android home screen. But when the handset was switched on by pressing the power button together with the volume button, the phone booted to a secret, encrypted partition which facilitated secret communication via EncroChat's French servers.
A "panic button" feature was available, where a certain PIN inputted to the device via the unlock screen would erase all data on the phone.
According to journalist Jurre van Bergen, the IP of EncroChat's server points to French web hosting company
OVH
OVH, legally OVH Groupe SAS, is a French cloud computing company which offers VPS, dedicated servers and other web services. As of 2016 OVH owned the world's largest data center in surface area. As of 2019, it was the largest hosting provide ...
.
EncroChat's SIM provider was the Dutch telecommunications firm
KPN.
EncroChat devices were particularly popular in Europe, although they were also sold in the Middle East and elsewhere in the world. One source told ''Vice Motherboard'' that they became the "industry standard" among criminals.
They were reported in July 2020 to cost €1,000 (£900) each, then €1,500 (£1,350) for a six-month contract to use EncroChat's solution.
EncroChat's website says that the firm had resellers in
Amsterdam
Amsterdam ( , , , lit. ''The Dam on the River Amstel'') is the Capital of the Netherlands, capital and Municipalities of the Netherlands, most populous city of the Netherlands, with The Hague being the seat of government. It has a population ...
,
Rotterdam
Rotterdam ( , , , lit. ''The Dam on the River Rotte'') is the second largest city and municipality in the Netherlands. It is in the province of South Holland, part of the North Sea mouth of the Rhine–Meuse–Scheldt delta, via the ''"N ...
,
Madrid
Madrid ( , ) is the capital and most populous city of Spain. The city has almost 3.4 million inhabitants and a metropolitan area population of approximately 6.7 million. It is the second-largest city in the European Union (EU), and ...
and
Dubai
Dubai (, ; ar, دبي, translit=Dubayy, , ) is the most populous city in the United Arab Emirates (UAE) and the capital of the Emirate of Dubai, the most populated of the 7 emirates of the United Arab Emirates.The Government and Politics of ...
, although Cox describes EncroChat as a "highly secretive" firm which "does not operate like a normal technology company".
The phones were reportedly bought via a physical transaction which "looked like a drug deal",
and at least one case involves an ex-military operative selling devices in
Northern Ireland
Northern Ireland ( ga, Tuaisceart Éireann ; sco, label= Ulster-Scots, Norlin Airlann) is a part of the United Kingdom, situated in the north-east of the island of Ireland, that is variously described as a country, province or region. Nort ...
.
Infiltration
The EncroChat encrypted messaging service and the related customized phones were discovered by the
French National Gendarmerie
The National Gendarmerie (french: Gendarmerie nationale, ) is one of two national law enforcement forces of France, along with the National Police (France), National Police. The Gendarmerie is a branch of the French Armed Forces placed under the ...
in 2017 when conducting operations against organized crime gangs.
At the time of the
Fellows and Boyle trial in December 2018, the NCA struggled to crack the lock screen passcode, as anything was wiped out after a set number of attempts.
The investigation accelerated in early 2019 after receiving EU funding.
At the end of January 2020, a judge in
Lille
Lille ( , ; nl, Rijsel ; pcd, Lile; vls, Rysel) is a city in the northern part of France, in French Flanders. On the river Deûle, near France's border with Belgium, it is the capital of the Hauts-de-France Regions of France, region, the Pref ...
, France, authorized the infiltration of the EncroChat servers. Intelligence and technical collaboration between the NCA, the National Gendarmerie and Dutch police culminated in gaining access to messages after the National Gendarmerie put a "technical tool" on EncroChat's servers in France.
The
malware
Malware (a portmanteau for ''malicious software'') is any software intentionally designed to cause disruption to a computer, server, client, or computer network, leak private information, gain unauthorized access to information or systems, depri ...
allowed them to read messages before they were sent and record lock screen passwords. Messages could be read by law enforcement beginning in April.
EncroChat estimated that around 50 percent of devices in Europe were affected in June 2020.
The National Gendarmerie formed a special unit to investigate the hacked information on 15 March 2020, then signed an agreement with the
Dutch Police
National Police Corps ( nl, Korps Nationale Politie), colloquially in English as Dutch National Police or National Police Force, is divided in ten regional units, a central unit, the police academy, police services center, and national control ...
to form a
joint investigation team Joint investigation teams (JIT) are law enforcement and judicial teams set up jointly by EU national investigative agencies to handle cross-border crime. Joint investigation teams coordinate the investigations and prosecutions conducted in parallel ...
(JIT) on 10 April, co-operating through
Eurojust with the support of
Europol.
The data was distributed by the JIT to other European partners, including the UK, Sweden and Norway.
The NCA began to receive information about the content of messages on 1 April 2020,
then started to build data analysis technology to automatically "identify and locate offenders by analysing millions of messages and hundreds of thousands of images".
The chief of the Dutch National Police Force, , compared the malware to "sitting at the table where criminals were chatting among themselves".
In May 2020, the wipe feature was disabled at distance by law enforcement in some units. The company initially tried to push an update in response to what was initially regarded as a bug, but the devices were struck again by malware altering lock screen passwords.
On the night of 12–13 June 2020, once EncroChat suspected the infiltration by law enforcement had occurred,
users received a secret message:
A few days later, an "email address long associated with EncroChat" informed ''Vice Motherboard'' that the service was shutting down permanently "following several attacks carried out by a foreign organization that seems to originate in the UK"; Cox publicly disclosed excerpts of the email on 22 June.
Europol and the National Crime Agency refused to comment at the time.
The identity of the persons in charge of EncroChat has not been revealed as of 3 July 2020.
Impact
European joint investigation team
The Europol-supported JIT, code named ''Emma 95'' in France and ''26Lemont'' in the Netherlands, allowed the gathering in real time of millions of messages between suspects. Information was also shared with law enforcement in several countries that were not participating in the JIT, including the UK, Sweden and Norway.
The Dutch police arrested more than 100 suspects and seized more than 8 tonnes of
cocaine
Cocaine (from , from , ultimately from Quechuan languages, Quechua: ''kúka'') is a central nervous system (CNS) stimulant mainly recreational drug use, used recreationally for its euphoria, euphoric effects. It is primarily obtained from t ...
, around 1.2 tonnes of
crystal methamphetamine
Methamphetamine (contracted from ) is a potent central nervous system (CNS) stimulant that is mainly used as a recreational drug and less commonly as a second-line treatment for attention deficit hyperactivity disorder and obesity. Metham ...
, 19 synthetic drug laboratories, dozens of guns and luxury cars, and around €20 million in cash.
On 22 June 2020 in a property in Rotterdam, authorities found
police uniform
A uniform is a variety of clothing worn by members of an organization while participating in that organization's activity. Modern uniforms are most often worn by armed forces and paramilitary organizations such as police, emergency services, se ...
s,
stolen vehicles, 25
firearm
A firearm is any type of gun designed to be readily carried and used by an individual. The term is legally defined further in different countries (see Legal definitions).
The first firearms originated in 10th-century China, when bamboo tubes ...
s, and 25 kg of
drug
A drug is any chemical substance that causes a change in an organism's physiology or psychology when consumed. Drugs are typically distinguished from food and substances that provide nutritional support. Consumption of drugs can be via insuffla ...
s in a different property.
On 22 June 2020, the Dutch police also discovered a "
" in a warehouse near the town of about 7.15 km east of
Bergen op Zoom. The facility, which was still under construction when discovered, consisted of seven cells made out of sound-proofed shipping containers;
torture tools were found including a
dentist's chair,
hedge trimmers,
scalpels and
pliers. The place was nicknamed by criminals the "treatment room" or the "ebi", in reference to
Extra Beveiligde Inrichting (EBI), a Dutch maximum security prison.
EncroChat probes in Ireland have left criminals scrambling for cover. €1.1 million worth of cocaine was seized in an Amsterdam flat, and €5.5 million of cannabis in a trailer in
County Wexford
County Wexford ( ga, Contae Loch Garman) is a county in Ireland. It is in the province of Leinster and is part of the Southern Region. Named after the town of Wexford, it was based on the historic Gaelic territory of Hy Kinsella (''Uí Ceinns ...
, both belonging to Irish gangs.
Prominent Irish gang boss
Daniel Kinahan
Daniel Joseph Kinahan (born 25 June 1977) is an Irish boxing promoter and suspected crime boss. He has been named by the High Court of Ireland as a senior figure in organised crime on a global scale. The Criminal Assets Bureau has stated he "c ...
was reported to have fled his "safe-haven" of Dubai on 9 July 2020.
Arrests were also made in Sweden.
French authorities declined to disclose information publicly about the arrests in July 2020.
United Kingdom
Operation Venetic
Operation Venetic was a British national response initiated by the
National Crime Agency (NCA). In June 2020, EncroChat had 10,000 users in the UK alone.
As a result of the infiltration of the network, UK police arrested 746 individuals, including major crime bosses, intercepted two tonnes of drugs (with a street value at the time in excess of £100 million), seized £54 million in cash, as well as weapons, including
submachine gun
A submachine gun (SMG) is a magazine-fed, automatic carbine designed to fire handgun cartridges. The term "submachine gun" was coined by John T. Thompson, the inventor of the Thompson submachine gun, to describe its design concept as an autom ...
s,
handgun
A handgun is a short- barrelled gun, typically a firearm, that is designed to be usable with only one hand. It is distinguished from a long gun (i.e. rifle, shotgun or machine gun, etc.), which needs to be held by both hands and also braced ...
s,
grenade
A grenade is an explosive weapon typically thrown by hand (also called hand grenade), but can also refer to a shell (explosive projectile) shot from the muzzle of a rifle (as a rifle grenade) or a grenade launcher. A modern hand grenade genera ...
s, an
AK-47 assault rifle, and more than 1,800 rounds of ammunition.
[ More than 28 million tablets of the sedative ]Etizolam
Etizolam (marketed under many brand names) is a thienodiazepine derivative which is a benzodiazepine analog. The etizolam molecule differs from a benzodiazepine in that the benzene ring has been replaced by a thiophene ring and triazole ring ha ...
were found in a factory in Rochester, Kent
Rochester ( ) is a town in the unitary authority of Medway, in Kent, England. It is at the lowest bridging point of the River Medway, about from London. The town forms a conurbation with neighbouring towns Chatham, Rainham, Strood and Gillin ...
. Additionally, 354 kg of cocaine were seized by the Eastern unit in Essex
Essex () is a county in the East of England. One of the home counties, it borders Suffolk and Cambridgeshire to the north, the North Sea to the east, Hertfordshire to the west, Kent across the estuary of the River Thames to the south, and G ...
and East Anglia
East Anglia is an area in the East of England, often defined as including the counties of Norfolk, Suffolk and Cambridgeshire. The name derives from the Anglo-Saxon kingdom of the East Angles, a people whose name originated in Anglia, in ...
, and 233 kg by the West Midlands
West or Occident is one of the four cardinal directions or points of the compass. It is the opposite direction from east and is the direction in which the Sun sets on the Earth.
Etymology
The word "west" is a Germanic word passed into some ...
unit. Police Scotland
Police Scotland ( gd, Poileas Alba), officially the Police Service of Scotland (), is the national police force of Scotland. It was formed in 2013, through the merging of eight regional police forces in Scotland, as well as the specialist service ...
seized 164 kg of cocaine, £200,000 of cannabis
''Cannabis'' () is a genus of flowering plants in the family Cannabaceae. The number of species within the genus is disputed. Three species may be recognized: ''Cannabis sativa'', '' C. indica'', and '' C. ruderalis''. Alternatively ...
and £750,000 in cash in several busts. In May 2020, police found two suitcases containing £1.1 million in Sheffield
Sheffield is a city status in the United Kingdom, city in South Yorkshire, England, whose name derives from the River Sheaf which runs through it. The city serves as the administrative centre of the City of Sheffield. It is Historic counties o ...
.
Four people have been charged by the NCA with conspiracy to murder as of 8 July 2020. British police claim to have prevented up to 200 gangland killings, although '' Vice News'' notes that "the number of homicides linked to high level organised crime—as opposed to street gangs—in this county is relatively low". Two corrupt law enforcement officers were also arrested as a result of the operation.
On 22 December 2020, Thomas Maher was jailed for 14 years and 8 months at Liverpool Crown Court
The Queen Elizabeth II Law Courts, in Derby Square, Liverpool, are operated by His Majesty's Courts and Tribunals Service. The building is used by the Crown Court, the Magistrates' Court, Liverpool District Probate Registry and the Liverpool Yout ...
. He had pleaded guilty to four counts of conspiracy to commit a crime at an earlier hearing.[ He was involved in conspiracies to smuggle about £1.5 million (€1.6m) of cocaine from the Netherlands to ]Ireland
Ireland ( ; ga, Éire ; Ulster Scots dialect, Ulster-Scots: ) is an island in the Atlantic Ocean, North Atlantic Ocean, in Northwestern Europe, north-western Europe. It is separated from Great Britain to its east by the North Channel (Grea ...
as well as laundering about £1 million (€1.09m) in cash between Ireland and the Netherlands.[ He had used two EncroChat phones, which were not recovered, using the aliases "Satirical" and "Snacker".][
In March 2022 the first murder plot convictions due to EncroChat were secured, against Paul Fontaine and Frankie Sinclair. By that time the NCA said that 2,631 people had been arrested in the UK as part of Operation Venetic; 1,384 had been charged, 260 convicted and over five and a half tons of class A drugs, 165 weapons and £75m in criminal cash had been seized.
]
Operation Eternal
Operation Eternal, the London Metropolitan Police
The Metropolitan Police Service (MPS), formerly and still commonly known as the Metropolitan Police (and informally as the Met Police, the Met, Scotland Yard, or the Yard), is the territorial police force responsible for law enforcement and ...
arm of the EncroChat operation, described itself as "the most significant operation the Metropolitan Police Service has ever launched against serious and organised crime". Around 1,400 EncroChat users were based in London at the time of its closure in June 2020. The Metropolitan Police seized more than £13.4 million in cash, 16 firearms, more than 500 rounds of ammunition, 620 kg of Class A drugs
These drugs are known in the UK as ''controlled drugs'', because this is the term by which the act itself refers to them. In more general terms, however, many of these drugs are also controlled by the Medicines Act 1968, there are many other drug ...
, and arrested 171 people. As of 8 July 2020, 113 of them have been charged; 88 face charges of conspiracy to supply Class A drugs, and 16 have been charged with firearms offences.
In September 2020 nine people were arrested after raids in Brighton
Brighton () is a seaside resort and one of the two main areas of the City of Brighton and Hove in the county of East Sussex, England. It is located south of London.
Archaeological evidence of settlement in the area dates back to the Bronze A ...
, Portslade
Portslade is a western suburb of the city of Brighton and Hove, England. Portslade Village, the original settlement a mile inland to the north, was built up in the 16th century. The arrival of the railway from Brighton in 1840 encouraged rapid de ...
, Kent
Kent is a county in South East England and one of the home counties. It borders Greater London to the north-west, Surrey to the west and East Sussex to the south-west, and Essex to the north across the estuary of the River Thames; it faces ...
, and London
London is the capital and largest city of England and the United Kingdom, with a population of just under 9 million. It stands on the River Thames in south-east England at the head of a estuary down to the North Sea, and has been a majo ...
linked to Operation Eternal. Three men were arrested in Brighton and Portslade, five men and a woman in Kent and London.[ They were arrested for a variety of charges, including conspiracy to supply cocaine.][ Police seized 10 kg of Class A drugs and £60,000.][
]
Convictions
On 21 May 2021, Carl Stewart of Gem Street, Liverpool
Liverpool is a city and metropolitan borough in Merseyside, England. With a population of in 2019, it is the 10th largest English district by population and its metropolitan area is the fifth largest in the United Kingdom, with a popul ...
was sentenced to 13 years and 6 months at Liverpool Crown Court after pleading guilty to attempting to smuggle cocaine, heroin
Heroin, also known as diacetylmorphine and diamorphine among other names, is a potent opioid mainly used as a recreational drug for its euphoric effects. Medical grade diamorphine is used as a pure hydrochloride salt. Various white and brow ...
, MDMA
3,4-Methylenedioxymethamphetamine (MDMA), commonly seen in Tablet (pharmacy), tablet form (ecstasy) and crystal form (molly or mandy), is a potent empathogen–entactogen with stimulant properties primarily used for Recreational dru ...
and ketamine
Ketamine is a dissociative anesthetic used medically for induction and maintenance of anesthesia. It is also used as a recreational drug. It is one of the safest anesthetics, as, in contrast with opiates, ether, and propofol, it suppresses ne ...
, as well as transferring criminal property. He had used EncroChat to transfer large amounts of class A and B drugs under the alias "ToffeeForce"[ (a reference to ]Everton F.C.
Everton Football Club () is an English professional association football club based in Liverpool that competes in the Premier League, the top tier of English football. The club was a founder member of the Football League in 1888 and has compe ...
). He was identified from a photo he had sent via Encrochat showing his hands holding a block of Blue Stilton
Stilton is an List of British cheeses, English cheese, produced in two varieties: Blue cheese, Blue, which has ''Penicillium roqueforti'' added to generate a characteristic smell and taste, and White, which does not. Both have been granted the s ...
. Police were able to identify him via his fingerprints in the photo.
Similar cases
The Canada-based company Phantom Secure
Phantom Secure was a Canadian company that provided modified secure mobile phones, which were equipped with a remotely operated kill switch. After its shutdown, criminal users fled to alternatives including ANOM, which turned out to be a honeypot ...
, which started as a legitimate firm selling modified mobile phones, provided "secure communications to high-level drug traffickers and other criminal organization leaders" according to a 2018 FBI takedown announcement. Its CEO, Vincent Ramos, was sentenced in 2019 to a nine-year prison sentence after telling undercover agents that he created the device to help drug traffickers. Customers included members of the Sinaloa Cartel, and the FBI reportedly asked Ramos to plant a backdoor in Phantom Secure's encrypted network, which he refused to do. After this was shut down, ANOM
The ANOM (also stylized as AN0M or ΛNØM) sting operation (known as Operation Trojan Shield (stylized TRØJAN SHIELD) or Operation Ironside) is a collaboration by law enforcement agencies from several countries, running between 2018 and 202 ...
was launched, but in 2021 was revealed to be a sting operation
In law enforcement, a sting operation is a deceptive operation designed to catch a person attempting to commit a crime. A typical sting will have an undercover law enforcement officer, detective, or co-operative member of the public play a role a ...
run by law enforcement agencies. The secure mobile phone company MPC was revealed in 2019 to have been created by Scottish criminals James and Barrie Gillespie. Christopher Hughes, a former employee of the company, is wanted by Dutch police for the murder of criminal turned blogger Martin Kok
Martin Kok (25 June 1967 – 8 December 2016) was a Dutch criminal turned blogger.
Early life
He grew up in Volendam and as a teenager sold eels along with his father and brother, dressed in traditional Volendammer garb of red shirt, baggy black ...
in December 2016.
Sky Global was a Canadian service provider that offered encrypted chat services and secure phones known as Sky ECC
Sky Global was a communications network and service provider founded in 2008 in Vancouver, Canada. A significant share of users of its systems were Transnational organized crime, international crime organizations involved in drug trafficking, and ...
. Dutch and Belgian police claim to have accessed and decrypted the systems traffic in early 2021, leading to numerous arrests.
References
{{Reflist
*
Cyberspace
Dark web
Defunct darknet markets
Distributed computing architecture
File sharing
Internet architecture
Internet culture
Internet terminology
Network architecture
Virtual private networks
Law enforcement operations
Android forks
Mobile Linux
Mobile operating systems
2016 software
Organized crime in Europe
2020 disestablishments