Security

Cyber-crime

Eurocops take down 'secure' criminal chat system known as Matrix

They took the red pill


Updated French and Dutch police have taken down the Matrix chat app, which was designed by criminals for criminals to be a secure encrypted messaging tool.

Cops in the Netherlands discovered the existence of Matrix while investigating the 2021 murder of crime reporter Peter de Vries, who was looking into the Moroccan mafia at the time. When the app's central servers were found to be in France, the Dutch and French plod formed a joint task force and together they managed to compromise the messaging system and read crooks' conversations. How that infiltration was achieved has not yet been publicly explained or divulged.

According to Europol, the app was significantly more advanced than other such criminal chat software. It was invitation-only, strongly end-to-end encrypted, and users would have to pay between €1,300 and €1,600 ($1,400 to $1,700) for a six-month subscription.

"It was soon clear that the infrastructure of this platform was technically more complex than previous platforms such as Sky ECC and EncroChat," Europol explained Tuesday. "The founders were convinced that the service was superior and more secure than previous applications used by criminals."

The task force found Matrix was operating on around 40 servers scattered throughout Europe, and had around 8,000 users. In a three-month operation officers managed to harvest from those machines 2.3 million messages in 33 languages – mainly discussions about money laundering, illegal arms deals, and drug trafficking, we're told.

That data is presently being scrutinized and investigations are ongoing.

Not the first time

When the Euro cops subverted the supposedly secure EncroChat messaging system in 2020 they found a wealth of data – including one particularly stupid corrupt British police analyst. Since then, the snared messages have led to the arrests of 6,558 people worldwide and the seizure of nearly €740 million ($776 million).

A year later there was more chat-cracking success when the Sky ECC communication system was successfully penetrated. In September of this year, the police pulled the same trick on the Ghost messaging system, leading to more criminals having their details exposed to investigators.

Around 8,000 people are having a really bad day ... The splash screen shown in the Matrix app after police compromised the network – Click to enlarge. Source: Europol.

With Matrix, the first users knew about the police action was when they met a splash screen that announced the shuttering of the service.

"It's inevitable," the screen proclaims. "It's not the first time and will not be the last time we were able to read the messages in real time. We gained access to data related to this service and our investigation does not end here."

To coincide with this warning, coppers in Germany and France took down the main servers, and there were also raids in the Netherlands, Lithuania, and Spain, which led to three arrests. More will undoubtedly follow. ®

Updated to add on December 4: No connection to Matrix protocol

Europol was in touch with The Reg overnight to ensure no one imagined the "Matrix" app had any connection to the open protocol for secure decentralized comms of the same name, saying: "The Matrix protocol (matrix.org) is by no means connected to the Matrix secured communication service that was targeted in OTF Continental."

Matthew Hodgson, technical co-founder of the Matrix open standard, told us: "This has nothing to do with the Matrix protocol; it's just an unfortunate naming coincidence."

Send us news
46 Comments

American cops are using AI to draft police reports, and the ACLU isn't happy

Do we really need to explain why this is a problem?

Police arrest suspect in murder of UnitedHealthcare CEO, with grainy pics the only tech involved

McDonald's worker called it in, cops swooped, found 'gun, suppressor, manifesto'

London's Met Police seeks business services, ERP refresh in £370M deal

Contract could be worth a cool £1 billion if associated organizations join

Europe signs off on €10.6B IRIS² satellite broadband deal

Service promised by 2030 for bloc's take on Starlink

Russia gives life sentence to Hydra dark web kingpin after seizing a ton of drugs

No exaggeration – literally a ton. Plus, 15 co-conspirators also put behind bars

Smile! UK cops spend tens of millions on live facial recognition tech

Labour government keen, though critics paint it as a severe threat to privacy

Bluesky too opaque about user figures for Euro watchdogs

X rival also under fire for failing to designate legal representative

European Cloud Competition Observatory created to keep an eye on software licensing

Initiative follows Microsoft settlement with CISPE consortium

Teen serial swatter-for-hire busted, pleads guilty, could face 20 years

PLUS: Cost of Halliburton hack disclosed; Time to dump old D-Link NAS; More UN cybercrime convention concerns; and more

Bloke behind Helix Bitcoin launderette jailed for three years, hands over $400M

Digital money laundering pays, until it doesn't

The hunt is on for the scum who stole Britain's largest inflatable planetarium

Have you seen this dome? It's full of stars

Tower PC case allegedly used as 'creative cavity' by drug importer

Motherboard missing, leaving space for a million hits of meth