Brazil encryption policy

Brazil's Vorcaro Forensics Cracked a Phone, Not WhatsApp's Encryption

Federal Police recovered 52 disappearing WhatsApp messages by exploiting a banker's own workaround, not by breaking end-to-end encryption.

Cracking a Phone, Not the Protocol People of Internet Research · Brazil 52 Ephemeral messages recovered 5 confirmed via WhatsApp, 47 recon… ~R$52B FGC hole from Master collapse Largest shortfall in the deposit-g… R$250K Per-depositor coverage cap FGC guarantee limit, consolidated … 6 years Years encryption case pending STF's ADI 5527/ADPF 403 on compell… peopleofinternet.com
Cracking a Phone, Not the Protocol People of Internet Research · Brazil 52 Ephemeral messages recover… ~R$52B FGC hole from Master collapse R$250K Per-depositor coverage cap 6 years Years encryption case pending peopleofinternet.com

Key Takeaways

On September 1, 2026, Supreme Federal Court (STF) Justice André Mendonça lifted secrecy on a 218-page Federal Police forensic report showing investigators had recovered 52 supposedly "disappearing" WhatsApp messages that Banco Master's Daniel Vorcaro sent to a contact attributed to Justice Alexandre de Moraes — five recovered directly from WhatsApp and 47 more reconstructed from matching digital artifacts, according to reporting on the report by Poder360 and CNN Brasil. The headlines have framed this as proof that WhatsApp's encryption can be defeated. It isn't. The distinction matters for how Brazil — and every government watching this case — thinks about encryption policy going forward.

How the messages actually surfaced

Vorcaro used WhatsApp's visualização única (view-once) feature, which is supposed to delete a message after it's opened. But instead of typing directly into WhatsApp, he drafted text in his iPhone's Notes app, took a screenshot, and sent the image as a view-once message — then deleted the note. That workaround left a trail: each screenshot generated a temporary PDF file that WhatsApp's transport encryption never touched, because it never left the device as a message. Federal Police used Cellebrite, the Israeli forensic firm's tool, to bypass the passcode on the seized iPhone 17 Pro, then ran the extracted data through IPED (Indexador e Processador de Evidências Digitais) — the PF's own open-source indexing tool, built after Operation Lava Jato and hosted on the agency's official portal. IPED matched timestamps across Notes, screenshots, and WhatsApp send logs to reconstruct the pattern.

That is device forensics on hardware seized under a warrant — not a backdoor into WhatsApp's Signal-protocol encryption. Meta was never asked to decrypt anything, and no vulnerability was introduced into the app that any other user relies on.

The case behind the phone

Vorcaro was arrested at a Rio airport on November 17, 2025, attempting to fly to Malta by private jet; the Central Bank ordered the extrajudicial liquidation of Banco Master the next day. The collapse left roughly R$51.8 billion — the largest hole in the fund's history — for Brazil's deposit-guarantee fund (FGC) to cover, according to Poder360, which also runs Operation Compliance Zero, a federal fraud and money-laundering probe. The FGC's own guarantee-payment page confirms Master, Master de Investimento and Letsbank were consolidated into one conglomerate for the R$250,000-per-depositor coverage cap. Given the scale of that fraud and Vorcaro's attempted flight, a court-authorized forensic search of his phone is a proportionate step — not an outlier.

Steelmanning the alarm

The strongest objection isn't really about encryption; it's about what these messages allegedly show. Vorcaro was communicating, via a channel designed to leave no trace, with someone attributed to the justice overseeing scrutiny of his bank. If genuine, the public interest in surfacing that contact is obvious, and critics who say ephemeral-messaging features shouldn't shield a justice's undisclosed contacts with a fraud suspect have a fair point. Forensic tools that can reconstruct deleted communications on a lawfully seized device are a legitimate check on exactly that kind of concealment.

The recovery method also cuts the other way: it validates, rather than undermines, the position Justices Rosa Weber and Edson Fachin previewed in their 2020 votes on ADI 5527 and ADPF 403 — that end-to-end encryption is essential to privacy and security and that Brazil's Marco Civil da Internet cannot be read to force platforms to build in access (ip.rec.br).

That case has sat unresolved for six years — paused by a vista request from Moraes himself in 2020 and returned to the docket only in 2023, per the same analysis — leaving Brazil without a settled doctrine distinguishing warranted device forensics from platform-level decryption mandates. The Vorcaro episode is exactly the fact pattern the STF needs to finally rule on: it shows encryption held at the transport layer while a targeted, warrant-backed search of a suspect's own hardware still produced results. Policymakers elsewhere — including EU lawmakers debating mandatory client-side scanning — should note that Brazil got useful evidence without weakening WhatsApp's protocol for two billion users worldwide.

The part getting less attention

What should worry observers isn't the forensics — it's the secrecy fight it triggered inside the court itself. Moraes says the plenary still lacks access to 18 petitions and 180 documents across 13 related proceedings; Mendonça says he has released everything legally permissible before a scheduled full-court vote. A justice who is both a subject of the leaked messages and the one demanding fuller access to the phone dump that produced them is an awkward look for institutional impartiality, regardless of the merits. Brazil's broader intermediary-liability overhaul, already flagged by EFF for its potential to incentivize enforcement overreach (EFF), makes procedural clarity — about forensics, about court secrecy, about the limits on both — more urgent, not less.

Encryption survived this case. Institutional transparency is the open question.

Sources & Citations

  1. Federal Police official portal
  2. FGC guarantee payment page
  3. Poder360: how PF found the messages
  4. Poder360: Master's R$51.8B FGC hole
  5. CNN Brasil: tracing Vorcaro's messages
  6. EFF on Brazil's intermediary liability regime
  7. ip.rec.br on ADI 5527 / ADPF 403