Silent Monitoring of Communications Application Users' Behavior and Its Significance for Critical Infrastructure Protection

19. decembra 2025

In December 2025, a practical proof of vulnerability in the communications applications WhatsApp and Signal was published, enabling silent monitoring of user behaviour based exclusively on knowledge of their phone number. 

This does not involve breaking encryption or compromising accounts. It concerns the exploitation of characteristics of these applications' delivery mechanisms, which allow indirect analysis of user behaviour without their knowledge.

The vulnerability stems from the way applications confirm receipt of network packets. Receipt confirmation is sent before the application verifies whether a message or reaction to a message actually exists. In practice, this means that an attacker can send special reactions to non-existent messages, with the target device responding without any notification or trace being displayed to the user in the user interface.

By measuring the response time between sending a request and receiving confirmation, it is possible to monitor changes in device behaviour over the long term. These time characteristics differ significantly depending on whether the device is active or in standby mode, whether it is connected via Wi-Fi or mobile network, or whether the user is moving. With systematic measurement, it is possible to determine with a high degree of probability periods of activity, inactivity, sleep, movement, or complete device shutdown.

From a practical perspective, this is a form of behavioural profiling. It does not allow reading communication content, but it enables reconstruction of daily routines, habits, and availability of a specific person. Combined with high probing frequency, this mechanism also has secondary consequences in the form of increased battery consumption and mobile data usage, which can lead to reduced device availability in critical situations without the user immediately noticing.

From the perspective of critical infrastructure protection, it is important to emphasize that the threat does not concern the technical systems of the applications themselves, but the persons who design, operate, and manage critical infrastructure. Operational personnel of energy networks, transport, water management, telecommunications, healthcare, public administration, and defence represent legitimate targets of intelligence and hybrid activities.

Position of AKI

The Critical Infrastructure Association of the Slovak Republic considers the findings concerning silent behavioural monitoring of communications application users to be relevant from the perspective of critical infrastructure protection and its personnel. AKI SR warns that leaks of metadata and temporal characteristics of communication can have significant intelligence value, even in cases where the communication content itself is strongly encrypted.

Mass-used communications applications represent a technological and operational dependency that must be taken into account when assessing risks according to the NIS2 directive and related regulatory frameworks. Critical infrastructure protection cannot be limited exclusively to technical systems, but must also include protection of the availability, behaviour, and routines of key personnel.

AKI SR recommends that critical infrastructure operators take these types of threats into account within risk analyses, mobile device usage policies, and assessments of digital dependencies.

24. septembra 2026
We are continuing the series of expert articles by the Critical Infrastructure Association of the Slovak Republic, in which we gradually introduce the individual essential services listed in Annex No. 1 to Act No. 367/2024 Coll. on Critical Infrastructure. Having covered the operation of pipelines for the transport of crude oil and motor fuels, today we move one step upstream to a service that stands at the very beginning of the entire oil chain: crude oil extraction.
24. septembra 2026
Pokračujeme v sérii odborných článkov Asociácie kritickej infraštruktúry Slovenskej republiky, v ktorej postupne predstavujeme jednotlivé základné služby uvedené v prílohe č. 1 zákona č. 367/2024 Z. z. o kritickej infraštruktúre. Po tom, ako sme sa venovali prevádzkovaniu potrubí na prepravu ropy a pohonných látok, sa dnes posúvame o krok proti prúdu k službe, ktorá stojí úplne na začiatku celého ropného reťazca: ťažbe ropy.
21. septembra 2026
On 16 September 2026, a test carried out in Norway demonstrated a new dimension of satellite navigation security. Europe’s Galileo system was tested under so-called spoofing conditions — a situation in which a receiver is fed a fake signal and may therefore receive incorrect information about its position.
21. septembra 2026
16. septembra 2026 sa v Nórsku uskutočnil test, ktorý ukázal nový rozmer bezpečnosti satelitnej navigácie. Európsky systém Galileo bol testovaný v podmienkach tzv. Spoofingu, teda situácie, pri ktorej je prijímaču podstrčený falošný signál a ten môže dostať nesprávnu informáciu o svojej polohe.
14. septembra 2026
The Critical Infrastructure Association of the Slovak Republic continues its series of articles focusing on basic services under Act No. 367/2024 Coll. on Critical Infrastructure. This time, we look at a basic service that remains largely invisible to the public, yet its disruption can have an immediate impact on transport, industry and the wider economy – the operation of pipelines for the transportation of crude oil and fuels.
14. septembra 2026
Asociácia kritickej infraštruktúry SR pokračuje v sérii článkov venovaných základným službám podľa zákona č. 367/2024 Z. z. o kritickej infraštruktúre. Tentoraz sa venujeme základnej službe, ktorá zostáva pre verejnosť väčšinou neviditeľná, no jej výpadok môže mať veľmi rýchly vplyv na dopravu, priemysel aj fungovanie ekonomiky: prevádzkovaniu potrubí na prepravu ropy a pohonných látok.
8. septembra 2026
Several incidents in the space of a single week. And in one case, 4.2 GW of generation capacity was temporarily taken offline. Germany is dealing with a series of attacks on its electricity grid that highlights one important point: the target does not necessarily have to be the power plant itself.
8. septembra 2026
Niekoľko incidentov v priebehu jediného týždňa. A v jednom prípade dočasne vyradená výrobná kapacita 4,2 GW. Nemecko rieši sériu útokov na elektrickú sieť, ktorá ukazuje dôležitú vec: terčom nemusí byť samotná elektráreň.
5. septembra 2026
District heating and cooling are an important part of the energy infrastructure of cities and municipalities. Their role is not limited to providing thermal comfort; they create stable conditions for the functioning of households, public institutions, industry and other facilities. As energy systems become increasingly technologically complex, the importance of their reliability, preparedness and ability to respond to operational disruptions is also growing.
5. septembra 2026
Diaľkové vykurovanie a chladenie predstavujú významnú súčasť energetickej infraštruktúry miest a obcí. Ich úlohou nie je len zabezpečiť tepelný komfort, ale vytvárať stabilné podmienky pre fungovanie domácností, verejných inštitúcií, priemyslu a ďalších prevádzok. S rastúcou technologickou komplexnosťou energetických systémov zároveň rastie aj význam ich spoľahlivosti, pripravenosti a schopnosti reagovať na narušenie prevádzky.