Telegram founder Pavel Durov has accused WhatsApp of misleading users about its privacy protections.
Quick Summary – TLDR:
- Pavel Durov claims WhatsApp encryption promises are misleading.
- Cloud backups may expose a large portion of user messages.
- Encryption exists, but backups weaken overall privacy.
- Debate highlights trade off between security and usability.
What Happened?
Pavel Durov publicly criticized WhatsApp, calling its end-to-end encryption claims a “consumer fraud.” He argued that while messages are encrypted during transmission, backup practices create serious privacy gaps.
WhatsApp’s “E2E encryption by default” claim is a giant consumer fraud: ~95% of private messages on WhatsApp end up in plain-text backups on Apple/Google servers — not E2E-encrypted. Backup encryption is optional, and few people enable it — let alone use strong passwords.
— Pavel Durov (@durov) April 12, 2026
WhatsApp Encryption Claim Under Scrutiny
WhatsApp has long promoted its end-to-end encryption as default, stating that only the sender and receiver can read messages. According to its official explanation, not even the company itself can access conversations.
However, Durov challenged this claim, pointing out that encryption only applies during message transfer, not necessarily when data is stored. He argued that this creates a false sense of complete privacy among users who may not fully understand how their data is handled.
The Backup Problem Explained
At the center of this debate is how WhatsApp manages chat backups.
- Messages are often stored on Apple iCloud or Google Drive.
- These backups may lack strong encryption by default.
- Users must manually enable encrypted backups.
- Many users either skip this step or use weak passwords.
Durov claimed that up to 95 percent of private messages could end up stored in plain text or weakly protected formats on cloud servers. He also noted that even if one user enables backup encryption, conversations may still be exposed if the other participant does not use the same setting.
This, he said, undermines the very purpose of end-to-end encryption.
Security Risks and Real World Impact
The concern is not just theoretical. Security experts have repeatedly warned that cloud backups are a common target for attackers.
- Hackers can access backups through phishing or stolen credentials.
- Cloud misconfigurations may expose sensitive data.
- Legal authorities can request access from service providers.
Durov also alleged that Apple and Google share backed up data with third parties multiple times each year, further raising concerns about user privacy.
Telegram vs WhatsApp: A Complex Comparison
Durov used the moment to defend Telegram, stating that his platform has never disclosed user message content in over a decade.
However, critics pointed out that Telegram does not enable end-to-end encryption by default for all chats. Instead, users must activate a separate Secret Chats feature to get full encryption. This means both platforms have different trade offs between security and convenience.
Meanwhile, privacy focused apps like Signal are often seen as stronger alternatives because they enforce default encryption without relying on cloud backups.
Industry Debate Heats Up
This controversy has reignited a broader discussion in the tech world about what true privacy really means.
Modern messaging apps must balance:
- Strong encryption
- Multi device access
- Ease of use
Features like cloud syncing make apps more convenient but also introduce new risks and vulnerabilities.
SQ Magazine’s Takeaway
I think this debate exposes a truth many users overlook. Just because an app says your chats are secure does not mean your data is fully protected. The backup loophole is real, and most people never check their settings.
In my view, companies should make privacy the default, not optional. If encryption can be weakened by a simple setting, then it is not strong enough for everyday users. This is a wake up call to look beyond marketing claims and understand how these apps actually work.