https://www.politico.eu/article/cryptophone-firm-dismisses-b...
Sky ECC denies the breach (see also [0]):
> "a fake phishing application falsely branded as Sky ECC was illegally created, modified and side-loaded onto unsecure devices"
The belgian police claims:
> Sky ECC's claims were "bullshit."
> So confident were the police that they broke Sky ECC's code, they said they sent the firm their bank account details to claim a $5 million (€4.2 million) bug bounty Sky ECC promised to pay out to security researchers that had managed it.
Quite ballsy.
> “The work is only starting,” a spokesperson for the Belgian judicial police had said Tuesday, adding that many more investigations were likely to follow as the decrypted messages yielded more leads.
I don't see why they'd give those criminals this notice to prepare. I'd assume a bunch of surprise house-visits would be more effective, if they have all this info.
The story smells somewhat fishy from both ends. Good drama though. If they really breached Sky ECC's security, they should be able to prove this by solving a cryptographic challenge by them.
[0] https://www.skyecc.com/sky-ecc-platform-remains-secure-and-n...