WhatsApp, Messenger and Signal have replaced text messages for most of us. Ofcom’s Online Nation report found that 90% of UK online adults used WhatsApp in 2025, up from 87% the year before, and the average user now spends 17 minutes a day inside the app. That scale is exactly why messaging apps have become such an attractive target for criminals, and why the risks of popular messaging apps now sit high on the UK’s regulatory agenda too.
The risks of popular messaging apps are not the same as the risks of email or social media. They involve encryption gaps that vary wildly between apps, metadata that keeps building a profile of you even when your words are protected, and a UK legal debate about whether the government should be able to see inside your chats at all. This article works through where the real risk sits, how WhatsApp, Signal, Telegram and iMessage compare, what the Online Safety Act actually changes, why “Shadow IT” is a growing problem for UK businesses, and what parents, employees and everyday users can do about it.
Table of Contents
What Puts Your Messages at Risk
Most of the risk in messaging apps comes down to four things: how the app handles encryption, how much data it collects about you, how easily scammers can reach you through it, and how casually people use it for sensitive business conversations.
Weak or Missing Encryption
Not every messaging app protects your messages the same way, and this is where most confusion starts. End-to-end encryption (E2EE) means only the sender and recipient can read a message, not even the app provider. Encryption-in-transit only protects the message while it’s travelling between servers, which means the provider can still read it once it arrives. Signal and WhatsApp use E2EE by default for every chat.
Telegram does not: standard Telegram chats sit on Telegram’s own servers and are only end-to-end encrypted if you deliberately start a “Secret Chat,” a detail plenty of Telegram’s users are unaware of. This single difference explains why security researchers keep singling Telegram out, even though it’s marketed alongside genuinely secure apps. It also means the level of protection you get from “a messaging app” depends entirely on which one you picked and which setting you left switched off, not on some general standard every app follows.
Data Collection and Retention
Even when message content is properly encrypted, the app still knows who you’re talking to, when, how often, and roughly where you were standing when you sent it. This is metadata, and it doesn’t need to be decrypted to be useful to whoever holds it. WhatsApp shares elements of your contact list and usage data with its parent company, Meta, for advertising purposes, something worth knowing before assuming an encrypted app means an entirely private one. None of this is illegal or hidden in the small print, but it’s rarely explained clearly at the point you sign up, and most users only discover the extent of it when they read a privacy policy in full for the first time.
Scams and Social Engineering Sent Through Chat
Phishing remains the most common type of cyber attack facing UK organisations, and DSIT’s Cyber Security Breaches Survey 2025/2026 confirms it as the leading cause of breaches reported by UK businesses and charities alike. Increasingly, that phishing arrives through a messaging app rather than an inbox, because a message from what looks like a colleague, a delivery firm or your bank gets far less scrutiny on WhatsApp than the same message would in a work email.
Business Use Without Safeguards
Employees frequently use personal messaging apps to share work documents, client details or passwords, often because it’s quicker than logging into a company system. None of this activity falls within a business’s normal security controls, which is where the risks of popular messaging apps stop being a personal problem and become a compliance issue, as the Shadow IT section below explains in more detail.
WhatsApp, Signal, Telegram and iMessage Compared
Every one of these apps handles security differently, and the differences matter more than most people assume when choosing which one to trust with a sensitive conversation. Working out the risks of popular messaging apps starts here, since encryption, metadata and jurisdiction vary far more between these four than most users expect. The table below compares the four messaging apps that dominate UK smartphones on the points that actually affect your privacy.
| App | Default E2EE | Metadata collected | Jurisdiction | Backup encryption |
|---|---|---|---|---|
| Yes, all chats | Contact list, usage data shared with Meta | US (Meta) | Encrypted only if enabled manually in settings | |
| Signal | Yes, all chats | Minimal; phone number only, no advertising data | US (non-profit) | Encrypted, passphrase-protected |
| Telegram | No, only “Secret Chats” | Standard chats stored on Telegram’s servers | UAE and multiple jurisdictions | Cloud chats are not end-to-end encrypted |
| iMessage | Yes, between Apple devices only | Limited, tied to your Apple ID | US (Apple) | Encrypted only with Advanced Data Protection switched on |
Signal collects the least by design, since it was built by a non-profit foundation with no advertising revenue to protect, which is why privacy specialists tend to recommend it first. WhatsApp sits in the middle: strong message-level encryption, but plenty of metadata flowing to Meta. Telegram’s biggest weakness is that most users assume the whole app is encrypted when only Secret Chats actually are.
iMessage is genuinely private only if you’re messaging another Apple device and Advanced Data Protection is switched on, which UK users should note is not guaranteed to remain available (more on that below). For a deeper look at how the underlying technology works, our end-to-end encryption explainer covers the protocol side in more depth, and our comparison of secure messaging apps goes further into picking the right one for your specific needs. None of the four apps above is universally “the safest,” since the right choice depends on who you’re talking to and what you’re discussing.
Why Encryption Alone Isn’t Enough
Encryption protects a message in transit, but it doesn’t protect what happens before or after. Two gaps catch out even careful users: what your phone backs up automatically, and what your usage patterns reveal, regardless of what you actually typed.
The Cloud Backup Gap
If you back up your WhatsApp chats to iCloud or Google Drive, that backup is often not covered by the same end-to-end encryption as the messages themselves, unless you’ve specifically switched on end-to-end encrypted backups. Once your chat history is stored in a cloud account, it could be accessed by the cloud provider or handed over in response to a legal request, in ways the original encrypted message never could be.
This single setting undoes a large part of what E2EE is supposed to guarantee, and most users never look for it because the app doesn’t draw attention to it either. It’s one of the clearest examples of how the risks of popular messaging apps sit outside the encryption itself, in settings menus most people never open.
What Your Metadata Reveals
Metadata is often more revealing than people expect. Knowing that you messaged a divorce lawyer at 11 pm, or contacted a specific colleague every day for two weeks before a redundancy announcement, tells a detailed story without a single word of the conversation being read. Apps that minimise metadata collection, like Signal, are the only real defence against this, since no amount of message-level encryption changes what the metadata shows. This is precisely why security researchers increasingly treat metadata protection as at least as important as message content when judging how private an app really is.
The UK Online Safety Act and Your Messages
Messaging app privacy in the UK is not just a technology question any more. It is also a live legal one, and the outcome will shape the risks of popular messaging apps for years to come.
Section 121 of the Online Safety Act gives Ofcom the power to require messaging platforms to use “accredited technology” to scan for illegal content, including material that would otherwise be protected by end-to-end encryption. Ofcom is due to publish its guidance on this in spring 2026, and the government has previously acknowledged that there is no known way to scan messages for illegal content without weakening encryption for everyone.
Signal and WhatsApp have both indicated they would rather withdraw from the UK than build in the kind of access this would require, and campaign groups have warned that any technique built for this purpose would create a single point of failure that criminals could exploit just as easily as regulators.
This isn’t hypothetical for UK users already. In February 2025, Apple withdrew its Advanced Data Protection feature, which offered end-to-end encrypted iCloud backups, for UK customers rather than comply with a government order to build in access. Anyone in the UK who set up an iPhone after that point does not have the option to turn ADP on, which directly affects how safe an iMessage backup actually is.
The debate over messaging app encryption in the UK has already changed what protection is available to ordinary users, not just what might change in the future. A similar proposal, often referred to as “Chat Control,” is being debated separately at EU level, which suggests this is not a one-off UK policy but part of a wider pattern across European regulators.
Messaging Apps at Work: The Shadow IT Problem
“Shadow IT” describes technology employees use for work that IT and security teams don’t know about or control, and messaging apps are its most common form. A quick WhatsApp message to a client, a Telegram group for a project team, a photo of a spreadsheet sent to a colleague: none of it looks risky in the moment.
The problem is that none of this activity is covered by a company’s data protection policies, retention rules or breach reporting process. If client data or personal information passes through a personal WhatsApp account and something goes wrong, the business still carries the same UK GDPR obligations it would for a proper breach, but without the audit trail that a managed system would have provided.
This matters more than it might seem: DSIT’s own figures show that 43% of UK businesses reported a cybersecurity breach or attack in the past 12 months, and a business cannot investigate or report on an incident properly if the relevant conversation happened on an employee’s personal phone rather than a system the company actually controls. Smaller organisations are typically the least prepared for this, since they’re less likely to have a written policy on which apps staff are allowed to use for client communication in the first place.
Our guide to protecting your business from cyber threats covers the wider compliance picture, and it’s worth reading alongside this one if messaging apps have crept into your team’s daily workflow. Targeted scams sent through personal chat apps, including convincing impersonations of senior colleagues, follow much the same pattern as the whaling attacks that target company email, just through a channel with far less oversight.
What Parents and Educators Need to Know
Messaging apps are where most children now socialise, which means the same encryption and metadata issues above apply directly to them, alongside risks that are specific to how young people use these apps. Ofcom found that 63% of children aged 8 to 14 already use WhatsApp, which puts many of the risks of popular messaging apps in front of children years before most parents expect it.
Group chats, disappearing messages and app-within-app features (games or “secret” messaging tools disguised as something else) can make it harder for parents to know what their child is being exposed to or who they’re really talking to. Age-inappropriate content can reach a child through a group chat just as easily as through social media, and a child who wouldn’t add a stranger on Instagram might not think twice about a message request in WhatsApp.
Our guide to children’s online safety has more details on setting up age-appropriate boundaries without shutting a child out of normal social contact.
How to Protect Yourself: A Practical Checklist
None of the risks above means you need to abandon messaging apps altogether. Most of the risks of popular messaging apps can be closed off with a handful of settings changes, and none of them takes more than a few minutes to work through.
- Turn on end-to-end encrypted backups in WhatsApp settings, rather than assuming your backup is automatically protected.
- Enable two-step verification on every messaging app you use, particularly for accounts tied to your phone number.
- Use disappearing messages for sensitive conversations, which limit what’s exposed if an account is later compromised.
- Avoid clicking links sent through chat apps unless you can verify the sender through another channel first.
- Keep personal messaging apps out of work conversations involving client data, and use your employer’s approved system instead.
- Review which apps have access to your contacts and photos, and remove permissions you don’t recognise or no longer need.
The NCSC’s guidance for high-risk individuals on protecting your accounts and devices sets out the same principles in more depth, and applies just as well to anyone who wants to reduce their exposure, not only those in high-profile roles. Working through this checklist once, and revisiting it whenever you switch phones, closes off most of the risks of popular messaging apps without asking you to give up any of the apps you actually rely on.
Understanding the risks of popular messaging apps doesn’t mean giving up the convenience they offer. It means knowing which app suits which conversation, checking the settings that actually protect your backups and metadata, and keeping an eye on how your business or your children are really using them day to day. A few minutes spent on the checklist above will do more for your privacy than switching apps ever will.
Frequently Asked Questions
These are the questions we’re asked most often about messaging app security, covering everyday use, business risk and the current state of UK law.
What are the main risks of popular messaging apps?
The risks of popular messaging apps fall into three groups: weak or absent end-to-end encryption on some apps, metadata collection that continues even when messages are encrypted, and scams delivered through chat rather than email. Business use without proper safeguards adds a fourth risk specific to workplaces.
Is it safe to share bank details over a messaging app?
Generally, no. Even with strong end-to-end encryption, the risk usually sits with the recipient’s device rather than the message itself. If their phone is compromised, backed up insecurely, or simply lost, your bank details are exposed regardless of how well the message was protected in transit.
Does Telegram encrypt all of my chats?
No. Only Telegram’s opt-in “Secret Chats” use end-to-end encryption. Standard Telegram chats, including group chats, are stored on Telegram’s servers without end-to-end encryption, a common misconception among its users.
Can the UK government read my encrypted messages?
Not currently, but the legal framework to compel this exists. Section 121 of the Online Safety Act gives Ofcom the power to require messaging platforms to scan for illegal content, which experts agree cannot be done without weakening encryption. Ofcom’s guidance on how it intends to use this power is due in spring 2026.
What happens to my messages if I delete a messaging app?
Deleting the app from your phone does not delete your data from the provider’s servers. To remove your information, you typically need to delete your account within the app’s own settings before uninstalling it, and even then some metadata may be retained for legal or safety purposes.
Are messaging apps safe to use for business communication?
Personal messaging apps like WhatsApp are not designed for business use and fall outside most companies’ data protection and audit requirements. If your team is using them for client work, treat it as a Shadow IT risk and move sensitive conversations to a properly managed business communication platform instead.
What should I do if I’ve been scammed through a messaging app?
Stop replying immediately, and don’t click any further links the sender has shared. If money changed hands, contact your bank straight away, since UK banks have dedicated fraud teams for this, and acting quickly improves the chances of recovering funds. Report the message within the app, block the sender, and consider reporting the incident to Action Fraud, the UK’s national reporting centre for fraud and cybercrime.