> ## Content Index
> Fetch the complete content index at: https://techlore.tech/llms.txt
> Use this file to discover other available public pages before exploring further.

# WhatsApp Leaked 3.5 Billion Phone Numbers
- URL: https://techlore.tech/whatsapp-leaked-3-5-billion-phone-numbers-surveillance-report/
- Published: 2025-11-21T03:12:00.000Z
- Updated: 2026-04-07T23:18:28.000Z
- Description: Techlore Surveillance Report: Weekly News for Your Digital Freedom
- Author: Henry Fisher
- Tags: Surveillance Report

This week's Surveillance Report covers WhatsApp's massive phone number enumeration flaw that exposed 3.5 billion users' data through poor rate limiting - potentially the largest data exposure in history. I also examine Google's new Android sideloading restrictions threatening open app distribution, the EU's concerning Digital Omnibus proposal that could significantly weaken GDPR protections, and disturbing attempts in Wisconsin and Michigan to ban VPN usage under the guise of age verification.

**⏱️ TIMESTAMPS:**  
00:00 Welcome to Surveillance Report 245  
00:29 WhatsApp's Phone Number 'Leak'  
06:08 Surveillance Report Back @ Techlore Announcement  
08:01 Google's Attacks on Android Freedom  
12:48 EU Saga Part 1: Chat Control  
15:56 EU Saga Part 2: Digital Omnibus  
20:22 Our Sponsor: EasyOptOuts!  
21:50 EU Saga Part 3: Cookies Finally Crumble!   
23:28 WhatsApp Interoperability Now Live  
26:26 USA's VPN Ban  
29:48 Cloudflare Outage  
30:50 Data Breaches & Service Updates  
34:18 Our Sponsor: EasyOptOuts!  
34:56 Final Words!

📰

Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [RSS app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG)

#### Episode Sources

****Highlight**

- <https://www.wired.com/story/a-simple-whatsapp-security-flaw-exposed-billions-phone-numbers/>
- <https://support.signal.org/hc/en-us/articles/6712070553754-Phone-Number-Privacy-and-Usernames>

****Google’s ‘Sideloading’ Saga**

- <https://arstechnica.com/gadgets/2025/08/google-will-block-sideloading-of-unverified-android-apps-starting-next-year/>
- <https://arstechnica.com/gadgets/2025/09/f-droid-calls-for-regulators-to-stop-googles-crackdown-on-sideloading/>
- <https://f-droid.org/en/2025/09/29/google-developer-registration-decree.html>
- <https://www.androidauthority.com/android-power-users-install-unverified-apps-3615310/>

****Chat Control**

- <https://digitalcourage.social/@echo%5Fpbreyer/115552705437735549>
- <https://digitalcourage.social/@echo%5Fpbreyer/115571721648039969>
- <https://digitalcourage.social/@echo%5Fpbreyer/115575902901048016>
- <https://www.patrick-breyer.de/en/eu-chat-control-proposal-still-poses-high-risks-despite-removal-of-mandatory-scanning-experts-warn/>
- <https://www.mullvad.net/en/blog/2025/11/14/mullvad-vpn-present-and-then/>
- <https://fightchatcontrol.eu/>

****Digital Omnibus**

- <https://noyb.eu/en/eu-commission-about-wreck-core-principles-gdpr>
- <https://edri.org/our-work/forthcoming-digital-omnibus-would-mark-point-of-no-return/>

****Cookie Crumble**

- <https://www.theverge.com/news/823788/europe-cookie-prompt-browser-changes-proposal>

****WhatsApp Interopability**

- <https://about.fb.com/news/2025/11/messaging-interoperability-whatsapp-enables-third-party-chats-for-users-in-europe/>

****Winsconsin’s VPN Ban**

- <https://www.eff.org/deeplinks/2025/11/lawmakers-want-ban-vpns-and-they-have-no-idea-what-theyre-doing>

****Cloudflare Outage**

- <https://www.bleepingcomputer.com/news/technology/cloudflare-hit-by-outage-affecting-global-network-services/>
- <https://blog.cloudflare.com/18-november-2025-outage/>

****Data Breaches & Updates**

- <https://www.caranddriver.com/news/a69384313/hyundai-data-breach-details/>
- <https://nerds.xyz/2025/11/logitech-cybersecurity-incident-zero-day/>
- <https://www.bleepingcomputer.com/news/security/jaguar-land-rover-cyberattack-cost-the-company-over-220-million/>
- <https://www.bleepingcomputer.com/news/security/pennsylvania-ag-confirms-data-breach-after-inc-ransom-attack/>
- <https://www.bleepingcomputer.com/news/security/doordash-email-spoofing-vulnerability-sparks-messy-disclosure-dispute/>
- <https://www.bleepingcomputer.com/news/security/princeton-university-discloses-data-breach-affecting-donors-alumni/>
- <https://www.404media.co/ai-porn-secret-desires-chatbot-face-swap/>
- <https://blog.mozilla.org/en/firefox/ai-window/>
- <https://nerds.xyz/2025/11/firefox-145-better-privacy-pdf-notes/>
- <https://blog.mozilla.org/en/firefox/tab-groups-updates/>
- <https://www.blender.org/download/releases/5-0/>
- <https://blog.torproject.org/new-release-tails-7%5F2/>
- <https://blog.torproject.org/new-release-tor-browser-1502/>
- <https://novacustom.com/product/shiftphone-8-1-with-iodeos/?wcmlc=USD&reloaded=1>
- <https://www.bleepingcomputer.com/news/security/google-fixes-new-chrome-zero-day-flaw-exploited-in-attacks/>
- <https://www.bleepingcomputer.com/news/software/thunderbird-adds-native-support-for-microsoft-exchange-accounts/>