Telegram says extortionists are planting illegal content into public group chats, then reporting it to Apple to trigger App Store takedowns. The alleged goal is to pressure group owners into paying ransom to avoid being targeted. The trick relies on hiding the illegal content by editing an older message so group members don’t notice or report it first.
What happened
Telegram's CEO alleged that an extortionist planted child sexual abuse material (CSAM) into a public group chat in order to get the app briefly removed from Apple's App Store. Rather than posting new illegal content that moderation systems and members would quickly catch, the attacker reportedly edited an older message in an active chat to insert the material. This made the content effectively invisible to group members, since edits to old messages don't surface the way new posts do.
The extortion mechanism
According to Telegram, the actors behind this tactic use automated accounts to plant illegal content in public groups and then report it directly to Apple, attempting to trigger removal of legitimate communities whose owners refused to pay them. The stated goal is ransom: group owners are pressured to pay to avoid being targeted this way. This turns a platform's own enforcement and reporting channels into a weapon against the very communities they're meant to protect.
Why it succeeded
The technique worked around normal safeguards in a few ways:
- Editing an old message avoided the scrutiny that new posts typically receive from both members and automated moderation tools.
- Automated accounts could plant content and file reports quickly, without relying on human coordination that might be noticed.
- The report was routed to an external party (Apple's App Store review process) rather than staying inside Telegram's own moderation pipeline, adding pressure through a channel the group owner doesn't control.
What to watch for
Community managers, moderators, and trust and safety teams should be alert to:
- Ransom or extortion demands tied to threats of platform or app store takedown
- Unexplained edits to older messages in high-traffic public groups
- Enforcement actions or removals tied to content that members say they never saw
- Suspicious or newly created automated accounts interacting with old posts
Building resistance
Organizations that run public communities should treat this as a real social engineering and extortion risk rather than a one-off technical glitch. Recommended steps include escalating any ransom demand tied to a takedown threat directly to legal and trust and safety teams instead of negotiating, monitoring for suspicious message edit activity, and maintaining a rapid response plan for platform or app store enforcement events. That plan should define who investigates, how evidence is preserved, and how the organization communicates with members and platform partners like Apple during an incident.
Key findings
- Telegram CEO alleged an extortionist planted CSAM in a public chat to trigger temporary App Store removal.
- The attacker allegedly hid the illegal content by editing an old message so members wouldn’t see/report it.
- Telegram claims the actors demand ransom from group owners to avoid being targeted and reported to Apple.
Who’s being targeted
- Commonly targeted roles: Community managers, Moderators, Trust & Safety teams, Legal, Executive leadership for crisis response.
- Affected industries: Online platforms / social media communities, Technology, Media.
- Attack channels: telegram, website.
- Impersonated: Extortionist posing as a “ransom” enforcer targeting Telegram group owners, Regular group participant/account (including automated accounts).
Red flags to watch for
- Ransom/extortion demand tied to platform takedown threats
- Threat involves planting/reporting illegal content rather than a legitimate policy dispute
- Pressure tactics implying immediate consequences if payment isn’t made
- Unusual message edits of older content in high-traffic chats
- Reports/enforcement actions that members say they never saw in-chat
- Suspicious new/automated accounts interacting with old posts
Frequently asked questions
How did extortionists get Telegram removed from the App Store?
According to Telegram, an attacker planted child sexual abuse material by editing an old message in an active public group, then reported the group directly to Apple to trigger removal.
Why didn't group members notice the illegal content?
The attacker allegedly hid the content by editing an older message in the chat, which kept it from appearing as new activity that members would see or report themselves.
What is the extortion angle in this attack?
Telegram claims the threat actors demand ransom from group owners in exchange for not targeting their communities with this planting-and-reporting tactic.
What should community managers do about this threat?
Treat ransom demands tied to platform takedown threats as a real risk, escalate to legal and trust-and-safety teams, and watch for suspicious edits to older messages.
Read the video transcript
Imagine your Telegram community getting an Apple App Store ban… because someone secretly edited an old message in your chat. Telegram’s CEO says extortionists plant illegal content in public groups, then report it to Apple to get Telegram briefly pulled, demanding ransom from group owners not to target their communities. Here’s the trick: they don’t post in the live chat. They edit an old message, so members never see it to report it, only the platform sees it when they file the complaint. If you ever get a ransom note tied to Telegram or App Store takedown threats, don’t negotiate, escalate it immediately to our legal or trust-and-safety team.