Extortionists Plant CSAM to Get Telegram Banned

The Hacker News · Medium sophistication
Last updated August 7, 2026

Telegram says extortionists are planting illegal content into public group chats, then reporting it to Apple to trigger App Store takedowns. The alleged goal is to pressure group owners into paying ransom to avoid being targeted. The trick relies on hiding the illegal content by editing an older message so group members don’t notice or report it first.

What happened

Telegram's CEO alleged that an extortionist planted child sexual abuse material (CSAM) into a public group chat in order to get the app briefly removed from Apple's App Store. Rather than posting new illegal content that moderation systems and members would quickly catch, the attacker reportedly edited an older message in an active chat to insert the material. This made the content effectively invisible to group members, since edits to old messages don't surface the way new posts do.

The extortion mechanism

According to Telegram, the actors behind this tactic use automated accounts to plant illegal content in public groups and then report it directly to Apple, attempting to trigger removal of legitimate communities whose owners refused to pay them. The stated goal is ransom: group owners are pressured to pay to avoid being targeted this way. This turns a platform's own enforcement and reporting channels into a weapon against the very communities they're meant to protect.

Why it succeeded

The technique worked around normal safeguards in a few ways:

  • Editing an old message avoided the scrutiny that new posts typically receive from both members and automated moderation tools.
  • Automated accounts could plant content and file reports quickly, without relying on human coordination that might be noticed.
  • The report was routed to an external party (Apple's App Store review process) rather than staying inside Telegram's own moderation pipeline, adding pressure through a channel the group owner doesn't control.

What to watch for

Community managers, moderators, and trust and safety teams should be alert to:

  • Ransom or extortion demands tied to threats of platform or app store takedown
  • Unexplained edits to older messages in high-traffic public groups
  • Enforcement actions or removals tied to content that members say they never saw
  • Suspicious or newly created automated accounts interacting with old posts

Building resistance

Organizations that run public communities should treat this as a real social engineering and extortion risk rather than a one-off technical glitch. Recommended steps include escalating any ransom demand tied to a takedown threat directly to legal and trust and safety teams instead of negotiating, monitoring for suspicious message edit activity, and maintaining a rapid response plan for platform or app store enforcement events. That plan should define who investigates, how evidence is preserved, and how the organization communicates with members and platform partners like Apple during an incident.

Key findings

  • Telegram CEO alleged an extortionist planted CSAM in a public chat to trigger temporary App Store removal.
  • The attacker allegedly hid the illegal content by editing an old message so members wouldn’t see/report it.
  • Telegram claims the actors demand ransom from group owners to avoid being targeted and reported to Apple.

Who’s being targeted

  • Commonly targeted roles: Community managers, Moderators, Trust & Safety teams, Legal, Executive leadership for crisis response.
  • Affected industries: Online platforms / social media communities, Technology, Media.
  • Attack channels: telegram, website.
  • Impersonated: Extortionist posing as a “ransom” enforcer targeting Telegram group owners, Regular group participant/account (including automated accounts).

Red flags to watch for

  • Ransom/extortion demand tied to platform takedown threats
  • Threat involves planting/reporting illegal content rather than a legitimate policy dispute
  • Pressure tactics implying immediate consequences if payment isn’t made
  • Unusual message edits of older content in high-traffic chats
  • Reports/enforcement actions that members say they never saw in-chat
  • Suspicious new/automated accounts interacting with old posts
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did extortionists get Telegram removed from the App Store?

According to Telegram, an attacker planted child sexual abuse material by editing an old message in an active public group, then reported the group directly to Apple to trigger removal.

Why didn't group members notice the illegal content?

The attacker allegedly hid the content by editing an older message in the chat, which kept it from appearing as new activity that members would see or report themselves.

What is the extortion angle in this attack?

Telegram claims the threat actors demand ransom from group owners in exchange for not targeting their communities with this planting-and-reporting tactic.

What should community managers do about this threat?

Treat ransom demands tied to platform takedown threats as a real risk, escalate to legal and trust-and-safety teams, and watch for suspicious edits to older messages.

Read the video transcript

Imagine your Telegram community getting an Apple App Store ban… because someone secretly edited an old message in your chat. Telegram’s CEO says extortionists plant illegal content in public groups, then report it to Apple to get Telegram briefly pulled, demanding ransom from group owners not to target their communities. Here’s the trick: they don’t post in the live chat. They edit an old message, so members never see it to report it, only the platform sees it when they file the complaint. If you ever get a ransom note tied to Telegram or App Store takedown threats, don’t negotiate, escalate it immediately to our legal or trust-and-safety team.

Similar attacks

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Researchers say a real macOS malware campaign is using “ClickFix” social engineering to trick users into installing an infostealer called AmnesiaStealer. Victims are lured to a counterfeit GitHub download page that encourages them to copy/paste a Terminal command, which then downloads and runs the…

August 14, 2026
Handala Uses Fake “Support” Chats to Drop Malware

Handala Uses Fake “Support” Chats to Drop Malware

Researchers linked the Iran-aligned Handala Hack persona to a Telegram-controlled backdoor (HEAVYGRAM) that can steal passwords and exfiltrate chat data. The campaign reportedly starts with social engineering on messaging apps (Telegram, WhatsApp, Instagram), where the attacker pretends to offer…

September 18, 2026
Iranian “Chosen Brick” Lures Sent via Telegram

Iranian “Chosen Brick” Lures Sent via Telegram

UK, US, and Dutch agencies warned that Iranian state-linked actors used social messaging apps to build trust with dissidents, journalists, and activists before sending disguised files that install Windows malware. The attackers often impersonated someone the target already knows or “technical…

September 17, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026
Iranian Spies Lure Targets via WhatsApp to Drop Malware

Iranian Spies Lure Targets via WhatsApp to Drop Malware

A joint UK-US-Dutch advisory warns Iranian state-backed cyber actors are targeting dissidents, activists, and journalists by first contacting them on WhatsApp or Telegram and building trust. The attackers then persuade victims to open a malicious file disguised as legitimate software (or even MRI…

September 16, 2026
Iran-Backed Spyware Uses Fake Support Chats

Iran-Backed Spyware Uses Fake Support Chats

UK and allied agencies warn that a Tehran-backed operation is targeting dissidents, activists, and journalists using social engineering to trick them into installing spyware called “Chosen Brick.” Attackers build trust on social media by impersonating known contacts or “technical support,” then…

September 16, 2026