Extortionists Plant CSAM to Get Telegram Banned

The Hacker News · Medium sophistication
Last updated August 7, 2026

Telegram says extortionists are planting illegal content into public group chats, then reporting it to Apple to trigger App Store takedowns. The alleged goal is to pressure group owners into paying ransom to avoid being targeted. The trick relies on hiding the illegal content by editing an older message so group members don’t notice or report it first.

What happened

Telegram's CEO alleged that an extortionist planted child sexual abuse material (CSAM) into a public group chat in order to get the app briefly removed from Apple's App Store. Rather than posting new illegal content that moderation systems and members would quickly catch, the attacker reportedly edited an older message in an active chat to insert the material. This made the content effectively invisible to group members, since edits to old messages don't surface the way new posts do.

The extortion mechanism

According to Telegram, the actors behind this tactic use automated accounts to plant illegal content in public groups and then report it directly to Apple, attempting to trigger removal of legitimate communities whose owners refused to pay them. The stated goal is ransom: group owners are pressured to pay to avoid being targeted this way. This turns a platform's own enforcement and reporting channels into a weapon against the very communities they're meant to protect.

Why it succeeded

The technique worked around normal safeguards in a few ways:

  • Editing an old message avoided the scrutiny that new posts typically receive from both members and automated moderation tools.
  • Automated accounts could plant content and file reports quickly, without relying on human coordination that might be noticed.
  • The report was routed to an external party (Apple's App Store review process) rather than staying inside Telegram's own moderation pipeline, adding pressure through a channel the group owner doesn't control.

What to watch for

Community managers, moderators, and trust and safety teams should be alert to:

  • Ransom or extortion demands tied to threats of platform or app store takedown
  • Unexplained edits to older messages in high-traffic public groups
  • Enforcement actions or removals tied to content that members say they never saw
  • Suspicious or newly created automated accounts interacting with old posts

Building resistance

Organizations that run public communities should treat this as a real social engineering and extortion risk rather than a one-off technical glitch. Recommended steps include escalating any ransom demand tied to a takedown threat directly to legal and trust and safety teams instead of negotiating, monitoring for suspicious message edit activity, and maintaining a rapid response plan for platform or app store enforcement events. That plan should define who investigates, how evidence is preserved, and how the organization communicates with members and platform partners like Apple during an incident.

Key findings

  • Telegram CEO alleged an extortionist planted CSAM in a public chat to trigger temporary App Store removal.
  • The attacker allegedly hid the illegal content by editing an old message so members wouldn’t see/report it.
  • Telegram claims the actors demand ransom from group owners to avoid being targeted and reported to Apple.

Who’s being targeted

  • Commonly targeted roles: Community managers, Moderators, Trust & Safety teams, Legal, Executive leadership for crisis response.
  • Affected industries: Online platforms / social media communities, Technology, Media.
  • Attack channels: telegram, website.
  • Impersonated: Extortionist posing as a “ransom” enforcer targeting Telegram group owners, Regular group participant/account (including automated accounts).

Red flags to watch for

  • Ransom/extortion demand tied to platform takedown threats
  • Threat involves planting/reporting illegal content rather than a legitimate policy dispute
  • Pressure tactics implying immediate consequences if payment isn’t made
  • Unusual message edits of older content in high-traffic chats
  • Reports/enforcement actions that members say they never saw in-chat
  • Suspicious new/automated accounts interacting with old posts
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did extortionists get Telegram removed from the App Store?

According to Telegram, an attacker planted child sexual abuse material by editing an old message in an active public group, then reported the group directly to Apple to trigger removal.

Why didn't group members notice the illegal content?

The attacker allegedly hid the content by editing an older message in the chat, which kept it from appearing as new activity that members would see or report themselves.

What is the extortion angle in this attack?

Telegram claims the threat actors demand ransom from group owners in exchange for not targeting their communities with this planting-and-reporting tactic.

What should community managers do about this threat?

Treat ransom demands tied to platform takedown threats as a real risk, escalate to legal and trust-and-safety teams, and watch for suspicious edits to older messages.

Read the video transcript

Imagine your Telegram community getting an Apple App Store ban… because someone secretly edited an old message in your chat. Telegram’s CEO says extortionists plant illegal content in public groups, then report it to Apple to get Telegram briefly pulled, demanding ransom from group owners not to target their communities. Here’s the trick: they don’t post in the live chat. They edit an old message, so members never see it to report it, only the platform sees it when they file the complaint. If you ever get a ransom note tied to Telegram or App Store takedown threats, don’t negotiate, escalate it immediately to our legal or trust-and-safety team.

Similar attacks

ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026
ClickFix Uses Fingerprinting to Target Mac Users

ClickFix Uses Fingerprinting to Target Mac Users

Microsoft tracked a real macOS ClickFix campaign using 250+ domains that fingerprint visitors to hide malicious pages from security scanners. Selected Mac users are shown a fake “Download for macOS” lure and prompted to copy/paste an obfuscated command into Terminal, which then pulls down scripts…

August 5, 2026
Cloaked Mac ClickFix Sites Push Terminal Infostealers

Cloaked Mac ClickFix Sites Push Terminal Infostealers

Microsoft Threat Intelligence tracked a real macOS “ClickFix” campaign that uses look‑alike domains to trick Mac users into copying and running a Terminal command. The operation now hides the malicious “Download for macOS” lure behind server-side browser fingerprinting, showing benign decoy pages…

August 5, 2026