Extortionists Plant CSAM to Get Telegram Banned

The Hacker News · Medium sophistication
Last updated August 7, 2026

Telegram says extortionists are planting illegal content into public group chats, then reporting it to Apple to trigger App Store takedowns. The alleged goal is to pressure group owners into paying ransom to avoid being targeted. The trick relies on hiding the illegal content by editing an older message so group members don’t notice or report it first.

What happened

Telegram's CEO alleged that an extortionist planted child sexual abuse material (CSAM) into a public group chat in order to get the app briefly removed from Apple's App Store. Rather than posting new illegal content that moderation systems and members would quickly catch, the attacker reportedly edited an older message in an active chat to insert the material. This made the content effectively invisible to group members, since edits to old messages don't surface the way new posts do.

The extortion mechanism

According to Telegram, the actors behind this tactic use automated accounts to plant illegal content in public groups and then report it directly to Apple, attempting to trigger removal of legitimate communities whose owners refused to pay them. The stated goal is ransom: group owners are pressured to pay to avoid being targeted this way. This turns a platform's own enforcement and reporting channels into a weapon against the very communities they're meant to protect.

Why it succeeded

The technique worked around normal safeguards in a few ways:

  • Editing an old message avoided the scrutiny that new posts typically receive from both members and automated moderation tools.
  • Automated accounts could plant content and file reports quickly, without relying on human coordination that might be noticed.
  • The report was routed to an external party (Apple's App Store review process) rather than staying inside Telegram's own moderation pipeline, adding pressure through a channel the group owner doesn't control.

What to watch for

Community managers, moderators, and trust and safety teams should be alert to:

  • Ransom or extortion demands tied to threats of platform or app store takedown
  • Unexplained edits to older messages in high-traffic public groups
  • Enforcement actions or removals tied to content that members say they never saw
  • Suspicious or newly created automated accounts interacting with old posts

Building resistance

Organizations that run public communities should treat this as a real social engineering and extortion risk rather than a one-off technical glitch. Recommended steps include escalating any ransom demand tied to a takedown threat directly to legal and trust and safety teams instead of negotiating, monitoring for suspicious message edit activity, and maintaining a rapid response plan for platform or app store enforcement events. That plan should define who investigates, how evidence is preserved, and how the organization communicates with members and platform partners like Apple during an incident.

Key findings

  • Telegram CEO alleged an extortionist planted CSAM in a public chat to trigger temporary App Store removal.
  • The attacker allegedly hid the illegal content by editing an old message so members wouldn’t see/report it.
  • Telegram claims the actors demand ransom from group owners to avoid being targeted and reported to Apple.

Who’s being targeted

  • Commonly targeted roles: Community managers, Moderators, Trust & Safety teams, Legal, Executive leadership for crisis response.
  • Affected industries: Online platforms / social media communities, Technology, Media.
  • Attack channels: telegram, website.
  • Impersonated: Extortionist posing as a “ransom” enforcer targeting Telegram group owners, Regular group participant/account (including automated accounts).

Red flags to watch for

  • Ransom/extortion demand tied to platform takedown threats
  • Threat involves planting/reporting illegal content rather than a legitimate policy dispute
  • Pressure tactics implying immediate consequences if payment isn’t made
  • Unusual message edits of older content in high-traffic chats
  • Reports/enforcement actions that members say they never saw in-chat
  • Suspicious new/automated accounts interacting with old posts
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did extortionists get Telegram removed from the App Store?

According to Telegram, an attacker planted child sexual abuse material by editing an old message in an active public group, then reported the group directly to Apple to trigger removal.

Why didn't group members notice the illegal content?

The attacker allegedly hid the content by editing an older message in the chat, which kept it from appearing as new activity that members would see or report themselves.

What is the extortion angle in this attack?

Telegram claims the threat actors demand ransom from group owners in exchange for not targeting their communities with this planting-and-reporting tactic.

What should community managers do about this threat?

Treat ransom demands tied to platform takedown threats as a real risk, escalate to legal and trust-and-safety teams, and watch for suspicious edits to older messages.

Read the video transcript

Imagine your Telegram community getting an Apple App Store ban… because someone secretly edited an old message in your chat. Telegram’s CEO says extortionists plant illegal content in public groups, then report it to Apple to get Telegram briefly pulled, demanding ransom from group owners not to target their communities. Here’s the trick: they don’t post in the live chat. They edit an old message, so members never see it to report it, only the platform sees it when they file the complaint. If you ever get a ransom note tied to Telegram or App Store takedown threats, don’t negotiate, escalate it immediately to our legal or trust-and-safety team.

Similar attacks

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Researchers say a real macOS malware campaign is using “ClickFix” social engineering to trick users into installing an infostealer called AmnesiaStealer. Victims are lured to a counterfeit GitHub download page that encourages them to copy/paste a Terminal command, which then downloads and runs the…

August 14, 2026
Instagram Copyright Strikes Used for Ransom

Instagram Copyright Strikes Used for Ransom

Scammers are filing fake copyright complaints to get Instagram accounts temporarily suspended, then demanding money to “withdraw” the complaint and restore access. Victims are pushed to communicate off-platform (for example, on Telegram) and asked to pay in cryptocurrency, yet even paying doesn’t…

September 10, 2026
Fake GTA 6 Demo Sites Push Password Stealer

Fake GTA 6 Demo Sites Push Password Stealer

Attackers are exploiting GTA 6 hype by creating convincing fake Rockstar-branded “demo” websites that appear in Google search results. The sites use “Play Now”/“Official Download” lures to trick people into downloading a small Windows executable that installs Vidar infostealer and steals saved…

August 24, 2026
Typosquat RubyGems Stealer Hits Dev Machines

Typosquat RubyGems Stealer Hits Dev Machines

Researchers found 16 look‑alike (typosquatted) RubyGems packages that trick developers into installing a Windows information stealer. The malicious gems run code automatically during installation, pull down additional malware, and then steal browser logins and crypto wallet data before uploading it…

August 18, 2026
Vishing Console + Fake CCleaner Trap Users

Vishing Console + Fake CCleaner Trap Users

This bulletin highlights multiple real-world threats, including voice-phishing (vishing) operations that industrialize account takeovers and a fake CCleaner download site that installs spyware. The items provide concrete, repeatable lures (a vishing-driven takeover workflow and a lookalike software…

August 17, 2026
Fake GitHub Lure Spreads AmnesiaStealer on macOS

Fake GitHub Lure Spreads AmnesiaStealer on macOS

Researchers describe AmnesiaStealer, a macOS infostealer spread via a convincing fake GitHub download page that tricks users into pasting a Terminal command. After installation, it uses an “Installer”-style password prompt to capture the Mac login password, steal browser and keychain data, and can…

August 14, 2026