Telegram Dating Bot Used for Romance-to-Arson Scam

The Hacker News · Medium sophistication
Last updated July 30, 2026

Russia’s FSB claims Ukrainian intelligence used a Telegram dating chatbot to deceive and psychologically pressure young Russians into sharing locations, clicking phishing links, and later carrying out arson or armed attacks. The alleged scheme started with romance-style outreach and payments via phishing links, then escalated to intimidation calls/messages impersonating Russian authorities. The article provides a step-by-step workflow that can be adapted into realistic awareness simulations.

How the attack unfolded

This case describes a two-phase social engineering operation that allegedly began on a Telegram dating chatbot. Agents posed as young women to build romantic relationships with targets, then asked them to share their geolocation for a meeting and to pay for movie tickets, concert tickets, or gifts through phishing links. This first phase relied on trust built through ordinary romantic chat, making the payment request feel like a normal next step rather than a scam.

The second phase shifted the pretext entirely. Impostors posing as Russian law enforcement authorities or officials from Rosfinmonitoring contacted the same targets through messaging apps, claiming that the money they had sent earlier had ended up funding hostile military activity. Under threat of criminal prosecution, targets were allegedly coerced into pseudo-operational tasks, including arson and armed attacks.

Why this approach succeeded

The scheme worked by combining two very different manipulation styles in sequence. The romance phase lowered defenses through emotional investment, making a request to click a link or share a location feel routine. The authority-impersonation phase then used fear and legal threats to override critical thinking. Targets were reportedly left unable to critically assess the situation due to psychological pressure, which is a common outcome when urgency and intimidation are layered on top of an existing relationship of trust.

What to watch for

  • A new online romantic contact who quickly asks for payment through a link rather than a known, trusted site
  • Requests to share a precise location for a first meeting with someone known only online
  • Unexpected contact from someone claiming to be law enforcement or a financial authority over a messaging app
  • Threats of prosecution used to force immediate compliance or continued "cooperation"
  • Claims that a routine past action, like buying a gift or ticket, is now tied to terrorism financing or criminal activity

Building resistance to this pattern

Awareness efforts should emphasize that legitimate authorities do not conduct financial investigations through casual messaging apps and do not threaten immediate prosecution to compel action. People should be encouraged to pause before clicking payment links shared by online contacts and to verify any claimed law enforcement contact through channels they look up themselves, not ones provided by the person contacting them. Training should also highlight that emotional pressure, whether romantic or fear-based, is a manipulation signal in itself. When a conversation moves from small favors to high-stakes demands, that shift is worth treating as a red flag rather than a natural escalation of trust.

Key findings

  • FSB alleges Telegram “failed to remove” channels/bots used for sabotage, terrorism coordination, and “cyber-fraud operations.”
  • A Telegram chatbot (“Daivinchik/Leo-Dating, Chatting, and New Friends”) was allegedly used to recruit targets using “deception and psychological manipulation.”
  • Agents allegedly “masquerade as young women,” build romantic relationships, then request geolocation and push payment for tickets/gifts through “phishing links.”
  • A second phase allegedly involved impersonation of “Russian law enforcement authorities or officials from Rosfinmonitoring” to intimidate targets into “pseudo-operational activities,” including arson/attacks.

Who’s being targeted

  • Commonly targeted roles: All employees (general awareness), Students/young adults (if applicable), Security awareness training teams, Physical security and critical facility staff, Fraud/finance teams (for phishing-link and money-mule awareness).
  • Affected industries: Government and public sector, Critical infrastructure (transport, energy, communications), Financial services/infrastructure.
  • Attack channels: telegram, website.
  • Impersonated: A young woman met via the Daivinchik/Leo dating chatbot, Russian law enforcement / Rosfinmonitoring (Federal Financial Monitoring Service).

Red flags to watch for

  • A new online romantic contact quickly asks you to pay via a link
  • Unfamiliar link for payments instead of trusted ticketing/retail sites
  • Request to share precise location for a first meeting
  • Threats of criminal prosecution used to force immediate compliance
  • Unexpected contact claiming to be authorities over messaging apps
  • Claims that routine actions (tickets/gifts) are tied to terrorism financing
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the Telegram dating bot scam start?

Agents allegedly posed as young women on the Daivinchik/Leo dating chatbot to build romantic relationships with targets, then asked for their location and pushed them to pay for gifts or tickets through phishing links.

How did the scam escalate to arson or armed attacks?

After the romance phase, impostors allegedly posed as Russian law enforcement or Rosfinmonitoring officials and claimed the targets' payments had funded a hostile military, then used threats of criminal prosecution to coerce them into pseudo-operational tasks including arson and armed attacks.

What red flags should people watch for in this type of scam?

Warning signs include a new online romantic contact quickly asking for payment via an unfamiliar link, requests to share a precise meeting location, and unexpected messages from people claiming to be authorities who threaten prosecution to force immediate compliance.

Who is most at risk from this kind of manipulation?

The scenario targeted young Russian men through a dating chatbot, but the underlying tactics apply broadly to students, young adults, and general users of messaging apps who interact with unknown online contacts.

Read the video transcript

Imagine this: a Telegram dating bot, Daivinchik, flirts with you… and weeks later someone’s ordering you to commit a crime. FSB says Ukrainian agents used this bot to masquerade as young women, build romance, then ask for your geolocation and for you to buy movie or concert tickets through a phishing link. Then phase two: someone messages you on Telegram, claiming to be Russian law enforcement or Rosfinmonitoring, saying your ticket payment funded the Armed Forces of Ukraine and threatening prosecution unless you ‘cooperate.’ Your move: if a new online romance sends payment links or anyone on Telegram claims to be law enforcement and threatens you, stop, don’t click, and verify using official contacts you look up yourself.

Similar attacks

Fake Public Security App Spreads Android RAT

Fake Public Security App Spreads Android RAT

Researchers tied the Flying Eagle Android remote-access trojan to a fake “Public Security” service app aimed at Android users in China. The malicious app was…

July 29, 2026
LogoKit Builds Real-Time Fake Login Pages

LogoKit Builds Real-Time Fake Login Pages

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the…

July 29, 2026