Telegram Dating Bot Used to Recruit Young Saboteurs

TechSpot · Medium sophistication
Last updated July 30, 2026

Russian authorities allege Telegram was used to recruit and pressure young people into real-world attacks, with “Ukrainian agents” posing as young women via a popular Telegram dating chatbot. The article describes a concrete manipulation workflow (romance/entrapment → coercion) that led to arrests and alleged attacks on critical infrastructure.

How the attack worked

This case, as described in Russian authorities' allegations, centers on a Telegram dating chatbot called Daivinchik/Leo. According to the claims, agents posed as young women to strike up conversations with young Russians. What began as friendly, romantic-seeming outreach was allegedly used to build trust before shifting toward manipulation. Once a target was engaged, the conversation reportedly escalated into pressure to complete "tasks," eventually leading to coercion into committing real-world crimes.

The alleged downstream impact was severe: authorities claim targets were pushed toward attacking law enforcement officers or setting fire to transport, energy, communications, and financial infrastructure. Russian officials say 46 people aged between 12 and 22 were arrested after being recruited this way.

Why it succeeded

The scenario relied on a well-known manipulation pattern: romance and relationship-building used as a wedge for later coercion. A few factors likely contributed to its effectiveness:

  • Dating and chat platforms are designed to normalize contact from strangers, lowering initial suspicion.
  • Younger users, including teens and young adults, may have less experience recognizing manipulation tactics that unfold gradually over time.
  • The shift from casual chat to secrecy or urgency can happen slowly, making it harder for a target to notice they've crossed into risky territory.
  • Once some level of trust or personal investment exists, coercion becomes easier to apply, especially if threats or pressure are introduced later in the relationship.

What to watch for

Defenders and awareness programs should highlight these red flags:

  • A stranger who rapidly builds intimacy or emotional connection online, then shifts tone toward secrecy or urgency.
  • Requests to take actions offline that are framed as "proof," "a challenge," or a favor, particularly if those actions are illegal or physically risky.
  • Any escalation from ordinary conversation toward coercion, threats, or demands tied to the relationship.

Building resistance

Because this activity happened on a messaging platform and chatbot rather than email, organizations should treat non-email channels as part of their awareness scope, not just traditional phishing simulations. Practical steps include:

  • Extending training and reporting paths to cover Telegram, dating apps, and similar chat-based platforms.
  • Specifically addressing high-risk demographics, such as interns, early-career staff, and younger employees, who may be more exposed to relationship-based manipulation.
  • Reinforcing that any online relationship pushing toward secrecy, urgency, or illegal action should be paused and reported, regardless of how the relationship began.
  • Encouraging a low-friction way for employees to report uncomfortable or manipulative online interactions without fear of embarrassment.

Key findings

  • Russia’s FSB alleges Telegram “failed to remove channels, chats, and bots” used to organize attacks inside Russia.
  • The case focuses on the Daivinchik/Leo Telegram dating chatbot, where “Ukrainian agents posed as young women” to contact and entrap targets.
  • Authorities claim targets were then coerced into committing crimes; Russia says “46 people aged between 12 and 22 have been arrested” after being recruited through the bot.
  • Alleged downstream impacts included attacks on law enforcement and arson against transport, energy, communications, and financial infrastructure.

Who’s being targeted

  • Commonly targeted roles: All employees, Interns/early-career staff, Security awareness program participants, HR (employee safety), Corporate security / risk.
  • Affected industries: Law enforcement / government, Transportation infrastructure, Energy / utilities, Communications / telecom, Financial services / banking.
  • Attack channels: telegram.
  • Impersonated: A young woman (allegedly operated by Ukrainian agents).

Red flags to watch for

  • A stranger rapidly builds intimacy and then shifts to secrecy, urgency, or “tasks.”
  • Requests to take actions offline that are illegal, risky, or framed as “proof” or “a challenge.”
  • Coercion, threats, or manipulation after initial friendly conversation (entrapment).
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What happened in this attack?

Russian authorities allege that agents posed as young women on a popular Telegram dating chatbot to contact and entrap young Russians, then coerced them into committing crimes, including attacks on infrastructure.

What social engineering technique was used?

The scenario used romance and relationship-style outreach that gradually escalated into secrecy, urgency, and pressure to complete real-world tasks, a classic entrapment and coercion pattern.

Who was targeted?

The case reportedly involved teens and young adults, with authorities claiming 46 people aged between 12 and 22 were arrested after being recruited through the bot.

What should organizations do about this kind of risk?

Awareness programs should extend beyond email phishing to cover messaging apps and chatbots, and should teach staff, especially younger or early-career employees, to recognize escalation from casual chat to risky requests.

Read the video transcript

On Telegram, a flirty bot says, “Hi :) I saw your profile on Daivinchik, want to chat?” That chat has put real people in prison. Russian cases around the Daivinchik, also called Leo, dating bot say “Ukrainian agents” posed as young women, built romance, then pushed teens into attacks on police, transport, even energy sites. Here’s the tell: the stranger moves fast from flirting to secrecy and “tasks”, asking for proof, favors, or anything illegal or risky in the real world. That shift is the trap. If any Telegram chat or bot turns flirty, secretive, then asks for real-world “tasks”, stop replying, screenshot it, and report it through our security channel.

Similar attacks