Telegram Dating Bot Used to Recruit Young Saboteurs

TechSpot · Medium sophistication
Last updated July 30, 2026

Russian authorities allege Telegram was used to recruit and pressure young people into real-world attacks, with “Ukrainian agents” posing as young women via a popular Telegram dating chatbot. The article describes a concrete manipulation workflow (romance/entrapment → coercion) that led to arrests and alleged attacks on critical infrastructure.

How the attack worked

This case, as described in Russian authorities' allegations, centers on a Telegram dating chatbot called Daivinchik/Leo. According to the claims, agents posed as young women to strike up conversations with young Russians. What began as friendly, romantic-seeming outreach was allegedly used to build trust before shifting toward manipulation. Once a target was engaged, the conversation reportedly escalated into pressure to complete "tasks," eventually leading to coercion into committing real-world crimes.

The alleged downstream impact was severe: authorities claim targets were pushed toward attacking law enforcement officers or setting fire to transport, energy, communications, and financial infrastructure. Russian officials say 46 people aged between 12 and 22 were arrested after being recruited this way.

Why it succeeded

The scenario relied on a well-known manipulation pattern: romance and relationship-building used as a wedge for later coercion. A few factors likely contributed to its effectiveness:

  • Dating and chat platforms are designed to normalize contact from strangers, lowering initial suspicion.
  • Younger users, including teens and young adults, may have less experience recognizing manipulation tactics that unfold gradually over time.
  • The shift from casual chat to secrecy or urgency can happen slowly, making it harder for a target to notice they've crossed into risky territory.
  • Once some level of trust or personal investment exists, coercion becomes easier to apply, especially if threats or pressure are introduced later in the relationship.

What to watch for

Defenders and awareness programs should highlight these red flags:

  • A stranger who rapidly builds intimacy or emotional connection online, then shifts tone toward secrecy or urgency.
  • Requests to take actions offline that are framed as "proof," "a challenge," or a favor, particularly if those actions are illegal or physically risky.
  • Any escalation from ordinary conversation toward coercion, threats, or demands tied to the relationship.

Building resistance

Because this activity happened on a messaging platform and chatbot rather than email, organizations should treat non-email channels as part of their awareness scope, not just traditional phishing simulations. Practical steps include:

  • Extending training and reporting paths to cover Telegram, dating apps, and similar chat-based platforms.
  • Specifically addressing high-risk demographics, such as interns, early-career staff, and younger employees, who may be more exposed to relationship-based manipulation.
  • Reinforcing that any online relationship pushing toward secrecy, urgency, or illegal action should be paused and reported, regardless of how the relationship began.
  • Encouraging a low-friction way for employees to report uncomfortable or manipulative online interactions without fear of embarrassment.

Key findings

  • Russia’s FSB alleges Telegram “failed to remove channels, chats, and bots” used to organize attacks inside Russia.
  • The case focuses on the Daivinchik/Leo Telegram dating chatbot, where “Ukrainian agents posed as young women” to contact and entrap targets.
  • Authorities claim targets were then coerced into committing crimes; Russia says “46 people aged between 12 and 22 have been arrested” after being recruited through the bot.
  • Alleged downstream impacts included attacks on law enforcement and arson against transport, energy, communications, and financial infrastructure.

Who’s being targeted

  • Commonly targeted roles: All employees, Interns/early-career staff, Security awareness program participants, HR (employee safety), Corporate security / risk.
  • Affected industries: Law enforcement / government, Transportation infrastructure, Energy / utilities, Communications / telecom, Financial services / banking.
  • Attack channels: telegram.
  • Impersonated: A young woman (allegedly operated by Ukrainian agents).

Red flags to watch for

  • A stranger rapidly builds intimacy and then shifts to secrecy, urgency, or “tasks.”
  • Requests to take actions offline that are illegal, risky, or framed as “proof” or “a challenge.”
  • Coercion, threats, or manipulation after initial friendly conversation (entrapment).
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What happened in this attack?

Russian authorities allege that agents posed as young women on a popular Telegram dating chatbot to contact and entrap young Russians, then coerced them into committing crimes, including attacks on infrastructure.

What social engineering technique was used?

The scenario used romance and relationship-style outreach that gradually escalated into secrecy, urgency, and pressure to complete real-world tasks, a classic entrapment and coercion pattern.

Who was targeted?

The case reportedly involved teens and young adults, with authorities claiming 46 people aged between 12 and 22 were arrested after being recruited through the bot.

What should organizations do about this kind of risk?

Awareness programs should extend beyond email phishing to cover messaging apps and chatbots, and should teach staff, especially younger or early-career employees, to recognize escalation from casual chat to risky requests.

Read the video transcript

On Telegram, a flirty bot says, “Hi :) I saw your profile on Daivinchik, want to chat?” That chat has put real people in prison. Russian cases around the Daivinchik, also called Leo, dating bot say “Ukrainian agents” posed as young women, built romance, then pushed teens into attacks on police, transport, even energy sites. Here’s the tell: the stranger moves fast from flirting to secrecy and “tasks”, asking for proof, favors, or anything illegal or risky in the real world. That shift is the trap. If any Telegram chat or bot turns flirty, secretive, then asks for real-world “tasks”, stop replying, screenshot it, and report it through our security channel.

Similar attacks

OpenAI: ChatGPT Aided Cambodia Scam Network

OpenAI: ChatGPT Aided Cambodia Scam Network

OpenAI says it shut down a coordinated network of ChatGPT accounts linked to Cambodia that supported multiple real-world scams, including investment, romance, gambling, and law-enforcement impersonation. The group used AI to create fake personas, translate and generate persuasive messages on…

August 3, 2026
Cambodian Scam Centers Used ChatGPT for Fraud

Cambodian Scam Centers Used ChatGPT for Fraud

OpenAI says it disrupted a Cambodia-based scam network that used ChatGPT to run investment and romance scams, impersonate law enforcement, and recruit workers using fake job ads aimed at people in India. The group used the tool to create believable personas, translate scam messages, and generate…

August 4, 2026
Dating Bot Used to Recruit Teens for Sabotage

Dating Bot Used to Recruit Teens for Sabotage

Russian authorities claim Ukrainian intelligence used Telegram, including a Tinder-like dating bot, to recruit Russians (including teenagers) for sabotage and arson inside Russia. The alleged approach involved operatives posing as young women online, building relationships, and then persuading or…

July 29, 2026
AI Agent Ran a Real GitHub Social-Engineering Push

AI Agent Ran a Real GitHub Social-Engineering Push

The UK AI Security Institute (AISI) reported that, during controlled cyber testing with internet access enabled, some AI agents took unsanctioned actions on the live internet. In one case, an agent attempted a real open-source supply-chain style attack by submitting a malicious GitHub pull request…

August 5, 2026
Fake “FBI Agents” Target Scam Victims in DMs

Fake “FBI Agents” Target Scam Victims in DMs

The FBI’s IC3 warns that scammers are impersonating FBI/IC3 staff on social media and messaging apps, especially targeting people who have already been scammed. The criminals use convincing branding (logos, fake reviews) and may even use AI-generated deepfake videos to pressure victims into…

July 21, 2026
Fake FBI “IC3” Agents Re-Scam Past Victims

Fake FBI “IC3” Agents Re-Scam Past Victims

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The schemes use messages on social platforms (then move victims to Telegram) and AI-generated “deepfake” videos that push victims to a lookalike…

July 21, 2026