Telegram Dating Bot Used to Recruit Young Saboteurs

TechSpot · Medium sophistication
Last updated July 30, 2026

Russian authorities allege Telegram was used to recruit and pressure young people into real-world attacks, with “Ukrainian agents” posing as young women via a popular Telegram dating chatbot. The article describes a concrete manipulation workflow (romance/entrapment → coercion) that led to arrests and alleged attacks on critical infrastructure.

How the attack worked

This case, as described in Russian authorities' allegations, centers on a Telegram dating chatbot called Daivinchik/Leo. According to the claims, agents posed as young women to strike up conversations with young Russians. What began as friendly, romantic-seeming outreach was allegedly used to build trust before shifting toward manipulation. Once a target was engaged, the conversation reportedly escalated into pressure to complete "tasks," eventually leading to coercion into committing real-world crimes.

The alleged downstream impact was severe: authorities claim targets were pushed toward attacking law enforcement officers or setting fire to transport, energy, communications, and financial infrastructure. Russian officials say 46 people aged between 12 and 22 were arrested after being recruited this way.

Why it succeeded

The scenario relied on a well-known manipulation pattern: romance and relationship-building used as a wedge for later coercion. A few factors likely contributed to its effectiveness:

  • Dating and chat platforms are designed to normalize contact from strangers, lowering initial suspicion.
  • Younger users, including teens and young adults, may have less experience recognizing manipulation tactics that unfold gradually over time.
  • The shift from casual chat to secrecy or urgency can happen slowly, making it harder for a target to notice they've crossed into risky territory.
  • Once some level of trust or personal investment exists, coercion becomes easier to apply, especially if threats or pressure are introduced later in the relationship.

What to watch for

Defenders and awareness programs should highlight these red flags:

  • A stranger who rapidly builds intimacy or emotional connection online, then shifts tone toward secrecy or urgency.
  • Requests to take actions offline that are framed as "proof," "a challenge," or a favor, particularly if those actions are illegal or physically risky.
  • Any escalation from ordinary conversation toward coercion, threats, or demands tied to the relationship.

Building resistance

Because this activity happened on a messaging platform and chatbot rather than email, organizations should treat non-email channels as part of their awareness scope, not just traditional phishing simulations. Practical steps include:

  • Extending training and reporting paths to cover Telegram, dating apps, and similar chat-based platforms.
  • Specifically addressing high-risk demographics, such as interns, early-career staff, and younger employees, who may be more exposed to relationship-based manipulation.
  • Reinforcing that any online relationship pushing toward secrecy, urgency, or illegal action should be paused and reported, regardless of how the relationship began.
  • Encouraging a low-friction way for employees to report uncomfortable or manipulative online interactions without fear of embarrassment.

Key findings

  • Russia’s FSB alleges Telegram “failed to remove channels, chats, and bots” used to organize attacks inside Russia.
  • The case focuses on the Daivinchik/Leo Telegram dating chatbot, where “Ukrainian agents posed as young women” to contact and entrap targets.
  • Authorities claim targets were then coerced into committing crimes; Russia says “46 people aged between 12 and 22 have been arrested” after being recruited through the bot.
  • Alleged downstream impacts included attacks on law enforcement and arson against transport, energy, communications, and financial infrastructure.

Who’s being targeted

  • Commonly targeted roles: All employees, Interns/early-career staff, Security awareness program participants, HR (employee safety), Corporate security / risk.
  • Affected industries: Law enforcement / government, Transportation infrastructure, Energy / utilities, Communications / telecom, Financial services / banking.
  • Attack channels: telegram.
  • Impersonated: A young woman (allegedly operated by Ukrainian agents).

Red flags to watch for

  • A stranger rapidly builds intimacy and then shifts to secrecy, urgency, or “tasks.”
  • Requests to take actions offline that are illegal, risky, or framed as “proof” or “a challenge.”
  • Coercion, threats, or manipulation after initial friendly conversation (entrapment).
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What happened in this attack?

Russian authorities allege that agents posed as young women on a popular Telegram dating chatbot to contact and entrap young Russians, then coerced them into committing crimes, including attacks on infrastructure.

What social engineering technique was used?

The scenario used romance and relationship-style outreach that gradually escalated into secrecy, urgency, and pressure to complete real-world tasks, a classic entrapment and coercion pattern.

Who was targeted?

The case reportedly involved teens and young adults, with authorities claiming 46 people aged between 12 and 22 were arrested after being recruited through the bot.

What should organizations do about this kind of risk?

Awareness programs should extend beyond email phishing to cover messaging apps and chatbots, and should teach staff, especially younger or early-career employees, to recognize escalation from casual chat to risky requests.

Read the video transcript

On Telegram, a flirty bot says, “Hi :) I saw your profile on Daivinchik, want to chat?” That chat has put real people in prison. Russian cases around the Daivinchik, also called Leo, dating bot say “Ukrainian agents” posed as young women, built romance, then pushed teens into attacks on police, transport, even energy sites. Here’s the tell: the stranger moves fast from flirting to secrecy and “tasks”, asking for proof, favors, or anything illegal or risky in the real world. That shift is the trap. If any Telegram chat or bot turns flirty, secretive, then asks for real-world “tasks”, stop replying, screenshot it, and report it through our security channel.

Similar attacks

OpenAI: ChatGPT Aided Cambodia Scam Network

OpenAI: ChatGPT Aided Cambodia Scam Network

OpenAI says it shut down a coordinated network of ChatGPT accounts linked to Cambodia that supported multiple real-world scams, including investment, romance, gambling, and law-enforcement impersonation. The group used AI to create fake personas, translate and generate persuasive messages on…

August 3, 2026
Scammers Lure Victims onto Microsoft Teams

Scammers Lure Victims onto Microsoft Teams

Victims in China reported losing thousands to hundreds of thousands of dollars after scammers convinced them to move conversations onto Microsoft Teams using login credentials the scammers provided. Common setups included romance and “investment” pitches (including crypto) and official-sounding law…

August 28, 2026
Fake N. Korean IT Workers Flood Job Applications

Fake N. Korean IT Workers Flood Job Applications

Research says a North Korea–linked operation (“PurpleDelta”) is using fake identities to apply for large volumes of remote IT jobs, sometimes successfully getting hired. Once inside a company, these “employees” can record meetings and steal sensitive information such as source code and internal…

August 19, 2026
Tesla ‘Crypto Presale’ Kit Fuels New Scam Wave

Tesla ‘Crypto Presale’ Kit Fuels New Scam Wave

The article describes real-world social engineering aimed at both consumers and financial firms, including phone-based attacks on hedge funds and a turnkey scam kit that impersonates Tesla to steal cryptocurrency. The kit uses a professional-looking fake presale website with urgency tactics…

August 12, 2026
Cambodian Scam Centers Used ChatGPT for Fraud

Cambodian Scam Centers Used ChatGPT for Fraud

OpenAI says it disrupted a Cambodia-based scam network that used ChatGPT to run investment and romance scams, impersonate law enforcement, and recruit workers using fake job ads aimed at people in India. The group used the tool to create believable personas, translate scam messages, and generate…

August 4, 2026
Dating Bot Used to Recruit Teens for Sabotage

Dating Bot Used to Recruit Teens for Sabotage

Russian authorities claim Ukrainian intelligence used Telegram, including a Tinder-like dating bot, to recruit Russians (including teenagers) for sabotage and arson inside Russia. The alleged approach involved operatives posing as young women online, building relationships, and then persuading or…

July 29, 2026