Telegram “Security Alert” Phish Hijacks Accounts

The Record · High sophistication
Last updated July 30, 2026

Researchers documented a real phishing operation that used Telegram “secret chats” to send fake security warnings to specific people, including an exiled Belarusian activist and users in Russia and Kazakhstan. Victims were pushed to click a personalized link and enter Telegram’s one-time login code (OTP), which would allow attackers to immediately take over the account. The campaign used anti-detection tricks (device checks, redirects, look‑alike characters) and follow-up pressure messages to increase success.

How the attack worked

The operation began with a fake Telegram security alert sent through the app's own end-to-end encrypted secret chat feature, from an unfamiliar account. The message claimed the recipient had violated Telegram's rules and warned that the account would be blocked unless they clicked a link to verify it. Instead of delivering malware, the goal was simpler and faster: trick the victim into entering Telegram's one-time login code (OTP) on a fake page. If the victim entered the code before it expired, attackers could immediately take over the account.

Each phishing link was individualized and included the target's phone number, letting operators track exactly who opened it. After a click, operators followed up with a second message claiming verification was still incomplete and citing suspicious activity, along with details about the victim's device, click time, and internet service provider, information collected the moment the link was opened.

Why it succeeded

Several factors made this campaign effective against specific, high-value targets:

  • The initial contact came through a private, encrypted channel, which can create a false sense of trust compared to email or SMS.
  • Urgency and threat of account loss pushed targets to act quickly rather than verify through official channels.
  • The follow-up message reused personal details gathered during the first click to appear more legitimate and increase pressure.
  • Infrastructure performed visitor checks and redirected security tools or unintended visitors to Telegram's real site or other harmless pages, reducing the chance of detection.
  • Messages disguised text by mixing Cyrillic with visually similar Latin and Greek characters, helping bypass automated content filters.

What to watch for

  • Unfamiliar accounts contacting you via secret chat or private message with account-blocking threats.
  • Any request to enter a one-time login code through a link rather than the app's own settings.
  • Follow-up messages that cite your device, location, or provider as a scare tactic.
  • Personalized links containing your phone number or other identifying details.

Building resistance

Treat any message warning of imminent account suspension as suspicious, especially from unknown senders. Never enter an OTP into a page reached via a chat link. Verify account status only through official in-app security settings. Because attackers can tailor pages to evade automated scanners and disguise text with look-alike characters, absence of an automated warning does not mean a message is safe, human judgment remains the last line of defense for high-risk users such as journalists, activists, and communications staff.

Key findings

  • Attackers initiated contact via Telegram secret chat, sending a fake “security alert” that threatened account blocking unless the victim verified via a link.
  • Phishing links were individualized and included the target’s phone number so attackers could track who opened them.
  • Goal was to steal Telegram’s one-time login code (OTP) and immediately hijack the account, no malware required.
  • Infrastructure performed visitor checks (browser/device) and showed the fake login only to intended targets; others were redirected to Telegram or benign pages to evade detection.
  • Operators sent a second pressure message after link clicks, including victim device, time of click, and ISP to appear legitimate.
  • Messages used look‑alike characters (Cyrillic mixed with Latin/Greek) to bypass automated detection.

Who’s being targeted

  • Commonly targeted roles: Executives, Communications/PR, Journalists/Media teams, HR/People Ops (highly targeted individuals), Any staff using Telegram or other messaging apps for work.
  • Affected industries: Civil society / NGOs, Journalism / media (activists and journalists mentioned).
  • Attack channels: telegram, website.
  • Impersonated: Telegram Security/Support (fake).

Red flags to watch for

  • Unfamiliar Telegram account contacting you via secret chat
  • Threat/urgency: account will be blocked unless you act
  • Requests for a one-time login code (OTP) via a link
  • Message includes personal device/ISP details to intimidate rather than prove legitimacy
  • Pushes you back to a link instead of using in-app official security settings
  • Continues escalating urgency after you already interacted once
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the Telegram phishing attack steal accounts without malware?

Attackers sent a fake security alert through a Telegram secret chat claiming the account would be blocked unless the victim clicked a link and entered their one-time login code. Entering that code allowed attackers to immediately take control of the account, no malware required.

How did attackers avoid getting caught by security tools?

The phishing infrastructure checked each visitor's browser and device, showing the fake login page only to intended targets while redirecting security tools and unrelated visitors to Telegram's real site or other harmless pages. Messages also swapped in look-alike Latin and Greek characters to evade automated text detection.

Why did the follow-up message include my device and internet provider?

After a target clicked the link, operators sent a second message citing details like device type, click time, and ISP that were collected when the link was opened. This was likely meant to make the warning look legitimate and pressure the victim into completing the fake verification.

What should I do if I get a Telegram message warning my account will be blocked?

Do not click the link or enter any one-time code sent through chat. Verify account status directly through Telegram's official in-app security settings instead.

Read the video transcript

Imagine this: a Telegram secret chat pops up, claiming you broke the rules and your account will be blocked unless you verify it now. The link they send is customized with your phone number. You tap it, and a perfect Telegram login page appears, asking for the one-time code just sent to your phone. The moment you type that OTP, they can hijack your account, no malware, no password needed. Here’s the creepy part: after you click, they send a second message quoting your device, time, even your internet provider to sound legit and push you to finish. Tools might see only real Telegram pages, but you see the trap. Your move: if any Telegram chat, especially an unknown secret chat, asks you to enter a one-time code from a link, stop and check your account only through Telegram’s official app settings.

Similar attacks

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Malicious GitHub Issue Can Hijack AI Coding Agents

Malicious GitHub Issue Can Hijack AI Coding Agents

Researchers showed that AI coding agents from Anthropic, Google, and OpenAI could be tricked by untrusted GitHub inputs (like an issue or workflow file) into taking unsafe actions. In the demos, a single malicious issue or writable workflow file could lead to remote code execution, stolen…

August 6, 2026
Fake Job Interview Lure Targets Crypto Staff

Fake Job Interview Lure Targets Crypto Staff

A North Korea-linked group is running fake recruitment campaigns to trick people into taking “online assessments” for jobs that don’t exist. The goal is to harvest personal details and potentially compromise corporate access, especially targeting non-technical staff in crypto firms who can…

July 30, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Teams Phishing Rises After Tycoon2FA Takedown

Teams Phishing Rises After Tycoon2FA Takedown

Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics rather than stop. The report highlights real campaigns that shifted toward Microsoft Teams-based social engineering, highly automated BEC…

July 24, 2026