Telegram “Security Alert” Phish Hijacks Accounts

The Record · High sophistication
Last updated July 30, 2026

Researchers documented a real phishing operation that used Telegram “secret chats” to send fake security warnings to specific people, including an exiled Belarusian activist and users in Russia and Kazakhstan. Victims were pushed to click a personalized link and enter Telegram’s one-time login code (OTP), which would allow attackers to immediately take over the account. The campaign used anti-detection tricks (device checks, redirects, look‑alike characters) and follow-up pressure messages to increase success.

How the attack worked

The operation began with a fake Telegram security alert sent through the app's own end-to-end encrypted secret chat feature, from an unfamiliar account. The message claimed the recipient had violated Telegram's rules and warned that the account would be blocked unless they clicked a link to verify it. Instead of delivering malware, the goal was simpler and faster: trick the victim into entering Telegram's one-time login code (OTP) on a fake page. If the victim entered the code before it expired, attackers could immediately take over the account.

Each phishing link was individualized and included the target's phone number, letting operators track exactly who opened it. After a click, operators followed up with a second message claiming verification was still incomplete and citing suspicious activity, along with details about the victim's device, click time, and internet service provider, information collected the moment the link was opened.

Why it succeeded

Several factors made this campaign effective against specific, high-value targets:

  • The initial contact came through a private, encrypted channel, which can create a false sense of trust compared to email or SMS.
  • Urgency and threat of account loss pushed targets to act quickly rather than verify through official channels.
  • The follow-up message reused personal details gathered during the first click to appear more legitimate and increase pressure.
  • Infrastructure performed visitor checks and redirected security tools or unintended visitors to Telegram's real site or other harmless pages, reducing the chance of detection.
  • Messages disguised text by mixing Cyrillic with visually similar Latin and Greek characters, helping bypass automated content filters.

What to watch for

  • Unfamiliar accounts contacting you via secret chat or private message with account-blocking threats.
  • Any request to enter a one-time login code through a link rather than the app's own settings.
  • Follow-up messages that cite your device, location, or provider as a scare tactic.
  • Personalized links containing your phone number or other identifying details.

Building resistance

Treat any message warning of imminent account suspension as suspicious, especially from unknown senders. Never enter an OTP into a page reached via a chat link. Verify account status only through official in-app security settings. Because attackers can tailor pages to evade automated scanners and disguise text with look-alike characters, absence of an automated warning does not mean a message is safe, human judgment remains the last line of defense for high-risk users such as journalists, activists, and communications staff.

Key findings

  • Attackers initiated contact via Telegram secret chat, sending a fake “security alert” that threatened account blocking unless the victim verified via a link.
  • Phishing links were individualized and included the target’s phone number so attackers could track who opened them.
  • Goal was to steal Telegram’s one-time login code (OTP) and immediately hijack the account, no malware required.
  • Infrastructure performed visitor checks (browser/device) and showed the fake login only to intended targets; others were redirected to Telegram or benign pages to evade detection.
  • Operators sent a second pressure message after link clicks, including victim device, time of click, and ISP to appear legitimate.
  • Messages used look‑alike characters (Cyrillic mixed with Latin/Greek) to bypass automated detection.

Who’s being targeted

  • Commonly targeted roles: Executives, Communications/PR, Journalists/Media teams, HR/People Ops (highly targeted individuals), Any staff using Telegram or other messaging apps for work.
  • Affected industries: Civil society / NGOs, Journalism / media (activists and journalists mentioned).
  • Attack channels: telegram, website.
  • Impersonated: Telegram Security/Support (fake).

Red flags to watch for

  • Unfamiliar Telegram account contacting you via secret chat
  • Threat/urgency: account will be blocked unless you act
  • Requests for a one-time login code (OTP) via a link
  • Message includes personal device/ISP details to intimidate rather than prove legitimacy
  • Pushes you back to a link instead of using in-app official security settings
  • Continues escalating urgency after you already interacted once
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the Telegram phishing attack steal accounts without malware?

Attackers sent a fake security alert through a Telegram secret chat claiming the account would be blocked unless the victim clicked a link and entered their one-time login code. Entering that code allowed attackers to immediately take control of the account, no malware required.

How did attackers avoid getting caught by security tools?

The phishing infrastructure checked each visitor's browser and device, showing the fake login page only to intended targets while redirecting security tools and unrelated visitors to Telegram's real site or other harmless pages. Messages also swapped in look-alike Latin and Greek characters to evade automated text detection.

Why did the follow-up message include my device and internet provider?

After a target clicked the link, operators sent a second message citing details like device type, click time, and ISP that were collected when the link was opened. This was likely meant to make the warning look legitimate and pressure the victim into completing the fake verification.

What should I do if I get a Telegram message warning my account will be blocked?

Do not click the link or enter any one-time code sent through chat. Verify account status directly through Telegram's official in-app security settings instead.

Read the video transcript

Imagine this: a Telegram secret chat pops up, claiming you broke the rules and your account will be blocked unless you verify it now. The link they send is customized with your phone number. You tap it, and a perfect Telegram login page appears, asking for the one-time code just sent to your phone. The moment you type that OTP, they can hijack your account, no malware, no password needed. Here’s the creepy part: after you click, they send a second message quoting your device, time, even your internet provider to sound legit and push you to finish. Tools might see only real Telegram pages, but you see the trap. Your move: if any Telegram chat, especially an unknown secret chat, asks you to enter a one-time code from a link, stop and check your account only through Telegram’s official app settings.

Similar attacks

Fake Job Interview Lure Targets Crypto Staff

Fake Job Interview Lure Targets Crypto Staff

A North Korea-linked group is running fake recruitment campaigns to trick people into taking “online assessments” for jobs that don’t exist. The goal is to…

July 30, 2026