A database allegedly containing the personal data of 182 million Telegram users is being offered for sale on the dark web. Security experts warn that the information could fuel targeted phishing campaigns.
An anonymous actor is offering a compressed 41.1 GB text file for sale on a well known underground forum. According to the seller, the dataset contains information belonging to 182 million Telegram users. As proof of authenticity, the seller provided a sample containing 60 records.
Security researchers from Cybernews analyzed the sample and found that the data primarily belonged to Russian speaking profiles. It remains unclear whether the information was obtained directly through a Telegram security vulnerability or whether it is a compilation of leaked datasets collected from various Russian online services and publicly available Telegram channels. The full scope of the database cannot currently be independently verified based on the limited sample size.
Increased Risk of Targeted Phishing Attacks
The leaked records reportedly include combinations of usernames, phone numbers, internal Telegram user IDs and, in some cases, full names. While this information alone is not sufficient to directly take over accounts or gain unauthorized access, it provides cybercriminals with a valuable tool for social engineering attacks. By combining real phone numbers with associated usernames, attackers can create highly targeted phishing messages. Fraudsters often impersonate official Telegram support representatives or employees of cryptocurrency exchanges in an attempt to trick victims into revealing passwords or verification codes.
Reports of Active Scam Campaigns Across Online Communities
Reports from online communities such as Reddit indicate that affected users are already encountering personalized phishing attempts. One user described the situation as follows:
“It seems like there are a huge number of posts referring to people receiving SMS messages supposedly from Telegram saying their account is about to be banned and they need to verify their account by following a link.”
Reddit user
Other users report scam attempts in which attackers copy the names and profile pictures of group administrators to send direct messages requesting that members verify their crypto wallets. The leaked phone numbers could also be used to target victims on other platforms such as WhatsApp or to combine the information with data from previous breaches, increasing the effectiveness of future attacks.
(ll)