Telegram Leaks & Data Breaches, History, IP Exposure & Protection

Knowledge Hub
Telegram Leaks

Telegram markets itself as the privacy-first alternative to mainstream messaging apps. That reputation has made it the platform of choice for hundreds of millions of users, activists, journalists, businesses, and everyday people who believe their conversations and contact details are protected. But a cascade of high-profile Telegram leaks, newly disclosed vulnerabilities, and data exposure incidents has fundamentally challenged that premise.

The risks are more layered than most users realize. A 200-million-record Telegram data leak surfaced in early 2025. A one-click IP leak vulnerability was publicly disclosed in January 2026. And a series of Telegram account compromises, some misreported as device-level hacks, have left millions of users questioning what the platform actually protects.

Security researchers are clear on one point: Telegram does not need to suffer a traditional breach for user data to end up exposed. Telegram-leaked data can originate from scraped contact records, aggregated credential dumps, third-party breaches involving Telegram-linked phone numbers, or architectural flaws that silently expose real IP addresses. Once that data circulates in leak forums and dark web markets, it fuels phishing campaigns, SIM-swapping attacks, and identity theft at scale.

This guide covers every major Telegram data breach and exposure incident on record, explains how Telegram leaks reach cybercrime communities, answers whether Telegram leaks your phone number, and shows you exactly how to check if your data was exposed, and what to do if it was.

The 200 Million Record Telegram Data Leak That Shook the Platform’s Foundations

On January 24, 2025, a dataset containing over 200 million Telegram records was leaked on one of the most active data-leak forums in the cybercrime underground. The post drew immediate attention from the security research community, and for good reason. The Telegram data leak spanned three separate databases labeled “Telegram user data,” “Source platform,” and “Telegram,” totaling 44GB of uncompressed data. What made it especially alarming was the nature of the exposed fields: email addresses, phone numbers, and usernames, not just the public-facing metadata Telegram claims to expose by design.

Telegram Leaks 200M Records

Researchers who analyzed a sample of the leaked Telegram data found approximately 66 million phone numbers paired with user IDs, alongside 10 million additional user records. A deeper examination of the full dataset identified roughly 60 million likely Telegram records, embedded within a broader collection that surfaced 16 billion credentials in total, suggesting the dump aggregated data from multiple sources, with Telegram representing a significant, separately labeled portion.

Telegram’s official response attempted to minimize the exposure. A company spokesperson told Cybernews that the records reflected user IDs and public usernames, the natural byproduct of Telegram’s contact-importing feature, not a system intrusion. But that explanation was directly contradicted by the presence of email addresses in the leaked sample. Email addresses are not publicly accessible on Telegram under normal circumstances. Users don’t expose them by joining groups, accepting contact requests, or appearing in searches. Their presence in the dataset pointed to something beyond routine scraping.

The security community remained divided on the precise origin: a new Telegram security breach, an aggregation of previously stolen credentials, or a combination of both. What was not in dispute was the downstream risk. A Telegram phone number leak of this scale creates fertile ground for targeted phishing campaigns, SIM-swapping attacks, identity theft, and credential stuffing across every platform those phone numbers touch. Phone numbers don’t change the way passwords do. Once leaked, they remain exploitable indefinitely.

What Are Telegram Leaks? Types, Causes, and Why They Keep Happening

In the cybersecurity community, the term “telegram leaks” refers to incidents in which user data from Telegram accounts surfaces in public databases, hacker forums, dark web markets, or leaked archives. The term is broad by necessity, because the mechanisms behind these exposures vary considerably and not all involve a traditional breach of Telegram’s infrastructure.

Researchers tracking Telegram leaked data have identified four primary causes:

  • Contact scraping via public discovery features. Telegram’s “Add by phone number” and “People Nearby” features have historically allowed automated tools to map phone numbers to user IDs and usernames at scale. This is how hundreds of millions of records can surface without any server intrusion.
  • Aggregated credential dumps. Many datasets labeled as Telegram data leaks are actually compilations that combine Telegram-sourced records with stolen credentials from unrelated breaches. The 200 million record dataset from January 2025 showed hallmarks of this approach.
  • Technical vulnerabilities exposing network data. The one-click Telegram IP leak vulnerability disclosed in January 2026 showed that architectural flaws, not just data theft, can constitute a serious exposure event. A user’s real IP address can be captured without compromising their account.
  • Databases shared across cybercrime communities. Once a leaked Telegram dataset enters underground circulation, it propagates rapidly. Dark web forums and cybercrime Telegram channels redistribute these archives, often repackaged under new names, making it impossible to contain any single exposure fully.

Because every Telegram account is tied to a phone number, even partial Telegram data leaks carry outsized risk. Phone numbers don’t expire. They link to bank accounts, two-factor authentication systems, and identity records. When a Telegram phone number leak lands in the wrong hands, the downstream attacks- SIM swapping, targeted phishing, identity linking across platforms- can persist for years after the original exposure.

Does Telegram Leak Your Phone Number? What the Data Shows

It is one of the most searched questions about the platform, and the answer is more complicated than Telegram’s privacy settings suggest: yes, Telegram can leak your phone number, and it has, at scale, through multiple mechanisms that range from deliberate design decisions to exploited vulnerabilities.

How Telegram Exposes Phone Numbers by Design

Every Telegram account is registered to a phone number. That number is the account’s foundational identifier, and Telegram’s contact discovery features have historically made it easier to extract than most users realize.

Telegram’s “Add by phone number” feature lets any user look up an account by entering a phone number. For years, this meant that automated scripts could query Telegram’s API with sequentially generated or dictionary-sourced phone numbers, receive confirmation when a number matched an active account, and silently build a database mapping millions of phone numbers to Telegram user IDs and usernames, no breach required. No server compromised. Just Telegram’s own infrastructure responding to legitimate-looking API calls at scale.

This is the primary mechanism behind the contact-scraping category of Telegram phone number leaks, and it is how hundreds of millions of phone numbers ended up in datasets that later circulated on leak forums.

The 200 Million Record Dataset: Phone Numbers at Scale

The January 2025 Telegram data leak that surfaced on underground forums contained approximately 66 million phone numbers paired with user IDs, a confirmed subset, with researchers estimating the true count of leaked Telegram phone numbers in the full 44GB dataset to be considerably higher. Telegram’s official response claimed these records were the product of contact importing, not a breach, an explanation that sidesteps the core issue entirely. Whether the phone numbers were scraped, imported, or stolen is largely irrelevant to the person whose number now appears in a criminal database.

The Durov Policy Shift: Legal Disclosure of Phone Numbers

Beyond scraping, there is now a second, formally sanctioned pathway for Telegram to leak phone numbers: legal requests from government authorities. In 2024, founder Pavel Durov confirmed that Telegram would comply with valid legal requests by sharing user IP addresses and phone numbers with law enforcement agencies. For users in jurisdictions with broad surveillance laws, or for dissidents, journalists, and activists operating under authoritarian governments, this policy change means Telegram’s privacy architecture no longer protects their phone numbers; they are accessible to any state actor with the legal standing to request them.

The Proxy Vulnerability: IP Address, Not Phone Number, But Linked

The January 2026 Telegram IP leak vulnerability did not directly expose phone numbers. It exposed real IP addresses. But in practice, the distinction matters less than it appears. An IP address combined with a Telegram username, both obtainable from a single malicious proxy link tap, is frequently sufficient to identify a user’s physical location, ISP, and, in many cases, their identity. When cross-referenced with a Telegram phone number leak dataset from 2025, an attacker can link an IP address, phone number, username, and location into a single target profile.

Does Telegram’s Privacy Setting Protect Your Number?

Telegram offers a setting under Privacy and Security that controls who can see your phone number: Nobody, My Contacts, or Everybody. Setting this to “Nobody” prevents your number from appearing in your profile. It does not prevent your number from being scraped via the API contact lookup mechanism, included in an aggregated breach dataset, or disclosed in response to a legal request. The setting controls display, not exposure.

The honest answer to whether Telegram leaks your phone number is this: the platform’s architecture, its history of mass scraping events, and its current legal disclosure policy collectively mean that phone number privacy on Telegram is conditional at best, and for many users who registered years ago before tightening their settings, their number has already appeared in at least one circulating dataset.

One Click Is All It Takes: The Telegram IP Leak Vulnerability

Just as the 200 million record story was gaining momentum, security researchers disclosed a separate and arguably more dangerous flaw, one that required no stolen database, no scraped records, and no server compromise. On January 10, 2026, researchers, including one operating under the handle @0x6rss, publicly disclosed what became known as the Telegram one-click IP leak vulnerability. Both Android and iOS clients were confirmed affected.

Telegram IP Leak

The mechanics are deceptively simple and rooted in a feature most users have never heard of.

Telegram includes a built-in MTProxy system, introduced in 2018 to help users in countries with restrictive internet access bypass censorship. When a user taps a proxy configuration link in the form t.me/proxy?…, Telegram automatically initiates a test connection to verify that the proxy server is reachable. The critical flaw is that this connectivity check fires before any user confirmation is displayed, and it routes directly from the device’s real network interface. Any VPN or SOCKS5 proxy the user has configured is bypassed entirely.

The attack chain is straightforward. An attacker who controls a fake MTProxy server sends a disguised proxy link to a target. Because Telegram’s interface renders these links as ordinary usernames, a link that displays as @durov in a chat could silently resolve to a malicious proxy URL; the victim has no reliable way to identify the trap before tapping. The moment they do, their real IP address appears on the attacker’s server in real time, along with precise timestamps.

Researchers drew a direct parallel to NTLM hash leaks in Windows environments. In both cases, a convenience feature designed to streamline the user experience silently exposes sensitive network data through an automatic background request the user never sees.

For most users, an exposed IP address sounds abstract. In practice, it enables neighborhood-level geolocation, ISP identification, and, in corporate environments, workplace identification. Proof-of-concept code published on GitHub shortly after disclosure confirmed that captured addresses appeared instantly on the attacker’s server. For journalists, activists, or dissidents who rely on t.me communications to operate safely under authoritarian regimes, a single tap on a disguised t.me leak link could undo years of operational security.

Telegram acknowledged the flaw when pressed by BleepingComputer, initially deflecting by noting that proxy operators naturally see the IP addresses of users who connect to them. After further questioning, the company committed to adding a warning prompt to proxy links in a future update. That fix, while useful, does not address the core architectural decision: running the connectivity check before presenting any user-facing confirmation. Until that changes, the Telegram proxy IP leak vulnerability remains an active risk for any user who receives unsolicited links in chats.

This is a straightforward SEO rewrite of existing published content; no issues here. Here it is:

The Handala Leak: When Telegram Account Compromise Is Mistaken for Device Hacking

Not every incident labeled a Telegram hack is what it initially appears to be, and the episode involving the hacktivist group Handala illustrates why that distinction matters enormously for how users understand and respond to Telegram security breaches.

Handala, a hacktivist group with a history of targeting Israeli institutions, claimed to have obtained access to sensitive communications from high-profile Israeli targets. The group’s announcement framed the operation as a device-level compromise, specifically alleging that iPhone handsets had been hacked to extract communications. The claim generated significant media attention, with coverage that largely accepted the device-hacking narrative at face value.

Cybersecurity analysts who examined the technical evidence reached a different conclusion. The signatures present in the leaked Telegram data were consistent with Telegram account compromise, not device intrusion. The distinction is not semantic. It changes everything about what was actually vulnerable, how the attack was executed, and what the affected users should have done to protect themselves.

Account Compromise vs. Device Hacking: Why the Difference Matters

A Telegram account compromise occurs when an attacker gains unauthorized access to a Telegram account by targeting the account’s authentication layer rather than the underlying device. The most common vectors include:

Session hijacking. Telegram maintains persistent login sessions across devices. An attacker who obtains a valid session token through phishing, malware, or interception can access an account’s full message history, contacts, and active chats from any device, without ever touching the victim’s phone. The victim’s iPhone remains completely uncompromised while their Telegram account is read in real time by the attacker.

SIM swapping. Because Telegram accounts are tied to phone numbers and use SMS verification as a primary authentication factor, an attacker who successfully transfers a victim’s phone number to an attacker-controlled SIM can receive the SMS verification code, log into the account from a new device, and access all unencrypted message history, again, without any device-level intrusion.

Social engineering and phishing. Attackers impersonating Telegram support, security teams, or trusted contacts can obtain verification codes directly from victims, bypassing device security entirely. This vector is particularly effective against high-value targets who receive high volumes of official-looking communications.

Linked device exploitation. Telegram’s multi-device feature allows accounts to be linked to additional devices through a QR code scan. An attacker who briefly gains physical access to an unlocked phone, or who tricks a user into scanning a malicious QR code, can link the account to an attacker-controlled device and maintain persistent access long after the initial session.

Why Misattribution Creates Real Security Risk

The Handala episode matters beyond its immediate context because misattributing a Telegram account compromise as an iPhone hack led to fundamentally misdirected security responses. Users and organizations who believed the threat was at the device level focused on device security, iOS updates, hardware security keys, and mobile device management, while leaving the actual vulnerability- their Telegram account authentication and session management- unaddressed.

This pattern of misattribution is not unique to the Handala case. Telegram hacked headlines routinely conflate device compromise with account compromise, credential theft with platform breach, and scraping with intrusion. Each conflation sends affected users in the wrong direction.

When Telegram account compromise is the actual vector, as analysts concluded it was in this case, the correct response is account-focused: terminate all active sessions immediately, change the account password, strengthen or re-enable two-factor authentication, audit linked devices, and review whether any active session tokens could have been intercepted through phishing or malware. None of those steps involve the iPhone’s operating system.

The Broader Lesson for Telegram Users

The Handala incident reinforced a point that security researchers consistently make about Telegram security: the platform’s end-to-end encryption in Secret Chats protects message content in transit, but it does not protect against an attacker who gains access to the account itself. Regular cloud chats, the default mode for most Telegram conversations, are stored on Telegram’s servers and are fully accessible to anyone who successfully compromises the account, regardless of how sophisticated the device’s own security is.

Telegram account security therefore depends on layers that exist entirely outside the device: a strong, unique account password, an active 2FA passphrase, regular session audits, and extreme caution with any links, QR codes, or verification requests received through the platform. An iPhone with the latest iOS update and a hardware security key is irrelevant if the Telegram account on it has a weak password, no 2FA, and three unrecognized active sessions quietly reading messages for weeks.

t.me Leak Links and Channels: What They Are and Why They’re Risky

Searches for t.me leaks and t.me leak links represent one of the most consistent query clusters in Telegram-related search traffic, and one of the most misunderstood. Users searching for these terms are typically looking for active Telegram channels that distribute leaked content, including databases, credentials, non-consensual intimate images, stolen corporate files, or hacked social media accounts. What most of those users do not realize is that accessing, sharing, or even joining these channels carries legal, privacy, and security risks that are rarely discussed alongside the links themselves.

What Are t.me Leak Channels?

A t.me link is simply Telegram’s standard URL format for accessing a channel, group, or user profile directly. A link formatted as t.me/channelname opens that channel in the Telegram app when tapped, or in Telegram’s web interface when opened in a browser. The format is identical whether the destination is a legitimate news channel, a business account, or a criminal marketplace distributing stolen data.

t.me leak channels are Telegram channels specifically created to distribute leaked content. They range considerably in what they share:

  • Credential and database leak channels distribute stolen login credentials, combo lists, email and password dumps, and databases scraped from breached platforms. These are the channels threat intelligence analysts monitor most closely, as they are often the first public distribution point for freshly stolen data, sometimes appearing within hours of a breach occurring elsewhere.
  • Personal content leak channels distribute non-consensual intimate images, private photos and videos obtained through account compromise or relationship abuse, and so-called “revenge porn.” These channels are illegal in most jurisdictions and are among the most actively pursued by law enforcement agencies that monitor Telegram.
  • Corporate and government leak channels distribute stolen internal documents, communications, financial records, and proprietary data, claiming they originate from hacked organizations or insider sources. The line between legitimate whistleblowing and criminal data trafficking is frequently blurred in this category, and the legal exposure for recipients varies significantly by jurisdiction.
  • Aggregated data dump channels redistribute existing Telegram leaked datasets, breach archives from other platforms, and repackaged versions of known databases, often with new branding to suggest fresh or exclusive content that is actually recycled material from prior exposures.

Why t.me Leak Channels Proliferate

The structural features that make Telegram attractive for legitimate communication make it equally attractive for distributing leaked content, and Telegram’s historically light moderation stance has allowed these channels to grow with minimal friction.

  • Channels can reach unlimited subscribers without algorithmic content suppression. A database dump posted to a t.me leak channel with 50,000 subscribers reaches all subscribers simultaneously, with no intermediary platform deciding whether the content is distributed.
  • Channel operators are difficult to identify. Telegram channel administrators can operate anonymously, rotating through throwaway accounts and phone numbers. When law enforcement takes down a channel, the operator typically migrates subscribers to a new t.me link within hours, often using automated redirect bots to route followers from the terminated channel to its replacement.
  • Content is difficult to moderate at scale. Database files, credential lists, and archive downloads are functionally indistinguishable from legitimate file sharing in Telegram’s infrastructure. Automated detection of leaked content requires context that Telegram’s moderation systems have historically not applied consistently.
  • The 2024 policy shift created new pressure but did not eliminate it. Following Pavel Durov’s arrest and Telegram’s subsequent commitment to cooperating with law enforcement on valid legal requests, some of the highest-profile t.me leak channels were terminated or migrated off the platform. But the underlying dynamic- a large user base, anonymous operation, and easy channel creation- means new channels replace terminated ones faster than enforcement can keep pace.

The Legal Risks of Accessing t.me Leak Links

This is where most users searching for t.me leaks significantly underestimate their exposure. Accessing, downloading, or sharing content from a t.me leak channel is not a legally neutral act in most jurisdictions, regardless of whether you contributed to the original breach.

Receiving stolen data. In the United States, the Computer Fraud and Abuse Act (CFAA) creates liability not only for those who steal data but in some circumstances for those who knowingly receive or possess stolen computer data. Accessing a Telegram leak channel that distributes stolen credentials or hacked databases can constitute knowing receipt of stolen property, depending on the context and jurisdiction.

Distributing non-consensual intimate images. In the UK, sharing non-consensual intimate images, including forwarding content from a t.me leak channel, is a criminal offense under the Online Safety Act 2023, carrying potential imprisonment. Similar laws exist across EU member states, Australia, Canada, and most US states. Forwarding a single image from a personal content leak channel can constitute a criminal act regardless of whether you were the source.

Corporate espionage exposure. Downloading or using leaked corporate documents, internal communications, financial records, client databases, from a t.me leak channel can create civil and criminal liability under trade secret law, even for individuals who had no involvement in the original theft.

Malware distribution disguised as leaked content. A significant proportion of files distributed through t.me leak channels are not what they claim to be. Threat researchers have documented extensive use of these channels to distribute infostealer malware, ransomware droppers, and trojanized archive files disguised as database dumps or credential lists. A user who downloads what appears to be a Telegram-leaked database may instead be executing a LummaC2 or RedLine infostealer that immediately begins harvesting credentials from their device. The irony- of seeking leaked data and becoming a victim of data theft in the process- is not lost on researchers who track these channels.

How to Identify a Malicious t.me Proxy Link vs. a Channel Link

Not every t.me link leads to a channel. As established by the January 2026 Telegram IP leak vulnerability, links formatted as t.me/proxy?server=…&port=…&secret=… are proxy configuration links that trigger an automatic connectivity check and can expose your real IP address the moment you tap them, before any warning appears.

The visual distinction in Telegram’s interface between a channel link and a proxy link is not always obvious, particularly when links are embedded in message text rather than displayed in raw URL format. Before tapping any t.me link received in a chat from an unknown sender:

  • Long-press the link on mobile to preview the raw URL
  • If the URL contains proxy, server, port, or secret parameters, do not tap it.
  • Links formatted as t.me/+XXXX are invite links to private groups or channels; they are generally safe to preview but carry risks if the destination is a criminal community.
  • Links formatted as t.me/username lead directly to a public channel or profile.

The Telegram proxy IP leak risk and the t.me leak channel ecosystem are distinct threats that share the same URL format, which is precisely what makes unsolicited t.me links in your inbox worth treating with consistent skepticism regardless of their apparent source.

What to Do If Your Content Appears in a t.me Leak Channel

If you discover that personal content, images, documents, credentials, or private communications have been posted to a t.me leak channel, the fastest available actions are:

Report directly to Telegram. Telegram’s abuse reporting mechanism is accessible at telegram.org/support or directly within the app by long-pressing a message and selecting Report. For non-consensual intimate image content, Telegram has dedicated reporting pathways that in some cases result in faster channel termination than standard abuse reports.

Submit a DMCA or legal takedown notice. If the content is original material you created and own the copyright to, a DMCA takedown request creates a legal obligation for Telegram to remove it from channels operating in or serving users in the United States.

Request Google deindexing. If the channel or its content appears in Google Search results, Google’s personal information removal tool can delist those specific URLs, reducing discoverability even if the underlying channel remains active.

Contact the Internet Watch Foundation if the content involves minors. The IWF operates internationally and has established relationships with platforms including Telegram for expedited removal of child sexual abuse material.

Engage a cyber incident response professional if the leaked content creates physical safety risks, reputational exposure, or legal liability. For corporate data appearing in a Telegram data leak channel, legal counsel should be involved before any contact is made with the channel operator or any attempt is made to download the leaked material for evidentiary purposes.

Telegram Data Breach History: Every Major Incident (2019–2025)

Telegram’s data breach history is longer and more varied than most users realize. The platform has never confirmed a traditional server intrusion of the kind that defines a textbook breach. Still, that framing obscures a consistent pattern of mass exposure events, scraped databases, and disclosed vulnerabilities that have collectively placed hundreds of millions of user records into criminal circulation. What follows is a chronological record of every major Telegram data breach, scraping incident, and security exposure.

2019, First Large-Scale Scraping Operation Documented

In mid-2019, researchers identified automated scraping campaigns targeting Telegram’s contact-discovery API at an industrial scale. Attackers queried the API with generated phone numbers, received confirmation responses for active accounts, and quietly assembled databases mapping phone numbers to user IDs. Telegram did not publicly acknowledge the activity or introduce meaningful API rate limiting at the time. This period established the scraping playbook that would be replicated in every subsequent mass exposure event.

2020, Iranian User Database Exposed

In January 2020, a Telegram data breach affecting Iranian users came to light when researchers discovered that a database of over 42 million Iranian Telegram users had been exposed. The dataset included phone numbers and Telegram user IDs. The exposure was linked to a vulnerability in a third-party Telegram bot and unofficial client rather than Telegram’s core infrastructure, a distinction Telegram has relied on repeatedly, but the practical impact on affected users was identical regardless of origin. The database circulated on underground forums for months following its initial disclosure.

2021, 500 Million Record Aggregation Surfaces

In early 2021, a dataset claiming to contain records on over 500 million Telegram users appeared on a popular hacking forum. Security researchers who examined the data found it was an aggregation, combining records scraped directly from Telegram with data pulled from other platform breaches where the same phone numbers appeared. The Telegram-sourced component was substantial. This incident established the aggregation model that would define subsequent Telegram leaked data events: original Telegram records combined with breach data from other services, merged into a single high-value package.

2022, Credential Markets Begin Featuring Telegram Data Routinely

By 2022, Telegram data leaks had become a standard line item in dark web credential markets rather than isolated incidents. Threat intelligence analysts tracking underground forums noted that Telegram user databases, varying in size, claimed source, and price, were appearing with consistent regularity. Many of these datasets were recycled versions of the 2020 and 2021 leaks, repackaged and resold to buyers who had not encountered them previously. The normalization of Telegram breach data in criminal markets during this period significantly expanded the pool of threat actors holding usable records.

2023, Kremlin-Linked Scraping Campaign Identified

In 2023, cybersecurity researchers documented a coordinated scraping campaign with suspected links to Russian state-affiliated actors targeting Telegram accounts belonging to Ukrainian officials, journalists, and civil society figures. The campaign used Telegram’s contact discovery features, combined with SIM-based registration for throwaway accounts, to map the communication networks of high-value targets. While the exposed data did not surface publicly as in previous Telegram data breaches, the incident underscored the extent to which nation-state actors had integrated Telegram scraping into active intelligence operations.

2024, Durov Arrest and the End of Telegram’s Non-Cooperation Policy

August 2024 marked a turning point that reframed the entire concept of Telegram data security. Telegram founder Pavel Durov was arrested in France on charges related to the platform’s alleged facilitation of criminal activity. In the weeks following his release, Durov confirmed that Telegram would begin complying with valid legal requests from government authorities by disclosing user IP addresses and phone numbers. This policy reversal did not constitute a Telegram breach in the technical sense. Still, for users who had trusted the platform precisely because of its historical refusal to cooperate with government surveillance, the effect was equivalent. Their data was now accessible through a formally sanctioned channel that had not existed before.

2025, The 200 Million Record Telegram Data Leak

January 24, 2025 brought the largest and most consequential Telegram data breach on record. A 44GB dataset spanning three labeled databases, “Telegram user data,” “Source platform,” and “Telegram”, surfaced on a major underground forum. The dataset contained approximately 66 million confirmed phone number-user ID pairings, 10 million additional user records, and email addresses that Telegram claimed could not be extracted through normal platform use. Researchers who analyzed the full dataset estimated it contained roughly 60 million likely Telegram records embedded within a broader collection of 16 billion total credentials. Telegram’s official response attributed the exposure to contact-importing features rather than to a breach, a position directly contradicted by the presence of email addresses in the leaked sample.

2026, One-Click IP Leak Vulnerability Publicly Disclosed

On January 10, 2026, researchers publicly disclosed the Telegram proxy IP leak vulnerability, a flaw in Telegram’s MTProxy implementation that allowed any attacker controlling a fake proxy server to capture a target’s real IP address the moment they tapped a disguised link. Unlike previous Telegram data breaches, this incident did not require a stolen database or a compromised server. It exploited a design decision baked into Telegram’s architecture: the connectivity check that fires automatically before any user confirmation is shown. Both Android and iOS clients were confirmed affected. Proof-of-concept code was published on GitHub within days of disclosure. Telegram committed to adding a warning prompt in a future update but has not addressed the underlying architectural issue.

Telegram Breach History: Summary Table

Year Incident Records Affected Type
2019 API scraping campaigns documented Undisclosed Scraping
2020 Iranian user database exposed 42 million Third-party vulnerability
2021 Aggregated dataset surfaces on forums 500 million (claimed) Aggregation + scraping
2022 Telegram data normalized in credential markets Ongoing Redistribution
2023 State-linked scraping of Ukrainian targets Undisclosed Nation-state scraping
2024 Durov policy reversal — legal IP/phone disclosure begins All users Policy change
2025 200 million record dataset published 200M+ records, 44GB Aggregation + scraping
2026 One-click IP leak vulnerability disclosed All mobile users Architectural vulnerability

Why Telegram Has Become a High-Value Target for Data Leaks and Surveillance

To understand why Telegram leaks, Telegram data breaches, and Telegram security vulnerabilities appear with such frequency, you need to understand what Telegram has become in the global digital ecosystem.

With over 900 million registered users, Telegram sits at an unusual intersection. Its reputation for speed, minimal moderation, and privacy, deserved or not, has made it the platform of choice for an extraordinarily diverse user base: political activists operating under authoritarian regimes, investigative journalists protecting sources, organized criminal networks, Fortune 500 businesses running internal communications, government officials, and hundreds of millions of ordinary consumers. No other messaging platform carries that same breadth of sensitive users under one roof.

That diversity is precisely what makes it such an attractive target. When a single Telegram data leak or account compromise succeeds, the potential harvest spans everything from personal contact details and private conversations to corporate intelligence and politically sensitive communications. Cybersecurity consulting firm NVISO has gone so far as to recommend that businesses without an essential operational need for the platform consider blocking Telegram’s API entirely, a striking position for a tool this widely deployed.

The platform’s threat surface has also expanded significantly due to a policy reversal most users didn’t notice. In 2024, Telegram founder Pavel Durov agreed to share user IP addresses and phone numbers with government authorities who submit valid legal requests. For a platform whose core identity was built on resisting exactly these kinds of demands, and whose growth was fueled in large part by users fleeing platforms that cooperate with surveillance, this represented a fundamental shift. It also served as a reminder that no platform’s privacy guarantees are unconditional, regardless of how those guarantees are marketed.

The combination of a massive, high-value user base, a history of architectural vulnerabilities, an expanding law-enforcement cooperation policy, and a reputation that attracts users who believe they are more protected than they actually are creates the conditions in which Telegram leaks and Telegram-exposed data incidents will continue to occur. The platform’s appeal is inseparable from its risk profile.

How Telegram Data Ends Up in Leak Forums and Dark Web Markets

When cybersecurity researchers trace the lifecycle of a Telegram data leak, they consistently find the same pattern: data originating from scraping operations, credential dumps, or technical vulnerabilities moves quickly into underground communities, where it is packaged, sold, and redistributed far beyond its original exposure point.

Leak forums and dark web marketplaces are the primary landing zones. These platforms regularly publish databases labeled “Telegram user database,” “leaked telegram accounts,” “Telegram scraped dataset,” or “Telegram contact dump.” The accuracy of these archives varies considerably; some contain verified, high-quality records matched to active accounts; others are padded with outdated entries, fabricated data, or records recycled from older breaches repackaged under a new name. That inconsistency doesn’t reduce their market value. Threat actors buy in bulk and filter later, running automated validation tools against live services to separate genuine credentials from noise.

Once a Telegram-leaked dataset enters underground circulation, containment becomes effectively impossible. Files spread across forums, paste sites, private Telegram channels, and file-sharing networks within hours. Each redistribution increases the number of threat actors who hold a copy, multiplying the downstream risk for every person whose data appears in the archive.

What makes this distribution cycle particularly unusual is that Telegram itself often becomes part of the chain. Certain cybercrime communities operate dedicated Telegram channels to share leaked databases, stolen credentials, combo lists, and hacking tools, sometimes including Telegram data leaks alongside breaches from other platforms. The platform whose user records are being exposed becomes the infrastructure through which those records are advertised and distributed. Researchers tracking the 2025 200 million record dataset observed exactly this pattern: threads discussing the dump appeared on traditional leak forums within hours, while Telegram channels began circulating download links shortly after.

Threat intelligence analysts continuously monitor these channels and forums, tracking newly circulating Telegram leaks, identifying fresh breach datasets, and flagging exposed records before they are weaponized at scale. For organizations, this kind of monitoring is the earliest possible warning that employee credentials or corporate contact data has entered the underground economy, often days or weeks before a formal breach notification would arrive through any other channel.

Why Telegram Leaks Are Valuable to Cybercriminals

A common misconception is that Telegram leaks only matter if private messages are exposed. They don’t. Even when message content remains encrypted and inaccessible, account-level data, phone numbers, usernames, user IDs, and email addresses give attackers enough to cause serious damage. In many cases, that metadata is more durable and more exploitable than the messages themselves.

Here is what a threat actor can do with a Telegram leak dataset:

SIM-swapping and account takeover. A phone number linked to a Telegram account is often the same number used for SMS-based two-factor authentication on banking apps, email accounts, and cryptocurrency wallets. Attackers who obtain a leaked Telegram phone number can target the victim’s mobile carrier directly, convincing support staff to transfer the number to an attacker-controlled SIM. From that point onward, every SMS-based 2FA code on every platform is routed to the attacker.

Targeted phishing campaigns. With a phone number and username in hand, attackers can send highly personalized messages impersonating Telegram support, employers, financial institutions, or contacts already in the victim’s network. The specificity of these attacks, addressing victims by name, referencing their Telegram handle, dramatically increases success rates compared to generic phishing blasts.

Cross-platform identity mapping. Phone numbers are among the most consistent identifiers across digital services. A Telegram phone number leak enables attackers to link a Telegram identity to accounts on WhatsApp, Signal, Instagram, LinkedIn, and banking platforms, thereby assembling a detailed profile of the target from fragments scattered across multiple breaches.

Credential stuffing. When leaked Telegram data includes email addresses alongside usernames, those pairs are fed directly into automated credential-stuffing tools. If a victim reused passwords across services, a single Telegram data leak can cascade into compromised email, social media, and financial accounts within hours.

Network mapping and social engineering. For high-value targets- executives, journalists, government officials- even knowing who communicates with whom on Telegram carries intelligence value. Leaked contact graphs allow attackers to identify relationships, impersonate trusted contacts, and construct social engineering attacks that are nearly impossible to detect.

Because Telegram functions simultaneously as a personal messaging app, a business communication tool, a news distribution platform, and, for many users in restrictive countries, a lifeline for secure communication, a successful attack originating from Telegram rarely stays contained within Telegram. The platform’s versatility is what makes Telegram leaks so disproportionately valuable to the threat actors who collect and trade them.

How to Check If Your Telegram Data Was Leaked

Knowing your data appeared in a Telegram data leak is only useful if you find out before an attacker acts on it. The 200 million record dataset from January 2025 circulated on underground forums for weeks before most affected users had any awareness it existed. The steps below provide the fastest available methods for checking your exposure across all major Telegram breach datasets currently in circulation.

Step 1: Search Have I Been Pwned for Your Phone Number and Email

Have I Been Pwned (haveibeenpwned.com) is the most widely used public breach search service and aggregates records from hundreds of major Telegram data leak datasets and breach databases. Most users know to search their email address, but for Telegram leaks, your phone number is equally important, since every Telegram account is registered to one.

Go to haveibeenpwned.com and search both:

  • Your primary email address
  • Your phone number in international format (e.g. +1XXXXXXXXXX)

If either appears in a known Telegram breach or in an aggregated dataset that includes Telegram records, HIBP will flag the specific breach name, the date it was indexed, and the data types exposed. A result showing “phone number,” “username,” and “Telegram” in the same breach record is a strong signal your Telegram-linked data is in active circulation.

Important limitation: HIBP indexes breaches after they are submitted and verified. The January 2025 Telegram data breach dataset, all 44GB of it, may not be fully indexed. A clean HIBP result does not guarantee your data is not circulating in unindexed datasets on private forums or dark web markets.

Step 2: Run a Dark Web Exposure Scan

Public breach search tools only cover datasets that have been discovered, submitted, and indexed. A significant volume of leaked Telegram data circulates exclusively on private dark web forums, closed Telegram channels, and invitation-only marketplaces that public tools never reach.

DeXpose’s free Email Data Breach Scan searches simultaneously across dark web markets, malware log databases, and breach archives, including sources that do not surface in public breach search tools. Enter your email address to receive an immediate report showing whether your credentials, phone number, or organizational data appears in dark web sources linked to Telegram data leaks or broader breach datasets.

For organizations concerned about employee exposure following a Telegram breach, DeXpose’s Dark Web Monitoring service provides continuous surveillance across underground sources, alerting you when new records matching your domain appear in circulation, often days before those datasets reach public indexing.

Step 3: Check Your Telegram Account for Signs of Compromise

Searching breach databases tells you whether your data was exposed. Checking your Telegram account directly tells you whether that exposure has already been acted on.

Open Telegram and navigate to Settings → Privacy and Security → Active Sessions (displayed as “Devices” on some versions). This screen shows every active login: device type, approximate location, IP address, and last active timestamp.

Look specifically for:

  • Sessions on devices you do not own or recognize
  • Logins from countries or cities you have not visited
  • Sessions showing activity at times you were not using the app
  • An unusually high number of active sessions

Any unrecognized session is a signal of potential compromise of a Telegram account. Terminate all unrecognized sessions immediately using the “Terminate All Other Sessions” option. Then change your password, re-enable or strengthen your 2FA passphrase, and check whether your linked email address has also been accessed without authorization.

Step 4: Search Telegram-Specific Leak Databases

Several threat intelligence platforms maintain searchable indexes specifically built around Telegram leak datasets. These go beyond general breach aggregators and focus on the scraping-based databases that dominate the Telegram data breach landscape.

  • IntelX (Intelligence X) at intelx.io allows searches by phone number, email, and Telegram username across indexed leak databases including those specifically labeled as Telegram-sourced. Results are partially gated behind a paid tier, but free accounts can confirm whether a match exists.
  • Leak-Lookup at leak-lookup.com indexes a broad range of breach databases and supports phone number searches relevant to Telegram phone number leak datasets.
  • DeHashed at dehashed.com supports searches by username, phone number, and email across a large corpus of breach data, with filters that can narrow results to Telegram-labeled datasets.

When searching these platforms, use every identifier associated with your Telegram account: your registered phone number, your username, your email address (if linked), and any alternate phone numbers you have used with the app in the past.

Step 5: Monitor Continuously, Not Just Once

Checking your exposure once provides a snapshot. Telegram data leaks and the broader breach ecosystem are not static: new datasets surface weekly, previously private dumps are publicly indexed, and records from the 2025 200 million record event continue to appear in repackaged form across new forums and markets.

Set up ongoing monitoring through:

  • Have I Been Pwned notifications, free email alerts when your address appears in a newly indexed breach
  • DeXpose Dark Web Monitoring, continuous surveillance across dark web sources with alerts for your domain, email addresses, and phone numbers
  • Google One Dark Web Report, monitors a limited set of personal identifiers against known breach datasets (note: Google discontinued its standalone dark web scanning feature in early 2026, redirecting users to alternative monitoring services)

The goal is to compress the window between when your data enters circulation and when you find out about it. In the January 2025 Telegram breach, that window was measured in weeks for most affected users. With active monitoring, it can be measured in hours.

What to Do If You Find Your Telegram Data Was Leaked

If any of the above steps confirm your data appeared in a Telegram data leak, act in this order:

  1. Change your Telegram password immediately and enable 2FA if not already active.
  2. Terminate all active sessions from Settings → Devices.
  3. Change the password on your linked email address; if your email appeared alongside your Telegram records, assume both are compromised.
  4. Contact your mobile carrier and request a SIM lock or additional account security; a Telegram phone number leak is a direct precursor to SIM-swapping attempts.
  5. Audit every account that uses the same phone number for SMS 2FA, banking apps, email providers, crypto exchanges, and switch to authenticator app-based 2FA where available.
  6. Monitor for phishing attempts targeting your phone number and email address in the weeks following discovery; attackers who purchase leaked Telegram data typically deploy phishing campaigns against fresh datasets within days.

How to Protect Yourself From Telegram Leak Risks

The accumulation of Telegram leaks, data breaches, and security vulnerabilities disclosed over the past 18 months points to a clear conclusion: protecting yourself on Telegram requires active participation, not passive trust in the platform’s privacy reputation. The following steps address the specific attack vectors these incidents have exposed.

Enable two-factor authentication with a strong, unique password. This remains the single most effective defense against Telegram account takeover, regardless of what data has already been exposed in prior leaks. Telegram’s 2FA system adds a password layer on top of SMS verification, meaning that even if an attacker obtains your phone number through a Telegram phone number leak and attempts a SIM swap, they cannot access your account without the second factor. Use a password that is unique to Telegram, not reused from any other service.

Treat every link in Telegram as potentially hostile. The Telegram one-click IP leak vulnerability demonstrated that a link displaying as an ordinary username can silently resolve to a malicious proxy server and expose your real IP address before any warning appears. Until Telegram deploys the confirmation prompt it has committed to, there is no reliable in-app indicator distinguishing a legitimate profile link from a disguised t.me proxy attack. On mobile, long-press any link before tapping to preview the raw URL. If it contains proxy, server, or port parameters, do not proceed.

Use a device-level VPN, not Telegram’s built-in proxy. Many users assumed Telegram’s MTProxy system protected their real IP address. The Telegram proxy IP leak vulnerability proved it does not; the connectivity check that triggers IP exposure fires before any proxy is applied. A device-level VPN routes all traffic, including Telegram, through an encrypted tunnel at the operating system level, preventing IP capture even when a malicious proxy initiates a direct connection. This is the only reliable architectural defense against the one-click exposure vector.

Check whether your data appeared in known Telegram leaks. Search your email address and phone number on Have I Been Pwned (haveibeenpwned.com), which aggregates records from major breach datasets including those linked to Telegram data leaks. You can also run a free exposure check through DeXpose’s Email Data Breach Scan, which searches dark web sources, malware logs, and breach databases simultaneously. If your phone number or email address appears in a leaked Telegram dataset, treat every account tied to that number as potentially compromised and prioritize changing the authentication methods on your most sensitive services first.

Audit your active sessions regularly. Telegram displays all active sessions and connected devices under Settings → Devices. Any session you do not recognize, an unfamiliar device, location, or login timestamp should be terminated immediately. A Telegram account compromised through session hijacking leaves this trace. If you find an unrecognized session, revoke all sessions simultaneously, change your password, and re-enable 2FA to invalidate any stolen session tokens.

Limit what you share on Telegram in the first place. No security configuration fully compensates for overexposure. Because Telegram-leaked data most commonly originates from contact scraping and aggregated records, the less personal information you associate with your account, the smaller your footprint in any future dump. Consider using a secondary phone number for Telegram registration, restricting who can find your account by phone number in Privacy Settings, and keeping sensitive communications on platforms that enable end-to-end encryption by default for all message types, something Telegram offers only in Secret Chats, not in standard group conversations.

Telegram Leak Removal: Can You Get Your Data Taken Down?

It is the first question most people ask after discovering their data appeared in a Telegram data leak: can I get it removed? The honest answer is that removal is rarely possible and rarely complete, but that does not mean you are without options. Understanding what can and cannot be taken down, and where to direct your effort instead, is the most useful framework for anyone dealing with the aftermath of a Telegram breach.

Why Telegram Leak Removal Is Exceptionally Difficult

When leaked Telegram data reaches an underground forum or dark web market, it has typically already been downloaded, copied, and redistributed dozens or hundreds of times before any removal request could be filed. The original forum post is one node in a distribution network that spans paste sites, private Telegram channels, file-sharing platforms, and closed criminal marketplaces, most of which operate outside any legal jurisdiction that would respond to a takedown request.

This is the fundamental problem with Telegram data leak removal: you are not dealing with a single copy of your data sitting on a server that can be deleted. You are dealing with a file that has been replicated across an anonymous, decentralized network specifically designed to resist takedown. Even when the original post is removed by the forum operator, law enforcement, or legal pressure, every downstream copy remains intact and in active circulation.

The January 2025 Telegram leaked dataset is illustrative. Within 72 hours of its initial appearance on an underground forum, researchers had identified the same dataset appearing across multiple secondary platforms. By the time most affected users became aware of the exposure, removing the data from circulation had become practically impossible.

What You Can Request From Telegram Directly

Telegram does offer formal mechanisms for data-related requests, though their scope is limited.

Under the General Data Protection Regulation (GDPR), users in the European Union and the European Economic Area have the right to request the deletion of personal data that Telegram holds about them. This covers data stored on Telegram’s own servers, your account information, message metadata, and contact records, not data that has already left Telegram’s infrastructure and entered third-party breach datasets.

To submit a GDPR deletion request to Telegram:

  • Navigate to Settings → Privacy and Security → Delete My Account.
  • Deleting your account removes your data from Telegram’s servers and breaks the link between your phone number and your Telegram identity going forward.
  • Alternatively, submit a formal data request through Telegram’s privacy contact at gdpr@telegram.org

Critical limitation: Deleting your Telegram account removes your data from Telegram’s live infrastructure. It does not remove your phone number, username, or user ID from any Telegram data leak dataset that was compiled before deletion. If your records appeared in the January 2025 dump, deleting your account today will not change what is already circulating on underground forums.

For users outside the EU, Telegram’s terms of service still permit account deletion and associated data removal from their servers, but the legal right to demand it is less enforceable. California residents may have additional rights under the California Consumer Privacy Act (CCPA), and UK users retain GDPR-equivalent rights under the UK GDPR framework.

Requesting Removal From Leak Forums and Dark Web Markets

In theory, some leak forums include contact mechanisms or abuse reporting channels. In practice, filing a removal request with a criminal marketplace is unlikely to yield meaningful results and, in some cases, risks drawing additional attention to your data by confirming its authenticity.

There are limited circumstances where removal requests have succeeded:

Mainstream platforms hosting leaked content. If Telegram leaked data, particularly non-consensual intimate images, personal identification documents, or financial records, has been posted on mainstream platforms like Reddit, Twitter/X, Discord, or Pastebin, those platforms have abuse reporting mechanisms and legal obligations that make removal genuinely achievable. Document the URL, submit a formal abuse report citing the specific violation, and follow up if the initial Report is not actioned within 48 hours.

Google Search removal. Google’s Remove Outdated Content tool and its dedicated personal information removal request process can delist specific URLs from search results. This does not remove the underlying content from the server where it is hosted, but it significantly reduces discoverability for anyone who would find it through a standard search. Submit removal requests at myaccount.google.com/remove-information. Eligible content includes doxxing information, government-issued ID numbers, financial account details, and in some jurisdictions, phone numbers and email addresses posted without consent.

Data broker removal. A significant secondary problem following any Telegram phone number leak is that data brokers, companies that aggregate and resell personal information, may incorporate your exposed data into their own commercial databases. Services like DeleteMe, Kanary, and Incogni automate opt-out requests to hundreds of data brokers simultaneously and can meaningfully reduce the surface area of your personal information in commercially accessible databases, even when removing data from criminal sources remains impossible.

Working With Professionals on Telegram Leak Removal

For high-profile individuals, executives, public figures, journalists, or anyone whose Telegram data breach exposure creates personal safety risks, professional assistance is available through several channels.

Cyber incident response firms can conduct a thorough assessment of where your data is circulating, identify the specific datasets that contain your records, and in some cases work with law enforcement contacts to pursue takedowns of the highest-risk exposures. This is resource-intensive work, but for targets whose exposed data creates physical security risks, it is often justified.

Legal counsel specializing in data privacy can assist with formal GDPR deletion requests, pursue platform operators through civil channels where jurisdiction permits, and in cases involving non-consensual intimate image sharing, engage criminal law frameworks that carry real takedown leverage.

Threat intelligence monitoring services like DeXpose track where your data surfaces across dark web markets and underground forums, providing early warning when your records appear in new datasets or are redistributed to previously unidentified platforms. This does not remove your data, but it compresses the window between when your records are weaponized and when you find out about it, which is the most actionable defense available once removal has proved impossible.

What You Should Focus on Instead of Removal

Given the practical barriers to Telegram leak removal, security professionals consistently advise shifting the focus from removal to mitigation, making the exposed data as difficult to weaponize as possible, even if it remains in circulation.

The most effective mitigation steps following confirmed Telegram data leak exposure:

Rotate every authentication factor tied to your exposed phone number. Switch from SMS-based 2FA to authenticator app-based 2FA on every account that supports it. A phone number in a Telegram breach dataset is a loaded weapon for SIM-swapping attacks; removing it as an authentication factor defuses it.

Place a SIM lock with your mobile carrier. Contact your carrier and request a port freeze or SIM lock, a requirement that any SIM transfer request be verified through an in-person identity check or a unique PIN. This is the single most effective defense against SIM-swapping attacks that originate from Telegram phone number leaks.

Change usernames where possible. If your Telegram username appears in a leaked Telegram dataset, consider changing it. While your historical records in existing datasets remain unchanged, breaking the link between your current username and your exposed phone number reduces the effectiveness of cross-platform identity mapping attacks.

Assume your phone number is permanently compromised and act accordingly. The records in the January 2025 Telegram data breach will not disappear. The most durable protection is treating your exposed phone number as a known quantity in criminal databases and restructuring your authentication and account recovery methods around that reality rather than around the hope that removal will eventually succeed.

Free Dark Web Report

Keep reading

No results found.