A 44GB uncompressed dataset allegedly containing 200+ million Telegram user records was advertised on a data-leak forum, with reporting indicating it was offered on BreachForums. The exposed data is described as including names, Telegram usernames, email addresses, and phone numbers, raising the likelihood of large-scale phishing and account-takeover targeting if the data is authentic and current.
Researchers cited in coverage said they had not yet confirmed whether the information reflects a new compromise or a repackaging/aggregation of older breached data, noting that the presence of Telegram user emails (not typically publicly accessible) may indicate more than simple scraping. Separately, Russia’s telecom regulator Roskomnadzor confirmed it is throttling Telegram for alleged noncompliance with Russian law and content takedown demands; this state-imposed disruption is a policy/regulatory action and not directly tied to the alleged data-leak incident.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers warned that the exposed Telegram-related dataset could be used for large-scale phishing campaigns against users. NVISO also highlighted growing threat-actor targeting of Telegram and urged businesses to restrict use of Telegram's API.
Subsequent analysis found the exposed material appeared to include about 60 million Telegram records alongside references to 16 billion credentials, and researchers said they could not confirm it represented a new breach rather than older stolen data. They assessed the dataset was likely not purely scraped because Telegram user email addresses are not publicly accessible, suggesting a mix of scraping and previously compromised data.
A threat actor exposed or advertised a purported Telegram user dataset on BreachForums on Jan. 24, claiming it contained more than 200 million records from three databases. The uncompressed data was described as 44 GB and allegedly included names, Telegram usernames, email addresses, phone numbers, and other personal details.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.