{"id":21447,"date":"2018-03-05T10:34:57","date_gmt":"2018-03-05T15:34:57","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=21447"},"modified":"2021-03-17T10:26:24","modified_gmt":"2021-03-17T14:26:24","slug":"telegram-accounts-stealing","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/telegram-accounts-stealing\/21447\/","title":{"rendered":"A wave of Telegram hacks hits: How to protect your account"},"content":{"rendered":"<p>Just like social media accounts, Telegram accounts are hijacking targets \u2014 especially if they are linked to channels with a lot of subscribers. Such accounts were in the crosshairs of a recent wave of attacks. This post explains how it happens and what to do about it. Let\u2019s go!<\/p>\n<h2>How are Telegram accounts hacked and stolen?<\/h2>\n<p>The short answer is: <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/phishing\/?utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=termin-explanation\" target=\"_blank\" rel=\"noopener\">phishing<\/a>. The user receives a message from a Telegram account with an official-sounding nickname (say, TelegramAdmin) stating that suspicious activity has been detected on their account and that the user must provide account confirmation or the account will be blocked. A link is provided to confirm the account.<br>\nNaturally, the link points to a phishing site with an address that seems trustworthy. It might be telegram-antispam.org or telegram-verification.site, or something like that.<a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/03\/05102621\/telegram-accounts-stealing-screenshot-1.png\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-21448\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/03\/05102621\/telegram-accounts-stealing-screenshot-1.png\" alt=\"\" width=\"826\" height=\"727\"><\/a><br>\nThe site looks like a carbon copy of the real Telegram login page at <a href=\"http:\/\/web.telegram.org\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">web.telegram.org<\/a>. The user is prompted to enter their phone number, confirmation code, and, if two-factor authentication is enabled, password. In case of a forgotten password, the scammers ask the user to go through the normal password-recovery process \u2014 click a link, receive a recovery code from (the real) Telegram, and provide that code to (the fake) Telegram..<br>\nOnce the victim enters all of this info, the scammers have everything they need to access the account and link it to another phone number. Along with the account, they get its channels.<\/p>\n<h3>How to protect your Telegram account<\/h3>\n<ul>\n<li>Enable two-factor account authentication. It\u2019s not a silver bullet, but it will make stealing your account harder.<\/li>\n<li>Be wary of messages from accounts that are not in your address book, and don\u2019t follow suspicious links. Telegram administrator accounts have verification badges in the account information. If you receive a message supposedly from Telegram, but there is no such badge, it\u2019s a scam. Another telltale sign is if Telegram prompts you about marking the message as spam. Obviously, the service won\u2019t detect a message from itself as spam.<\/li>\n<\/ul>\n<div id=\"attachment_21449\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/03\/05102617\/telegram-accounts-stealing-screenshot-2.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-21449\" class=\"size-large wp-image-21449\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/03\/05102617\/telegram-accounts-stealing-screenshot-2-1024x260.jpg\" alt=\"\" width=\"1024\" height=\"260\"><\/a><p id=\"caption-attachment-21449\" class=\"wp-caption-text\">Official Telegram accounts have badges, fake accounts do not<\/p><\/div>\n<ul>\n<li>Before entering personal info on any Web page, check that the connection is secure, and take a close look at the domain name of the page in the address bar. In this case, it should be telegram.org, not telegram-antispam.org, antispam-verification.com, or any such variant.<\/li>\n<li>Install a <a href=\"https:\/\/www.kaspersky.com\/internet-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kismd___\" target=\"_blank\" rel=\"noopener nofollow\">security solution with antiphishing capability<\/a> on every device that permits it.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kis-trial-cyberattacks\">\n","protected":false},"excerpt":{"rendered":"<p>Avoid the phishing bait and protect your Telegram account<\/p>\n","protected":false},"author":2473,"featured_media":21450,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2683,9],"tags":[2672,2003,315,607,76,2859,611,131],"class_list":{"0":"post-21447","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"category-tips","9":"tag-accounts","10":"tag-hijacking","11":"tag-identity-theft","12":"tag-messengers","13":"tag-phishing","14":"tag-target-phishing","15":"tag-telegram","16":"tag-tips"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/telegram-accounts-stealing\/21447\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/telegram-accounts-stealing\/12683\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/telegram-accounts-stealing\/10507\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/telegram-accounts-stealing\/14809\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/telegram-accounts-stealing\/13124\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/telegram-accounts-stealing\/12549\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/telegram-accounts-stealing\/15437\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/telegram-accounts-stealing\/15134\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/telegram-accounts-stealing\/19814\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/telegram-accounts-stealing\/4781\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/telegram-accounts-stealing\/10060\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/telegram-accounts-stealing\/9030\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/telegram-accounts-stealing\/16019\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/telegram-accounts-stealing\/19815\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/telegram-accounts-stealing\/19731\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/telegram-accounts-stealing\/19761\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/phishing\/","name":"phishing"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/21447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2473"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=21447"}],"version-history":[{"count":6,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/21447\/revisions"}],"predecessor-version":[{"id":39057,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/21447\/revisions\/39057"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/21450"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=21447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=21447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=21447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}