A Telegram user said an attacker took over his account without phishing links, a stolen password, or a malicious app. The attack required only a series of late-night calls, voicemail, and about five minutes.
Інцидент стався близько четвертої ранку. За словами постраждалого, який понад десять років працює у криптоіндустрії, о 3:54 його телефон почав безперервно дзвонити з прихованого номера. Приблизно десять послідовних викликів мали не просто розбудити власника, а утримувати його телефонну лінію зайнятою, поки зловмисник намагався увійти в Telegram за його номером.
Паралельно атакувальник запросив код входу через автоматичний телефонний дзвінок. Оскільки лінія була зайнята, виклик із кодом, за словами потерпілого, перенаправився на голосову пошту, де автоматична система вголос продиктувала код підтвердження. Після цього зловмисник отримав віддалений доступ до голосової пошти, прослухав повідомлення та використав код для входу.
“At 3:54 a.m., my phone rings about ten times in a row. The number is hidden. This wasn’t harassment. It was an attack: keep my line busy.”
By 3:59 a.m., an unknown device had already been authorized on the account.
“At 3:59, he was already in.”
This time, the noisy nature of the attack worked against the attacker. The repeated calls woke the account owner, and instead of going back to sleep, he checked his notifications. Telegram showed a new login from a device he did not recognize.
“Fortunately, the attack was noisy. The calls woke me up. At four in the morning, all I wanted was to go back to sleep, but I had enough common sense to check the notifications. Telegram showed a new login from a device I didn’t recognize. That check is what saved me.”
According to the victim, during the few minutes of access, the attacker managed to browse old conversations and interact with Telegram crypto wallet bots. In every bot he found, he entered the /balance command and then /start, apparently trying to locate cryptocurrency. The bots were no longer active, so no funds were stolen, according to the account owner. However, the situation could have ended much worse: the attacker had enough access to set his own two-factor authentication password on the account.
“I was lucky to react quickly. He was inside for about five minutes. I don’t keep anything valuable in Telegram. But the real problem would have been all the scam messages he could have sent to my contacts. I’m an administrator of several groups, people trust me, so he could have caused a lot of damage.”
After the incident, the victim contacted his mobile carrier. According to him, an employee said that many users had recently been disabling voicemail, likely because of risks like this.
“When I called my carrier, they told me that a lot of people have been disabling voicemail lately… probably for exactly this reason.”
After the story was posted on X, other users began sharing similar experiences. One said attackers took over his WhatsApp account using the same method and suggested that such attacks may be fully automated.
“My WhatsApp was taken over the same way. I also have reason to believe this is being carried out in a fully automated manner.”
Another user reported a similar attempt, but said two-factor authentication prevented the attackers from gaining access to the account. A third described having a Telegram account compromised and said he decided to block the SIM card afterward.
“The same thing happened to me. They couldn’t get in because of 2FA.”
“Unfortunately, this is very common with Telegram. The same thing happened to me. After that, I blocked the SIM card.”
This type of attack highlights a weak point that many users rarely think about. The account itself may be protected by modern security measures, but the phone number used for login or account recovery can still depend on older carrier features such as voicemail and call forwarding.
Researchers recommend contacting your mobile carrier and checking which additional features are enabled on your number, especially voicemail and call-forwarding services. Any unnecessary features should be disabled. Users are also advised to avoid authentication methods that depend on the mobile network, including codes sent by SMS or automated phone calls, whenever a more secure option is available.
“The attack takes advantage of little-known mobile carrier features that were likely originally designed for accessibility. It is important to check with your carrier whether such features are enabled.”
For additional protection, users are encouraged to use stronger multi-factor authentication methods, such as one-time codes generated by an authenticator app or physical security keys. At the time of publication, Telegram had not publicly commented on the incident.
The case shows that account security does not depend only on the messenger itself. If a login code can be retrieved through an insecure voicemail system, even one overlooked carrier feature can become an entry point for an attacker.