Telegram account hacked: take it back, then shut out the QR-code and login-prompt tricks seen in 2026
Telegram account hacked? End the attacker’s session, turn on two-step verification and a passkey, and see how the QR-code and login-prompt scams work.
Telegram accountsBy Dariusz KrasinskiPublished 12 min read
In short
- Scanning a Telegram QR code or approving a login prompt starts signing another device in to your account. Nothing about it “verifies” you.
- End unknown sessions under Settings > Devices from a device you were already logged in on, then turn on two-step verification.
- Channel ownership can’t move without the owner’s two-step verification password, so set one before you need it.
Telegram account hacked? Act from a device that is still logged in: open Settings > Devices, end every session you don’t recognise, then turn on two-step verification so your number alone can’t log anyone back in. Campaigns researchers documented in 2026 trick you into scanning a QR code, approving a login prompt or typing your login code into a fake page.
Telegram account hacked? What to do in the first hour
Speed matters, because whoever holds a session can read your cloud chats and write to your contacts as you. Work through these steps in order, ideally on the device you have been signed in on for longest.
Use a device that is still signed in
Telegram identifies users only by phone number, so a session you already have is your strongest tool. Its FAQ is blunt: “we can’t help you unless you have access either to the phone number or to Telegram itself on any of your devices.”
End the sessions you don’t recognise
Open Settings > Devices (on some apps, Privacy & Security > Active Sessions) and terminate anything unfamiliar. If you can’t tell which is which, CYFIRMA’s advice is to log out of all other sessions (Terminate all other sessions).
Turn on two-step verification, or change its password
Go to Settings > Privacy and Security > 2-Step Verification. If it is off, pick a password you use nowhere else and add a recovery email; Telegram says “the phone number alone will not be enough to log in to your account.” If it was already on, change the password: CYFIRMA’s advice is to do so “as soon as possible”, because phishing pages ask for it.
Check what was sent in your name
Scroll through recent chats for messages you didn’t write. Researchers at both CYFIRMA and Bitdefender found that hijacked accounts are used to send the same lure to the victim’s contacts, sometimes with requests for money.
Warn your contacts another way
Tell friends, colleagues and group members, by a call or a different app, to ignore links or requests that came from your account, because the attack spreads through trusted contacts.
Review your channels and groups
Open each chat you own or administer and check the admin list, recent posts and invite links. The section on channels below covers what an attacker can and can’t do there.
Call your phone provider if the SIM is at risk
If your phone was stolen or the number may have been moved to another SIM, Telegram’s FAQ tells you to ask your provider to block the old SIM and issue a new one with your number.
A brand-new session can’t end the others straight away
Telegram’s API documentation lists this error for ending other sessions: “You can’t logout other sessions if less than 24 hours have passed since you logged on the current session.” It cuts both ways. An attacker who has just signed in can’t use that session to throw you out, but if you sign back in on a new device you may have to wait before you can end theirs. That is why the device you were already using matters.
Locked out of your Telegram account? How to get back in
If the attacker has ended your sessions, you need the phone number: sign in again with the login code Telegram sends to it. Ask for the code once and wait for it: requesting it again and again triggers a flood wait on sign-in that can last until the next day. If the number itself is gone, ask your provider for a new SIM with the same number first. What happens after the code depends on the two-step verification password.
- No password is set: the code gets you back in. End the other sessions, allowing for the 24-hour rule above, and set a password straight away.
- The attacker set or changed the password: use the recovery option on the password screen. As Telegram’s password documentation describes it, recovery sends a code to the account’s recovery email and entering it removes the current password, so it helps only if that email is still yours.
- You still have a signed-in session but not the password: the same documentation describes a reset from a logged-in session that starts “a 7-day server-side timer” before the password is removed.
- You have the code, but no password and no other session: the documentation says “the account can be deleted”. Treat that as a last resort, because Telegram’s FAQ warns: “All groups and channels that you’ve created are orphaned and left without a creator but admins retain their rights.”
How Telegram accounts get hijacked in 2026
Three techniques stand out in 2026 research. None of them breaks Telegram’s encryption or guesses a password. Each one gets a valid session onto the attacker’s device, either by persuading you to approve it or by copying one you already have.
| Technique | What you see | What the attacker gets | Reported by |
|---|---|---|---|
| QR-code lure | A Telegram-style QR code to scan, framed as a vote, a contest or a verification step | A signed-in session on their device | Bitdefender, April 2026; CYFIRMA, February 2026 |
| Login-prompt phishing | A QR code or a fake login form, then a real Telegram prompt in your app that the page calls a “security check” | Full session access once you approve | CYFIRMA, February 2026 |
| Desktop session theft | Nothing: a script named “Windows Telemetry Update” copies files in the background | Telegram Desktop’s tdata folder, usable without a password or code | Kaspersky, June 2026 (a prototype) |
The older trick is back too. AhnLab reported in May 2026 that SMS messages claiming a security problem lead to fake Telegram login pages that collect phone numbers and login codes. Telegram’s servers automatically invalidate login codes that are sent to another Telegram chat, but nothing stops you typing a code into a website. Treat a login code like a password.
A hijacked account is often the start of a wider scam rather than the goal. For the other half of the pattern, see how Telegram impersonation scams work.
The Telegram QR code scam: scanning is signing in
Telegram lets you log in on a computer by scanning a QR code with the app on your phone. It is a real, convenient feature, and it is exactly what the scam abuses. The lure often arrives from a familiar contact, sometimes someone you haven’t spoken to in a while, whose account has already been taken: vote for a child’s artwork, support a school competition, help someone win a prize, or confirm you are human. The page shows a QR code and asks you to scan it with Telegram.
The entire attack hinges on one misunderstanding: users think they are proving something when they are actually granting access.
Bitdefender’s advice is to treat any QR scan that asks you to link a device as a login request, not a verification step.
Fake approval prompts and “security check” pages
CYFIRMA’s February 2026 report describes a campaign with two entry points: scan a QR code, or type your phone number, login code and two-step verification password into the page. Either way the attacker’s app, using its own API credentials, starts a legitimate login, and Telegram shows a genuine prompt in your app asking you to confirm with options such as “This is me” or “Yes”. The page frames it as a security check.
- You didn’t start the login yourself, but a prompt appeared anyway.
- A page you reached from a link tells you to approve something in Telegram.
- The request is dressed up as a vote, a prize, a verification or a security check.
- A website asks for your login code or your two-step verification password.
Any one of these is enough to stop. CYFIRMA’s rule is the simplest one to remember: only approve a Telegram login or authorisation prompt if you personally started that login.
Session theft from Telegram Desktop
Telegram Desktop keeps its login in a folder called tdata. In June 2026 Kaspersky described a PowerShell script, named “Windows Telemetry Update”, that archives that folder and sends it to a Telegram bot. Whoever holds the copy can use the account without a password or code until the victim checks the active sessions and ends the suspicious one.
Keep this in proportion. Kaspersky says the script appears to have been caught in the prototype stage, and the stealer “likely hasn’t compromised any accounts yet, as experts found no evidence of actual data transfers.” It is still a useful warning, because session theft skips the login prompt entirely. Don’t run scripts or “updates” that someone sends you. The fix is the same as for every other technique: end the unknown session.
How to check and end active Telegram sessions
Every device and app signed in to your account is listed under Settings > Devices; open it regularly, not only after something goes wrong. Telegram’s API documentation shows what each session carries:
- the device model, platform and system version;
- the app name and version, and whether it is an official Telegram app;
- when the session was created and when it was last active;
- the last known IP address and the country and region worked out from it;
- whether the session is still waiting for a two-step verification password.
That last flag is worth knowing. A session that is waiting for your password means someone got past the login code or a QR scan and stopped only because two-step verification asked for more. End it, and treat your code or the scan as compromised.
Telegram also tells your other devices when a new one logs in. According to the login documentation, apps show a notification asking whether you recognise an unconfirmed session, and answering no logs that session out. If you get one of these and you didn’t just sign in somewhere, answer no.
Set up Telegram two-step verification and a passkey
Two-step verification adds a password on top of the login code. Once it is on, Telegram says “you will need both an SMS code and a password to log in.”
- Two-step verification: Settings > Privacy and Security > 2-Step Verification. Use a password you don’t use anywhere else.
- Recovery email: add one when you set the password, and protect that mailbox with a strong password and its own second factor, as Telegram recommends.
- Passkey: Settings > Privacy and Security > Passkeys, which Telegram says you can set up on any device.
- Phone number: keep the account on an active number you control, even with a passkey.
Passkeys arrived on 12 December 2025. Telegram’s announcement says they let you log in “with a PIN or biometric data like Face ID and fingerprints — instead of an SMS code.” It doesn’t switch codes off, though: Telegram’s FAQ says “with a passkey, you can still request an SMS code in order to log in”, and a passkey does nothing to stop you approving a QR code or a prompt. Keep two-step verification on as well. Kaspersky recommends passkeys for their protection against leaks and phishing.
Two-step verification has one weak spot
It protects you only while the password stays secret. The manual path in CYFIRMA’s campaign asks you to type it into the phishing page. Enter it only in Telegram’s own apps, or in a login you started yourself on a tool’s own site.
What a hijacked account means for your channels and groups
Whoever controls your account can do whatever that account can do in each chat you run: post, edit, remove members, change the description or invite links, and appoint admins if you are allowed to.
Ownership itself is better protected. Telegram’s method for transferring a channel needs the owner’s two-step verification password and fails if two-step verification isn’t on at all. It also refuses when the password was changed less than 24 hours ago or the session was created less than 24 hours ago. A fresh session from a QR scan therefore can’t hand your channel to someone else on day one, which gives you time to end it.
| Check | Why it matters |
|---|---|
| Every admin has their own account with two-step verification | One hijacked login then can’t take the whole team with it |
| Admins get only the rights they need | Telegram sets rights one by one, such as posting, banning users and adding admins, so a compromised helper can do less |
| Have a second way to reach members | If the owner account is taken, members need to hear from you somewhere the attacker can’t post |
| Know which tools hold a session | Each one appears under Settings > Devices, and anything you no longer use should be ended there |
If Telegram limits the account after it was misused, see what to do when a Telegram account is frozen.
Is it safe to connect Telegram to a tool with a QR code?
It can be, but a legitimate tool and a phishing page use the same Telegram login, and scanning the code starts a new session either way. The difference is who started it, where, and why.
| Question | A tool you chose | QR or prompt phishing |
|---|---|---|
| Who starts the login | You, on purpose, on the tool’s own website | A message or link that reached you, often from a contact |
| Where the password is typed | Only if the account has two-step verification, as part of that login | Into a page that relays it to the attacker |
| Afterwards | The session is under Settings > Devices; end it any time | End it under Settings > Devices as soon as you notice |
Before connecting any tool, check the address in the browser and find out where it keeps the session and how you remove it.
How a connected session is kept and removed
Dripl connects an account the same way: you scan a QR code shown on Dripl’s own site with the Telegram app on your phone, or sign in with your number and the login code Telegram sends, and an account with two-step verification asks for that password too. See how connecting works.
Each connected account’s session is a separate file on Dripl’s server that only the Dripl app can read, and session files are never returned by the API or shown in the dashboard. Removing an account in Dripl logs its session out on Telegram’s side and deletes the session file. The details are on the security page, under Telegram accounts.
Dripl doesn’t detect or block hijacking, so the checks above still apply to every account you connect. You can also end its session yourself under Settings > Devices, like any other.
Multi-account
Connect several Telegram accounts with a QR code, give each its own sending pace and proxy, and see at a glance which ones need you.
Telegram impersonation scams
A Telegram impersonation scam copies your channel or admins to trick members. Learn to spot clones, report them and make your community harder to copy.
Frozen accounts
Telegram account frozen? See what read-only mode blocks, how to appeal via @SpamBot before the deletion date, and how to keep work accounts clear of reports.
Sources
- Telegram FAQ: 2-Step Verification, lost phones and sessions · checked
- Telegram blog: passkeys (12 December 2025) · checked
- Telegram API: user authorisation, login codes and confirming logins · checked
- Telegram API: two-step verification, password recovery and reset · checked
- Telegram API: auth.resetAuthorizations · checked
- Telegram API: the authorization (session) object · checked
- Telegram API: channels.editCreator (ownership transfer) · checked
- Telegram API: admin rights · checked
- CYFIRMA: re-emerging Telegram phishing campaign targeting authorisation prompts (7 February 2026) · checked
- Bitdefender: Telegram QR code scam (28 April 2026) · checked
- Kaspersky: a Telegram session stealer that needs no password (23 June 2026) · checked
- AhnLab ASEC: Telegram smishing is back (20 May 2026) · checked
How the guides are researched and updated: editorial standards.
FAQ
Questions, answered
Can’t find it? Contact support
Does two-step verification stop QR-code phishing?
It stops the attacker taking full control, as long as they don’t have the password: Bitdefender notes that someone who gets in through a QR login can’t fully control the account without it. It can’t help if you type the password into the phishing page, so enter it only in Telegram’s own apps or a login you started yourself.
What is a Telegram passkey and should I use one?
A passkey lets you log in with your device’s PIN, fingerprint or face scan instead of an SMS code. Telegram added it on 12 December 2025, under Settings > Privacy and Security > Passkeys. It gives you a login that doesn’t depend on an SMS code, but codes still work, so keep two-step verification on and the account on a phone number you control.
Can Telegram support give me my hacked account back?
Telegram’s FAQ says the phone number is the only way it identifies users, so it can’t help unless you still have the number or a signed-in device. With either, you recover the account yourself: sign in, end the other sessions and change the two-step verification password. If the number is at risk, ask your provider for a new SIM with the same number first.
What if I already typed my login code into a website?
Assume someone has signed in or is about to. Open Settings > Devices on a device you trust, end any session you don’t recognise, including one still waiting for a password, and turn on two-step verification if it is off. Telegram cancels codes that are sent in a Telegram chat, but not codes typed into a website.
How do I know if someone else is using my Telegram?
Look for an unfamiliar device, app or location under Settings > Devices, messages you didn’t send, contacts replying to things you never wrote, or a new-login notification you didn’t expect. Any one of these is reason to end the other sessions now rather than wait.