Two Common Mistakes on Telegram That Allow Scammers to Hijack Accounts
Telegram account takeovers are on the rise due to simple user mistakes, including entering OTPs on phishing links and failing to enable Two-Step Verification.

Telegram account takeover incidents are currently occurring with increasing frequency. According to cybersecurity guidance, these compromises are largely driven by simple mistakes made by users themselves, which allow threat actors to gain unauthorized control of their accounts.
Two Common Mistakes Putting Accounts at Risk
Cybersecurity guidance highlights two critical security lapses that frequently lead to Telegram account hijackings:
- Entering OTP codes into phishing links: Users are often deceived into submitting their One-Time Password (OTP) verification codes on fraudulent websites created by scammers.
- Failing to enable Two-Step Verification: Many users do not set up an additional cloud password or Two-Step Verification, allowing attackers to access the account solely with the intercepted OTP.
Consequences of an Account Takeover
Once attackers successfully gain access to a Telegram account, they take over full control and exploit it for malicious activities. Notably, perpetrators frequently use the compromised account to target and scam individuals found within the victim's contact list, multiplying the impact of the attack.
Recommended Security Measures
To safeguard Telegram accounts from unauthorized access, users are advised to take immediate preventive steps:
- Never share or enter an OTP code with anyone or on suspicious links.
- Immediately activate the Two-Step Verification feature within the app's settings to establish a strong cloud password.
Source: Cyber Security Agency of Singapore



