A Telegram admin account is compromised: protect the group
Secure a compromised admin account and group, keep verified communications available when the whole team loses access, and check what recovery actually restored.
If an administrator reports losing control of their Telegram account, start two jobs in parallel: the account holder works on account security, while trusted administrators check what is happening in the group. Address an active scam promptly, while labeling unconfirmed details as suspicions.
This guide covers incident response. For a planned change of owner, use the handover procedure. A successful login does not establish that group ownership and permissions were restored.
Establish a trusted way to coordinate
Contact the affected person through a previously verified alternative, such as an established phone number or an in-person conversation. Do not accept new account-management instructions solely from the account under investigation. A message saying “everything is fixed” needs the same caution.
Write a short starting record:
- Which account and group are affected
- What was observed, with time and time zone
- Whether the person still has a trusted, signed-in device
- Which other administrators still have access
- Which harmful changes are continuing now
An unexplained logout, unfamiliar message or missing permission is a reason to investigate, not proof of who caused it. Keep observed facts separate from guesses. For example: “The owner denies sending today's payment request; it remains pinned” gives the team a concrete task without accusing a named person.
Agree who handles the account and who handles the group. Avoid several people changing the same settings at once. Keep the incident discussion away from a moderator chat if the suspected account can still read it.
If a trusted session is still available
Use a device you control and have no reason to distrust. Preserve that working session while you inspect the situation; signing out reflexively can remove the access you need. If the device itself may be compromised, do not enter fresh secrets on it.
Telegram's account-security FAQ points to Settings → Privacy and Security → Two-Step Verification, then Settings → Devices or Active Sessions to end the lost device's session.
Work through the controls deliberately:
- Inspect login protection. Enable two-step verification if absent. Change a potentially exposed password through the official app if permitted, using a unique password and your own recovery mailbox. Record unavailable actions rather than starting repeated resets.
- Review sessions. Identify your current device and the other devices you recognize. End sessions associated with a lost device or access you cannot account for, where Telegram permits it. Never give another person a session file or login QR code to perform this check.
- Verify the result. Reopen the device list and check that the targeted sessions are gone. Record any termination that was refused; clicking a button does not establish success.
- Review passkeys. Open Telegram's passkey settings and compare the listed keys with your own setup. A listed key alone does not prove compromise. Remove keys you did not create or no longer control, then verify the list while keeping your trusted session. Passkey removal is a separate check: ending a session does not confirm that registered login credentials were revoked.
- Check recovery access separately. Secure the associated email and phone account through their own providers if either may also be affected.
Telegram's two-factor documentation describes the additional password and email recovery flow. Treat password protection and session termination as separate checks. Do not declare containment merely because a password setting changed.
Why a newly signed-in device may be unable to end other sessions
Telegram's session-termination reference documents a restriction when the current session is less than 24 hours old. A successful new login therefore may not let you remove an older session immediately.
Follow the exact notice in the official app. If another trusted, established session exists, check the available action there. Otherwise, record when Telegram says to return and keep the group response running. Do not repeatedly sign in, disable security settings or pay someone promising to bypass the wait. A countdown is an unresolved task, not confirmation that the attacker has lost access.
If no trusted session remains
Use Telegram's official login and recovery prompts from a trusted device. If the phone or SIM was lost, Telegram's FAQ directs you to the carrier to block the old SIM and recover the same number, then sign in and review sessions.
A replacement SIM is not a guarantee that every login requirement is satisfied. If the app asks for a password you do not know, follow its recovery choices and read the consequences before confirming anything. Do not invent a recovery deadline from someone else's case. The official Telegram support form is an available place to describe a blocked login; a submission does not establish a recovery outcome.
Meanwhile, give trusted administrators the verified facts through the agreed alternative channel. Ask them to inspect the group's actual state. Do not ask them to share an account or send you their login code as a shortcut.
Do not delete the Telegram account to “clear the hack.” Account deletion is irreversible. Telegram's deletion warning makes that consequence explicit. Avoid paid recovery intermediaries and anyone asking for codes, passwords or access to your email.
If the whole team loses group access
First identify what is unavailable. “The group is gone” can describe several observations that need different responses.
- One administrator cannot sign in. Another trusted administrator can still see the group and its settings. Continue that person's account recovery while the available colleague protects the group within their rights.
- Accounts work, but the group will not open or management rights are missing. Record Telegram's exact notice and ask another established administrator who already belonged to the group to check. This alone does not prove deletion, takeover, a platform restriction or anyone's responsibility.
- Telegram explicitly reports an account or group restriction. Record which object the notice concerns and what official next step it offers. An invalid invitation, a missing directory listing or one person's inability to send does not by itself establish a group-wide block.
Verify the observation from an existing trusted session or through another previously known administrator. Do not sign out of your only working session as an experiment or give a stranger access to investigate. If the cause is unresolved, say so: “The team has not confirmed access to the group; the cause is still being checked.”
If nobody retains the necessary rights, deleting posts, fixing pinned notices and operating the moderation bot in that group remain unavailable. Do not announce that restrictions are active based on an intention or a last-known setting. State what the team can actually do now.
Keep an announcement route outside the unavailable group
Use a website, mailing list or other announcement channel members already recognize and the team still controls. Check that this route also remains accessible: another Telegram chat is not a reliable fallback when its only responsible account is locked out. Name a person to publish updates and a backup with their own verified access.
A useful notice includes the current status, a temporary help route and the time of the next update with its time zone. For example: “The team cannot currently manage the main group. We will post another update here by 18:00 UTC, even if the cause is still unresolved. Please use our usual website contact form for help.”
Replace those details with a real contact and an update time the team can meet. Do not turn an update deadline into a recovery promise. Do not publish affected-member lists, personal phone numbers or new payment instructions. If suspicious payment requests are circulating, the crypto-community scam response provides a relevant warning and verification workflow.
Previously saved rules, staff responsibilities and approved public materials can support continuity. Telegram Desktop export saves accessible history into files; it does not restore ownership, permissions or an unavailable group. Do not export all members and conversations merely to issue a notice. Use the minimum scope described in the history-export guide; a new export may be impossible without access.
Choose the official route for the observed problem
For a blocked login, use Telegram's support form. For other questions from an account that works, the FAQ points to Settings → Ask a Question. If the issue is specifically an account's spam restriction, the Spam FAQ directs users to the official @SpamBot. That is not a general group-recovery service.
Keep the request factual: the available account or group identifier, time, exact notice, remaining rights and checks already performed. Never include a password, login code or session file. Record when you contacted support and any response; do not claim that recovery has been accepted without confirmation. There is no basis to guarantee a deadline or outcome.
If Telegram imposed a restriction, use the available appeal process. A backup communication route is for verified notices, not evading enforcement through new accounts, mirrors or reposting prohibited material. Do not begin moving the community before establishing what is permitted and who can authorize the decision.
When access returns, verify the exact group and each responsible person's rights, rather than just a successful sign-in. If the chats are connected through Telegram Communities, also review staff-chat visibility and access. Then complete the checks below and tell members only what has been confirmed.
What the remaining administrators should check
Work from each administrator's actual permissions. Telegram provides separate privileges, and its permission model limits which administrators a delegate can manage. Do not assume that any admin can demote the owner, reverse a takeover or change every setting.
Start with the active harm, then inspect these areas:
- Owner and administrator list. Record who Telegram currently identifies as owner, any new administrators and unexplained privilege changes. Revoke suspicious access only where your own rights permit. If the action is unavailable, record that blocker rather than promoting more people indiscriminately.
- Bots. Check newly added bots, their exact profiles and rights. Compare them with the tools the team intentionally installed. Remove an unauthorized bot if you can, then check the result. A familiar display name is not enough to identify a service.
- Messages and group identity. Inspect pinned notices, payment requests, description links and recent announcements. Preserve the minimum evidence needed before removing harmful material, without delaying urgent cleanup for a full archive.
- Invitations. Identify suspicious or exposed invitations and revoke those you are authorized to manage. Check other entry routes before announcing that access is closed; use the invite-link review.
- Moderation settings. Look for unexpected permission changes, disabled filters or altered log destinations. Change only what you can explain and verify.
For example, a trusted moderator might be able to remove a scam message but not change the owner or remove another administrator. Removing the message is useful containment. Report the remaining access problem explicitly; “the post is gone” and “the group is secure” are different conclusions.
Preserve a small, useful incident record
Inspect Recent Actions promptly. Telegram describes an admin-only, 48-hour view. For the detailed investigation flow, use the Recent Actions guide.
Keep the time, account identifier, affected setting or message, observed action and outcome of the response. If a screenshot is necessary, crop out unrelated conversations, phone numbers and working private invitations. Store evidence where only the people handling the incident can access it. Do not collect an entire member database to explain one changed administrator.
If the incident includes exposed personal data or illegal material, do not reproduce the contents in screenshots or staff copies. Follow the doxxing guide's safer evidence and reporting procedure.
Treat log attribution carefully: an action attributed to the affected account identifies the account used, not necessarily the person operating it. Missing evidence is also worth recording, especially if the event is outside the available window. Do not promise deleted-message recovery.
Warn members through a verified channel
Use an established announcement channel or a group notice posted by a trusted administrator who still has permission. If the affected person cannot post safely, another verified team member should issue the warning. Avoid sending everyone to a newly created “support” account.
A useful notice states the affected account, the requests members should ignore for now, and where verified updates will appear. For example, after checking the facts:
“Today's payment request from the administrator account is being investigated. Please do not pay or share login codes in response. Updates will appear in this channel.”
Adapt the text to what actually happened. Do not repeat an attacker's payment details or make the malicious link easier to click. Ask members with relevant evidence to use an existing private reporting route rather than posting personal details publicly.
Check Defendy and confirm what is restored
Review Telegram rights, Defendy roles and access to the log destination separately. Defendy does not recover personal Telegram accounts or restore group ownership. A bot role does not secure the owner's login.
After authorized Telegram admin changes, inspect the role documentation before using /reload: it rebuilds administrative Defendy roles from Telegram and may replace bot-only assignments. Verify the resulting roles. Check that the intended group is selected in the Mini App, the moderation bot still has the necessary rights, and the log goes to a destination the trusted team can read.
Use a harmless agreed test to check the needed moderation action. Where logging is configured, verify the relevant enabled event. Defendy logs contain selected recorded events; they are not an account-recovery service or proof of complete incident coverage.
Before closing the incident, confirm:
- The account holder controls the login and recovery methods being relied on, including registered passkeys
- Session review succeeded, with no unresolved termination prompt
- Telegram shows the expected owner, administrators and bot rights
- Suspicious invitations and announcements have been addressed
- Defendy roles and log access have been checked
- A named person owns every remaining restriction or recovery step
If ownership is still wrong or an essential action remains blocked, keep that outcome open. Never promise a return of the account or group based only on a support request or a successful login.
Sources checked on October 7, 2026. The examples are illustrative; this article does not report a live account-recovery test.