Telegram account hacking rarely starts with “breaking the encryption”. It is more likely that the user gives the login verification code to a fake customer service, scans an unfamiliar QR code, runs a program that steals the session, or forgets to clear the login on the old computer. The goal of security settings is simple: Even if a text message is intercepted or a device loses control, an attacker cannot easily take over the account.
Check below in order of priority. The interface path may differ depending on the version, but you should enter it from the official client’s Settings → Privacy and Security. Do not follow web pages sent by strangers.
1. Confirm that the bound number is still under your control
Telegram accounts are associated with mobile phone numbers. The official FAQ recommends always using the latest number you control; when changing numbers, you should migrate them through the in-app Change Number instead of waiting for the old number to be recycled by the operator.
Check that the SIM can still receive communications and that the operator account is protected by an additional PIN or number transfer. Continuing to rely on your existing login device if your number becomes invalid will make future recovery difficult. Virtual numbers, temporary access numbers and company numbers that are not under your control all increase risk.
2. Set up Passkey, but don’t give up other recovery methods because of this
Telegram joins Passkeys in 2025. It allows login to be completed with a device PIN or biometrics, reducing reliance on SMS verification codes. Go to Settings → Privacy and Security → Passkeys to see if it can be created; Passkeys can be saved in supported password managers or device ecosystems and synced to your other devices.
Do two things after creating it: Verify that the password manager itself is protected by strong authentication; Keep the phone number you still control. Passkey improves login convenience and anti-phishing capabilities, but it does not mean that the account will no longer be related to the number, nor should the unique Passkey be left on a device that may be lost.
3. Turn on two-step verification and set up a recovery email
Telegram’s Two-Step Verification requires an additional password when logging in from a new device. This password should not be the same as your email, phone unlock code, or other website. Using a password manager to generate and save long, unique passwords is more reliable than relying on simple words from memory.
Set up a recovery email and immediately confirm that the email address is correct. The recovery mailbox itself also needs to have multi-factor authentication enabled; otherwise the attacker can simply take over the mailbox first. When receiving a reset request, first check the kernel from Telegram settings without clicking the button in the email from unknown sources.
Don’t confuse 2-Step Verification passwords with SMS/in-app login codes. Neither type of credentials is required by anyone claiming to be an administrator, channel support, recruiter, or investment advisor.
4. View Devices / Active Sessions
Open Devices or Active Sessions in Privacy and Security and step through device model, client, location, and recent activity. The location usually comes from a network address and can only be used as a clue. There is no need to panic immediately if the city is slightly off; unfamiliar devices, unusual countries, or computers you no longer use should terminate the session.
Keep the current device first, and terminate sessions that you are sure you don’t recognize or no longer control. If you suspect that your account has been stolen, change your two-step verification password, protect your recovery email, check your bound number, and notify contacts who may have received fake messages.
Cleaning up regularly is more effective than reminiscing after an incident. Check your session list immediately after sharing a computer, repairing equipment, selling an old phone, or borrowing someone else’s computer.
5. Add local lock to each device
Telegram’s in-app Passcode Lock is used to prevent others from opening chats directly after getting an unlocked device. It is not the same function as two-step verification of accounts: the former protects the native application entrance, and the latter protects new logins.
Set a short auto-lock time and enable device disk encryption, system login password, and biometrics. Desktops are especially prone to staying logged in for long periods of time and should not be relied upon solely on office door locks. Notification previews may also leak information when the screen is locked or cast, and sensitive text may be hidden based on device scenarios.
6. Identify five common takeover methods
“Official Customer Service” asks for verification code
The Telegram login verification code is used to log in to your account and is not used for refunds, unblocking, voting, verification, or joining channels. Whoever the verification code is sent to can complete the login.
QR code login induction
Telegram Desktop/Web QR code is used to add new devices to your account. Strange websites that ask you to “scan the QR code to verify that you are not a robot” or “scan the QR code to vote” may essentially be authorizing a new session. Before scanning the QR code, only enter from the official client and official domain name that you actively open.
Session files and desktop programs
The so-called red envelope grabbing, channel collection, automatic trading, and member cracking tools may steal local sessions. Do not send Telegram Desktop data directories, session strings, or debug logs to anyone; do not run software whose origin cannot be verified.
SIM card replacement and number recovery
Attackers may take advantage of carrier procedures to control numbers; obsolete numbers may also be reassigned. Two-step verification, Passkey and carrier account protection can reduce risk, but the most important thing is to promptly migrate Telegram to a number you still control.
Fake channels and fake administrators
Avatar and display name can be copied. Verify accurate @username, common groups, official website links and historical behavior. The certification mark is used to identify an official identity and does not mean that every investment, recruitment or payment information is safe.
7. Adjust phone number and forwarding privacy
Check settings for Who can see my phone number, Who can find me by my number, forward message links, group invitations, and calls in Privacy and Security. Choices should be based on social needs, there is no “off them all” that works for everyone.
Telegram usernames are the public discovery portal. After setting up a username, others can contact you without knowing your number; you can remove the username if you don’t want to be publicly searchable. Restricting the visibility of your number does not erase information held by people who already know or have saved your number.
What to do first when the account is abnormal
Do not log out first while there is still one device online. Go to Devices to terminate unfamiliar conversations, set up or change two-step verification, check your number and email address, and then notify your contacts to ignore suspicious messages. If access to all devices is lost, follow the account recovery path and number control conditions in Telegram’s official FAQ.
Don’t send verification codes, IDs, or passwords to “paid recovery experts” in search results. Telegram official support will not ask for remote control of your computer through private messages with strangers.
Minimum check once a month
- The bound number is still under your control.
- Passkey is available and has a reliable backup path.
- Use a unique two-step verification password to restore email security.
- There are no strange or abandoned sessions in Devices.
- The local lock application on mobile phones and computers works normally.
- Do not display unnecessary sensitive content on the lock screen.
- No Telegram tools or clients from unknown sources are installed.
FAQ
Can Passkey completely replace a mobile phone number?
It cannot be understood this way. Telegram officials still recommend keeping the bound number under your control, and Passkey is one of the more secure and convenient login methods.
Will terminating other sessions delete the chat?
Terminating the session will cause the corresponding device to log out of the account, which does not mean deleting the cloud chat. Secret Chats on this device are device-specific and cannot be restored from the cloud after exiting.
What should I do if I receive a verification code that I did not apply for?
Don’t forward or type to unfamiliar pages, check Devices and 2-step verification status. The verification code itself may indicate that someone attempted to log in, but success can only be determined when combined with the session list.
Sources
- Telegram: Passkeys, Gift Purchase Offers and More — Passkey login, management path and instructions for retaining active numbers.
- Telegram: Active Sessions and Two-Step Verification — Official introduction to active sessions and two-step verification.
- Telegram FAQ — Number change, account security, verification code, local lock and privacy settings.
- Telegram: Security — Security model description of cloud chat and Secret Chats.
This page was last reviewed on August 9, 2026. Telegram interfaces can change by client and version.