Skip to main content

Trends & statistics

Cybercrime discussions are moving toward Telegram, new research finds

Cybercrime discussions are moving toward Telegram, new research finds

Summary: NordLayer Intelligence by NordStellar tracked cybercrime discussion across dark web forums and Telegram. Telegram’s average share across 7 categories reached 45% in early 2026, up from 28% in 2025.

In the first 5 months of 2026, Telegram’s average share of cybercrime discussion reached 45%, compared with 28% across all of 2025. That is a 61% increase.

For anyone who keeps systems patched and accounts secure, the change points to a rise in high-volume, low-skill attacks that can be quickly launched and easily scaled.

What the research measured

From January 2024 to May 2026, NordLayer Intelligence analyzed monthly post counts across dark web forums and Telegram channels monitored by its platform.

Discussion volume by threat type: Telegram and dark web forums

The 2026 figures only cover the period from January to May. The counts measure discussion volume, not confirmed criminal activity or victims. Only aggregate counts were analyzed, and no personal user data was collected. The findings are limited to sources monitored by NordLayer Intelligence and do not represent all activity on Telegram or the dark web.

The 7 cybercrime categories tracked

The research covers 7 popular cybercrime categories: malicious AI tools, deepfakes, ransomware-as-a-service, stealers, distributed denial-of-service, malware, and phishing. Each category was measured separately across both dark web forums and Telegram channels.

How the “share” was calculated

The 45% figure is an average across the 7 categories, not the total percentage of all cybercrime posts on Telegram. NordLayer Intelligence first measured Telegram’s share of posts in each category separately, and then averaged those figures. This is an unweighted average, so each category counts equally, regardless of its total post volume.

Why cybercriminals are gravitating toward Telegram

According to Vakaris Noreika, Cybersecurity Expert at NordLayer Intelligence by NordStellar, one reason for the increase may be law enforcement pressure on traditional dark web forums.

Law enforcement takedowns of dark web forums

High-profile seizures of large hacker forums, such as LeakBase, could have pushed threat actors to look for alternatives.

“Dark web forums are essentially communities for threat actors, and they spend years building their reputation to prove the trustworthiness of their sellers,” explains Noreika. “Each time a dark web forum gets taken down, it fragments the market. The threat actor community that used the forum then scatters across other smaller forums, where the once-trusted sellers enter as new, unverified users, and find it challenging to find new potential buyers.”

Even after threat actors join a new forum, they know it could meet the same fate.

“Building credibility, and even getting accepted into a new dark web forum, requires time and effort, and with the increasing likelihood of it eventually getting shut down, some threat actors might deem the investment no longer worthwhile,” says Noreika. “Telegram operates without these complex re-registration and reputation-building processes, so it becomes the simpler alternative.”

A lower barrier to entry for less experienced hackers

Telegram is a mainstream messaging platform that requires no special software or an invitation to access. In contrast, reaching dark web forums takes more technical steps, which is harder for newcomers.

“Compared with the dark web forums, Telegram presents a much lower-friction environment, so less experienced threat actors can reach cybercrime communities more easily,” says Noreika. “Even though the platform blocked over 20 million groups and channels this year according to their official safety report, cybercriminals regroup quickly, just as they have long done on the dark web, and doing so is far easier on Telegram.”

What stays on the dark web, and why

NordLayer Intelligence breaks down the current Telegram cybercriminal community into 2 parts. Most participants are newcomers looking for automated, mass-volume attacks. Alongside them are more experienced actors who use Telegram to advertise services or carry out lower-value deals, while keeping their main operations on the dark web. The dark web still plays a role in higher-value activity.

“Despite the risks posed by ongoing law enforcement operations, the dark web offers higher operational security, and threat actors aren’t likely to trust Telegram for high-value transactions,” says Noreika. “The reputation and vetting infrastructure exists on the dark web for a reason. It’s unlikely that threat actors would carry out highly expensive and risky deals in a messaging platform that should cooperate with law enforcement.”

What this means for the attacks you’ll see

This rise in discussion volume does not mean the attackers are becoming more skilled. Instead, the data tells about a growing number of lower-skilled threat actors who use easily accessible tools to launch high-volume campaigns.

IT teams will have to pay closer attention to several types of attacks, like phishing, credential theft, account takeover attempts, denial-of-service-for-hire (a paid service that floods a website or network with traffic to knock it offline), and deepfake-enabled fraud. Each of these can be scaled quickly.

Steps to reduce your exposure

Follow the core cybersecurity practices recommended by the CISA.

  • Use a unique password for every account, and store your passwords in a reputable password manager. Credential theft is still one of the most common ways attackers gain access.
  • Enable multi-factor authentication wherever possible, preferably using phishing-resistant methods (passkeys or security keys). Phishing-resistant MFA can stop more than 99% of identity-based attacks. Even when an attacker already has the correct username and password.
  • Keep your operating system, applications, and other software up to date. Enable automatic security updates where possible. Vulnerability exploitation is the most common initial infection vector for the 6th consecutive year.
  • Keep publicly available personal information to a minimum and review the privacy settings on your social media accounts.

If credentials or other sensitive information are exposed, it’s important to act quickly. Deep and dark web monitoring can provide alerts of many instances of leaked data. It allows for the detection of leaks across Telegram and multiple dark web forums, and also helps respond fast: change passwords, revoke access from compromised accounts, and stay on high alert for any signs of escalation.

Limits of the data

From January 2024 to May 2026, a total of 86 dark web forums and 1,890 Telegram channels were monitored. The source pool changed over this period. New sources emerged, and others were shut down or seized, so year-on-year comparisons reflect changes in activity alongside changes in the source pool itself.

The same set of channels was not tracked unchanged across all three years. Post counts measure discussion volume within monitored sources only. They do not confirm criminal activity, victims, or the full scale of activity on either Telegram or the dark web.

This analysis is provided for general information only and does not constitute legal, security, or professional advice, nor any guarantee of security or outcome. It reflects activity detected within NordLayer Intelligence’s monitored sources during the stated period and describes aggregate patterns only. References to third-party platforms and services are for identification and factual reporting only and do not imply any wrongdoing by, endorsement by, or affiliation with those parties. All third-party trademarks remain the property of their respective owners.

Cybersecurity Copywriter

Share this post

Stay in the know

Subscribe to our blog updates for in-depth perspectives on cybersecurity.