top of page
Soft diagonal parallel lines graduating from deep navy to light cream, faint teal midtone

Telegram Is Not the Black Market. But It Can Look Like One.

  • CorporateSurvivorDiaries
  • Aug 4
  • 4 min read
Abstract navy and teal illustration of a stylised paper-plane icon — evoking Telegram's logo — dissolving into fragmented chat bubbles and data points, symbolising how a messaging platform

In May 2026, 17-year-old Samiksha Narsale sat India's NEET medical entrance exam along with roughly 2.2 million other students. A week later, rumours broke that the question paper had leaked — on Telegram. A retest was ordered. True to form, the same Telegram channels Narsale followed promptly filled with rumours that the retest paper had leaked too. "Suddenly, everyone felt they had to be on Telegram," she told CNA, "because you didn't know what information might appear there." Acting on the National Testing Agency's recommendation, India's government blocked the app nationwide from 16 to 22 June. Telegram challenged the block in the Delhi High Court — and lost. The judge found the platform "structurally prone to swift and wide circulation of unlawful content," and the government's own submission during the hearing put it more bluntly: Telegram, the Centre argued, had become "the new dark web."


The exam leak is almost a sideshow. What CNA's reporting actually surfaces is a pattern: investigators across the region have traced stock-price rigging, investment fraud rings, and organised scam operations back to the same platform, again and again. Not because Telegram is uniquely malicious, but because of what it structurally rewards — closed groups that can be created and abandoned in minutes, invite links standing in for identity checks, and enough scale that one scammer becomes a broadcaster.


So the more honest framing isn't "Telegram is the black market." It's that Telegram's architecture — semi-anonymous, hard to fully police, built for speed — lets parts of it function like one.


The personal risk: A scam often begins elsewhere — WhatsApp, a job board, a dating app — somewhere with enough legitimacy to make first contact plausible. Telegram becomes the next stage once trust needs building at scale: a group chat of fake "successful investors," a slick channel with thousands of subscribers, screenshots of other people's supposed profits. Only once that scaffolding is up does the actual ask arrive. Singapore has seen this precisely: an SPF advisory issued 16 July warned of fraudulent Telegram messages impersonating GST Voucher and MediSave communications, which directed victims to phishing sites collecting personal details and, in some cases, tricked them into surrendering Telegram verification codes — enabling account takeovers that hand scammers a more credible channel from which to target the victim's own contacts. In investment and advance-fee scams specifically, the story rarely ends at the first payment; a "verification fee" or "withdrawal tax" often follows, right before the operator vanishes and resurfaces under a new name.


That vanishing act is the hinge to the bigger story. It's one thing for a single scammer to disappear and rebrand. It turns out to be just as easy for entire criminal marketplaces.


The corporate risk: As law enforcement has disrupted major cybercrime forums — including BreachForums and LeakBase — some of that trade has migrated to Telegram, where stolen data can be advertised to a criminal audience of thousands almost instantly, no special access required. These channels are more exposed than the "dark web" label suggests — public or easily joinable, which is why it is appealing to researchers who can access these Telegram group chats fuss free. Tools built for this economy are themselves sold as a service — cybercriminals could subscribe to a phishing kit called JokerOTP, which automated phone calls that talked victims out of their one-time passwords; the tool was used in over 28,000 attacks across 13 countries before Dutch and UK police dismantled it. Its developer was arrested in April 2025, and this February, Dutch police arrested a third suspect — the man accused of selling access to the tool through a Telegram account. Steal, threaten, sell, repeat: those are the mechanics now running through Telegram channels at industrial scale. For a GRC team, the uncomfortable implication is that a channel like this may reveal your breach before your own security team knows it has happened.


Zoom out, and Singapore's numbers tell a split story. Overall scam losses actually fell in 2025, from roughly S$1.1 billion to S$913.1 million, per SPF's Annual Scam and Cybercrime Brief — a drop of nearly S$200 million. But government-official impersonation scams, precisely the category behind July's GST Voucher advisory, remain a specific area of concern for SPF even as the overall trend improves. The specific playbook this article is about is not going away.


What companies should do now: Assume your brand will eventually be impersonated on Telegram, and monitor for it rather than waiting on a customer complaint. Check whether your threat intelligence coverage extends past dark-web forums into Telegram channels — that's increasingly where your own breach surfaces first. State plainly, everywhere you communicate with customers, which channels you'll never use to ask for OTPs or credentials.


What individuals should do now: Treat any OTP request as suspicious, no matter who appears to be asking — including a contact whose account may itself be compromised. Never use a link inside a Telegram message to check a government payout; go direct to gov.sg. And if a "fee" appears after you've already paid something, that's not a delay — that's confirmation you're already inside the scam. When in doubt, call the ScamShield Helpline at 1799 before you click.

 
 
 

Comments


bottom of page