On the day of the invasion, CPR documented a six-fold increase in Russia-Ukraine Telegram groups themed on the war.
It’s been observed that some of the groups that coordinate cyberattacks on Russia boast more than 250,000 users.
“Telegram has become a digital forefront of the conflict, where people are choosing sides online,” said Oded Vanunu, Head of Products Vulnerabilities Research at Check Point Software.
71% of Telegram groups relevant to the conflict push flash news of unedited and often unverified information. These groups are found to contain hackers, IT professionals and other “IT fans”.
23% of the groups are set up to coordinate cyberattacks on Russia, mostly DDoS with some calling for SMS and call-based attacks.
Not all are focused simply on coordinating cyber-offensives against Russia, with 4% of Telegram groups set up to request cryptocurrency donations to support Ukraine. Many of these groups have tens of thousands of users though CPR warns that many are suspicious and likely fraudulent.
Recommended
- Comment | Building better tech companies from the inside out
- Online child safety boosted through Scots Cyber Citizens programme
- Comment | Reconnecting with Scotland’s cyber community
Vanunu added: “We’re seeing people from all corners of the world organising themselves and resources to support either Russia or Ukraine. Some groups are coordinating cyberattacks to target Russia. Other groups are serving as information and news hubs to report a raw side of the war.
“Other groups are requesting funds to either support Ukraine or commit fraud. All in all, we’ve seen a six-fold surge in Telegram groups themed on the Russia-Ukraine war the day Russia invaded Ukraine. I strongly recommend people to watch their Telegram activity closely and the types of people you may come in contact with.
“There’s a side on Telegram looking to take advantage of supporters of either Ukraine or Russia.”
Cyber Safety Tips for Telegram Users
- Don’t press random links. Don’t press on links that have origins unfamiliar to you, especially in times of crisis and extreme circumstances. Criminals might leverage and exploit the situation to try steal credentials, private details and other personal information by sending out malware or phishing links
- Beware of suspicious requests. If a message from an unknown source makes a request or a demand that seems unusual or suspicious, this might be evidence that it is part of a phishing attack.
- Think twice before sending money. Sending money to unknown sources requesting assistance may often result in fraud. Beware with whom you are communicating and what kind of information you are being asked to provide. Social media messages are not the platform for large financial transactions, especially to unrecognised sources.
- Verify your sources. Consume news feeds and seek “truth” from reliable sources that you can trust.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





