Your identity can be traced down on Telegram, even with a locked-down profile
The Youth Affairs Ministry of Karachay-Cherkessia plans to spend 550,000 rubles (about $7,315) on the “Insider” system. This system searches and monitors Telegram posts and can also match Telegram IDs to phone numbers from leaked databases — in other words, unmask users.
The most interesting part of this tender: the contractor must check whether more than 300,000 phone numbers (supplied by the ministry itself) are registered on Telegram. Regional authorities have never admitted so openly before that they already hold a database of phone numbers and are willing to share it with an outside contractor for deanonymization purposes.
The contract is already being prepared for signing. Everything points to “Insider” going live in Karachay-Cherkessia. Similar procurements happen regularly across Russia. Below is a list of known cases we found.
Russian security agencies already use the “Insider” system for deanonymization and, as a result, to prosecute Russians with anti-war views. Meduza reported that police departments in three Russian regions signed government contracts to buy a system for unmasking Telegram users. In December 2023, security agencies used such a deanonymization bot to identify a user who was later fined under the “discrediting the army” law over a comment. The court accepted a screenshot from the bot linking the phone number to the account as one of its arguments.
The origin of “Insider” and its buyers
The developer of “Insider” and of “Demon Laplace” (a social media monitoring system that “Insider” is usually sold together with) is Evgeny Venediktov, a former TV journalist who worked at NTV company. He now heads the nonprofit “Center for Research on Legitimacy and Political Protest.”
Venediktov and his “Demon Laplace” have been known since 2015, when the project was framed as volunteer monitoring of social media for extremism. The project passed its findings to the police and prosecutors, though Venediktov publicly denied selling the software to security agencies. His company received its first government contract at the end of 2017 — a license for the Novgorod regional government worth 1 million rubles (about $13,300). The number of this contract was No. 0150200000617000892-0749066-01, dated December 13, 2017, completed December 25, 2017. From 2018, now registered as a sole proprietor, Venediktov began winning contracts regularly, including with universities (for example, a contract with Yaroslavl State University) and with the police. “Demon Laplace” has been listed in Russia’s official register of domestic software since October 2022. The “Insider” module appeared later than the main program. Venediktov unveiled it in August 2022 in a video on his YouTube channel, and the first sales with this module happened in March 2023.
In 2019, Venediktov, according to an investigation by IStories (“Important Stories”), helped journalists identify the administrator of the anonymous channel “Comrade Major,” who had published data on participants in protest actions. Today the product is officially sold through Venediktov’s sole proprietorship. A product description is available on the developer’s website and in a software product catalog. Access, however, is limited to government bodies only.
Systems like this aren’t limited to Telegram. According to the developer’s own description, “Demon Laplace” (the suite that “Insider” is sold as part of) collects data from VKontakte and Telegram. An investigation by Sem’ na Sem’ (“Seven by Seven”, a Russian independent media), based on that same description, found that it also tracked Facebook, Instagram, X, Odnoklassniki, and LiveJournal. The Karachay-Cherkessia tender’s technical specifications describe functions specifically for Telegram, but that’s just one module in a system built by design to cover the whole range of popular platforms.
“Insider” is far from the only tool of this kind. There’s also “Okhotnik” (“Hunter”), a system developed by the St. Petersburg company T.Hunter. The system is now owned by the Avtomatika concern, which is part of the Rostec governmental corporation.
Unlike “Insider,” which mainly works by matching a phone number to an ID against pre-collected databases, “Okhotnik” hunts down a person’s digital footprint on its own, without a ready-made database. It analyzes data from dozens of sources in real time. AI processes data from social networks, forums, messengers, classified-ad sites, cryptocurrency blockchains, and even the dark net, while security agencies provide access to their own databases on their end. In other words, “Insider” is essentially a database plus a search engine, and “Okhotnik” is an AI system that independently traces the digital footprint of a specific anonymous channel across dozens of sources simultaneously. The Bell (another independent Russian media) refers to sources which are familiar with how the system works: they say that the number of databases feeding into “Okhotnik” exceeds 700 (the company itself has claimed over 300 sources on its website). Starting in 2026, Rostec plans to supply “Okhotnik” to police and FSB units across the country.
There are also doxxing bots built on leaked databases. The best known, “Eye of God,” stopped operating after searches of its team in February 2025. Userbox took its place, but its owner was also detained on October 31, 2025, and that bot stopped responding too. “Khimera” is still alive today, though according to journalist Andrei Zakharov, after the crackdowns began, it relocated its staff out of Russia and revoked free access for law enforcement. Technically, the principle is the same as with government-run services: matching leaked data to identifiers.
In late 2024 there appeared Article 272.1 of the Russian Criminal Code on “illegal handling of personal data,” punishable by up to 10 years in prison. Under this article the cases against the admins of doxxing bots have been investigated. According to Novaya Gazeta Europe, one of these aggregator bots (unnamed) recently started charging security officials for hiding their own personal data from search results.
Regional police departments actively purchase these government systems, for example, in Chechnya, Amur Region, and Kamchatka. “Insider” and similar services are also used by the governments of Pskov, Oryol, and Belgorod regions, by the Kuban Center for Civic Education of Youth, and by Yakutia’s procurement center.
People can be found through their Telegram IDs
Every Telegram account has a numeric identifier (ID). It is entirely independent of your phone number or username, and it never changes. You can hide your number in privacy settings, and you can delete your username too, but the ID is always there. You can see it in the link to your profile in the web version of the messenger, or retrieve it through a bot.
Does it require any hacker trick or a Telegram breach? No. When you sign up for Telegram, the messenger assigns your account a number (the ID). This number is visible in the app, for example in the link to your profile. That’s how every messenger works. The server needs something to distinguish one account from another. So every profile has an ID that is visible by default. “Insider” doesn’t hack Telegram. Instead, it takes this public identifier and cross-references it against a database of other people’s leaked data. Imagine that you had a card catalog of phone numbers and a separate card catalog of names: you only need to match one against the other using a shared field.
Once the ID is known, the rest is easy. The system cross-references it against a vast collection of leaked phone number databases. According to investigative journalist Andrey Zakharov, “Insider’s” database holds more than 76 million such records. If there’s a match, “Insider” pulls in all the other information that has ever leaked alongside that phone number: name, addresses, workplace, email, and sometimes even links to other people.
According to IStories, “Insider’s” database includes leaked data from Yandex Food (Yandex Eda), Wildberries, Sportmaster, SberSpasibo, the Moscow Electronic School, and other services. Your phone number could have surfaced through a food delivery order, a marketplace purchase, or a supermarket loyalty program — and from there it simply sits in the same database as your Telegram ID.
Within Telegram, these systems have a much broader feature set than just deanonymization by phone number. Based on the public tender documents from Karachay-Cherkessia, the standard set of modules in such a system includes:
- keyword monitoring of channels and chats,
- exporting message history (including messages from closed channels and chats without any public links),
- searching a username across several hundred external internet sources simultaneously (an account can be linked to profiles on other social networks),
- generating instant alerts whenever a target word appears,
- retrieving a phone number for a given account via a dedicated module.
Telegram itself doesn’t leak your data. You leave the digital footprint yourself. Many people still mistakenly consider Telegram a private messenger. The privacy of a closed group protects you from outsiders who aren’t in the chat, but it doesn’t protect you from a chat member who wants to export the entire message history. Nor does it protect you from a moderator bot whose developer was handed admin rights by the chat’s owner without a second thought. Even if you personally have never posted your phone number and have deleted your username, your ID (visible in any public activity you have in the group) is enough for a deanonymization system.
A link is just as dangerous as a phone number
When matching against a database doesn’t work, systems like this have a fallback: send the user a message with a link and see what happens when they click it. Here it’s worth distinguishing between two mechanisms.
- The first is a narrow, Telegram-specific vulnerability: a malicious proxy link makes the app silently contact an attacker’s server in the background. This exposes the IP address and the exact connection time, but nothing more. The browser isn’t involved at all. In January 2026, the discovery was first described in the Chekist42 Telegram channel, then confirmed by independent researchers going by GangExposed_RU and 0x6rss. On January 12, the specialized outlet BleepingComputer reported on it. Telegram subsequently confirmed the vulnerability and promised to add warnings before opening such links. Importantly, this vulnerability works even with a VPN or SOCKS5 proxy turned on, because the app contacts the attacker’s server before the traffic ever enters the encrypted tunnel.
- Second, a broader and older technique is an ordinary link that opens in a browser. There, the server gets not just the IP address but data from the request itself (operating system, browser), and if the page contains code, also screen resolution, language, and time zone. If the link opens in a browser and the page has a WebRTC script, the browser can expose the real IP address despite an active VPN: WebRTC establishes a connection through a separate channel that many VPNs don’t intercept. You can check for this leak at browserleaks.com/webrtc. We cover how to disable WebRTC in the “Recommendations” section below.
If you want to verify this yourself without putting anyone else at risk: the free service canarytokens.org generates a test link specifically for self-checks. Send it to yourself on Telegram and open it from another device. The notification that arrives in your email will show exactly what an attacker would see.
Clicking a link from Telegram is already a risk, even if you don’t download anything or enter a password. A single click is enough for a remote server to get your IP address, and if it’s a regular web link, a fairly precise picture of your city, device, and browser too. And the link doesn’t have to come from a stranger. A friend’s account can be compromised or temporarily hijacked, with the message sent without their knowledge. The rule “I’m not downloading anything, so it’s safe” doesn’t hold.
Recommendations
For bot and service developers
- Don’t store or log users’ phone numbers any longer than the service itself actually needs them. Every extra database is a potential leak that will end up feeding a deanonymization system.
- If your bot or service displays users’ Telegram IDs openly to any chat member or third party, stop doing that. Publicly displaying an ID (and, where possible, a real username) is rarely functionally necessary and creates an unnecessary point of exposure for deanonymization. A separate question is how the ID is stored inside the system, if it isn’t exposed externally at all. Don’t write IDs to log files or a database unless a function actually needs it. Keep them only in memory and only for the duration of the sessions. If you do need to store an ID, keep the record’s lifespan to a minimum and purge it on a schedule rather than leaving it indefinitely. If your service sends user data to external systems (for example, a CRM or analytics platform, via an automatic notification on every action), don’t send the raw Telegram ID if the recipient doesn’t specifically need it. Use your own internal technical identifier instead, a separate one for each external partner. Limit who on your team can access the table with IDs, and log those accesses. If the ID does end up in a database, encrypt it on disk. Hashing the ID by itself doesn’t help much. An ID is just a number, and with a known range of possible values, a hash can be brute-forced. So, hashing is not a substitute for access control and retention limits, only a supplement to them.
For chat admins and moderators
- Telegram doesn’t let you ban just link-sharing for chat members — you can only block all messages from them. The easiest way to moderate messages is through a trusted bot. But there’s a catch. We found working open-source solutions. TG-Spam is the most mature: MIT license, actively maintained, deployable via Docker even on a low-powered server, with instructions for non-programmers. To guard against CAPTCHA bypassing when new members join, there’s a separate open-source bot, teknologi-umum/captcha. Both need to be self-hosted on your own server. There’s still no ready-made cloud service built on them that you can trust by default.
- Even a group’s privacy settings don’t protect against message history being exported via the API by bots if a compromised account ends up among the members. Remind the people in your chats about this often.