Instant messaging: iMessage, Facebook, Instagram messenger and the big lie of Telegram

Image depicting Telegram's collaboration with the Russian government.

Telegram

Remember when Pavel Durov, the “rebel” founder of Telegram, fled Russia in 2014 “persecuted” for refusing to hand over user data to the Russian government?

An epic narrative that sold the app as a bastion of privacy in the face of oppressive governments.

Today, with some 900 million users, Telegram is one of the favorite alternatives to WhatsApp? along with Signal, but leaked documents and forensic analysis reveal that this battle against the Russian government was pure theater.

While you think you are using secret chats (which almost nobody activates) because let’s remember that Telegram does not encrypt messages by default -you have to activate it manually-, governments like Russia access millions of unencrypted messages from this app; and meanwhile, your profile is an asset for them in the shadows.

Not to mention other uses such as cybercriminals using it to control malware from their Telegram bots.

Yes, as you can see, today I’m not going to speak very well of Telegram, although I must admit that it has highly recommended news channels and discussion forums that cover specialized information of each niche; in fact, here you have the one of our blog: https://t.me/josecurityChannel

Let’s start with the Big Lie of the “Heroic Exile”.

The official story is known: Pavel Durov stood up to the Kremlin, refused to collaborate, sold his company VKontakte (the “Russian Facebook”), and ran away to create “censorship-free” Telegram.

Formidable, a perfect script worthy of Netflix.

But recent research such as iStories (June 2025) shows something disturbing: Telegram always maintained privileged channels with the FSB (Russian secret service).

According to internal documents, Russian authorities receive priority access to user data without a court order, contradicting the image of “defender of freedom”.

Why the setup? Simple: so that the West trusts the app. Something similar to what I commented in a previous article, but on that occasion from the U.S. government and Signal.

While Russia labeled Telegram a “threat,” it quietly used it as a tool for mass espionage. A game of double identity more elaborate than a fake profile on Tinder.

And what about Telegram encryption, well, the same thing: The Green Padlock Trick that very few know about and use.

Here’s the first risk of this app: πŸ”’ End-to-end encryption (E2EE) is NOT default in Telegram. It only exists in “secret chats”, which you must manually enable (and they appear with a green padlock).

The vast majority of users never use them. Your group conversations, public channels and normal 1-on-1 chats are stored on Telegram servers with client-server encryption.

The problem? The decryption keys are controlled by the company, not you.

“Telegram’s architecture allows governments to access data with a simple informal request” - Denis Ivanov, cybersecurity researcher at RYS.io.

As I mentioned at the beginning, Telegram is also exploited by cybercriminals because it allows them to create bots that automate tasks.

However, in my opinion, the fault does not lie with the application, but with the improper uses that some people make of it. Instead of criticizing the tool for this, the right thing to do is to take action against those who use it illegally.

The truth is that these bots are a marvel for automating tasks… and also the wet dream of cybercriminals.

Using Telegram’s open API this is used for:

  • Create Command and Control Centers: campaigns such as ToxicEye (Check Point, 2021) use Telegram bots to leak files and take remote control of infected computers or BlackGuard, stealing passwords and files.
  • Massive credential theft: info-stealer logs exchanged in clandestine channels included millions of email addresses
  • They notify in real time when a victim falls for phishing (“Alert! Someone entered data on your fake PayPal page”).
  • They exfiltrate sensitive data from companies (documents, credentials) directly to Telegram chats, as companies do not usually block Telegram applications in case their workers use it.
  • Dissemination of personal data: such as the case this week in which in a Telegram channel “Alvise PΓ©rez Chat " -linked to the MEP and leader of the political party *Se AcabΓ³ la Fiesta-*a user published telephone numbers, IDs, addresses and emails of seven socialist ministers (PSOE) and several former ministers of the Popular Party (PP).

The irony is that Telegram promotes its bots as “innovative” tools, and the reality is that they are, but it does not verify their security and so anyone can use them for different purposes.

And here comes to hair the example of the ham knife: excellent tool to cut ham, but also to cut someone’s neck πŸ”ͺ (and not for this reason we will ban the sale of these knives so useful for Spaniards who eat that delicious acorn-fed Iberian ham).

For me, one of the most interesting features of Telegram is that it allows you to hide your phone number behind an “@nickname”. This is especially useful for flirting on Tinder without giving out your phone number to any match at the drop of a hat.

But if you think that protects your identity from governments or hackers, forget it:

  • Metadata: Telegram stores your IP, devices used, contacts and connection times. With that, an intelligence service perfectly identifies live patterns. In addition, whoever has access to the routers can correlate the auth_key_id accompanying each packet of your MTProto encryption protocol to infer the approximate location of the device.
  • Public groups = data mine: Do you enter political or activist channels? Your profile is linked to “sensitive” topics even if you don’t write anything. I’m certainly on file in all the hacker and cybersecurity forums, I wouldn’t run away!
  • And the recent 2025 bombshell: leaked FSB documents show them cross-referencing Telegram data with facial surveillance on public transport to identify dissidents.

On the other hand, Telegram also boast a self-destruct feature…. Which doesn’t destroy that much!

Telegram deletes inactive accounts after 1 year - sounds good? Yes, but there’s a catch:

  • Messages you sent to others are NOT deleted. If you wrote something compromising to a contact, it will still be in their their chat even if you delete your account.
  • Hidden backups: Forensic evidence suggests that some servers keep “technical” copies for up to 5 years… accessible under “exceptional legal requirements”.

As I always say, in peacetime, this mass collection seems “harmless”. But in conflicts (like the Ukraine-Russia war), Telegram becomes a geopolitical weapon:

  • Real example (2023): Ukrainians used Telegram channels to coordinate resistance. Months later, Russian missiles hit premises right where those groups physically gathered. Coincidence? Ukrainian intelligence services accuse Telegram of leaking locations via metadata.
  • Another fact: 70% of the war propaganda channels are broadcast via Telegram…. because it allows apparent anonymity for the operators.

And as I say, in times of war, everyone shuts down social media and instant messaging applications that are unreliable for their interests, as happened recently when Iranian authorities urged citizens to uninstall WhatsApp.

In conclusion, Telegram is not the “anti-system” app that Durov sold us.

It is a giant with servers in Dubai (a country without strict privacy laws), which collaborates with governments while pretending to confront them, and whose technical design prioritizes convenience over real security.

Using it thinking it’s “safe” is like believing that a person with an eye twitch is winking at you out of love πŸ˜‰.

The reflection is always the same: If something is free (like Telegram), you are the product.

But here the price is not seeing ads… it’s that your digital life can be used by secret services, criminals or both.

Let’s take a quick look at other alternatives…

If you are looking for real privacy, consider Threema, Session or Wire.

  • Threema (Switzerland)

  • End-to-end encryption by default.

  • No phone number is required; the public key is generated locally.

  • GDPR compliant.

  • Session (Project Loki, Australia)

  • Based on a decentralized onion network that hides metadata.

  • Random 66-character identifiers; no mobile links.

  • Open source and public security audits.

  • Wire (Germany/Switzerland)

  • Legal transparency and Axolotl encryption by default in chats and calls.

  • Enterprise business model (does not rely on ads or data mining).

  • Periodic audits and full compliance with European regulations.

SMSSMS*(Short Message Service*) text messages were the pioneers of mobile communication. They started with very basic functions and soon evolved into MMS*(Multimedia Messaging Service*), which allowed images, audio or video to be added to a larger message.

Today they are rarely used between individuals, but are still valuable in environments with limited coverage.

While instant messaging platforms require at least a 3G connection, an SMS can be sent over 2G, which is crucial during natural disasters, in rural areas or when traveling abroad without data.

Nowadays, companies are the main users of SMS: they send appointment reminders, verification codes and, increasingly, advertisements. Some even hide the sender’s number to prevent unsubscription or blocking, a practice that borders on illegality.

In security, SMS has fallen out of favor as a second authentication factor**(MFA**, Multi-Factor Authentication). SIM swapping (SIM card duplication) and signal interception make them vulnerable.

Variable code applications (e.g. Authenticator) or FIDO2 (Fast IDentity Online 2) physical keys are recommended today.

In addition, smishing - a variant of SMS phishing - is still on the rise: cybercriminals send shortened links that redirect to fraudulent websites to steal credentials or install malware. It is essential to remain vigilant, check the real URL and be wary of alarmist messages.

As of February 2025 the Order TDF/149/2025 reinforces in Spain the blocking of senders who hide or manipulate the calling line identifier, makes it more difficult to send unauthorized promotional SMS and obliges operators to filter false numbers.

**Practical suggestion ** Activate the Robinson List to reduce unsolicited marketing and check if your operator offers free anti-spam filters.

Finally, it is worth knowing about RCS*(Rich Communication Services*), a standard that combines the best of SMS with modern features (read confirmations, sending files, optional encryption). Its adoption will grow in 2025 when Apple adds official support to iOS 18, narrowing the gap between iPhone and Android users.

iMessage

On Apple devices, iMessage encrypts end-to-end**(E2EE**) conversations between iOS, iPadOS or macOS users.

When the recipient does not use these systems, the message is sent as SMS/MMS -without encryption-, with the aforementioned risks.

Until the end of 2022 iCloud backups were not encrypted. With Advanced Data Protection, available globally from January 2023, the user can activate the encryption of copies, photos and messages, and do not forget to write down the recovery key.

Facebook Messenger and Instagram

When we install Facebook Messenger or Instagram on our mobile, we grant permissions that allow them to collect metadata - device model, approximate location, usage habits - which Meta then uses in its advertising machine. Using the web versions reduces that access.

Meta uses its applications to spy on you in depth, as you can read here.

Since December 2023 Meta has been deploying E2EE encryption by default in chats, but the company continues to collect metadata (connection time, frequent contacts, IP address). In addition, encryption for groups remains optional.

It is therefore advisable to carefully review the privacy settings of these applications: disable the “Online” status, disable contact synchronization and disallow unnecessary permissions (microphone, camera or permanent location).

Recommendations:

πŸ” And now… What do you think?

Are you still using Telegram as if it were a fortress? Did you know about the Durov vs Russia theater?