USENIX Security2026Top-tier venue
Stayin' Alive: How Global Stolen Data Markets Thrive on Telegram
Tina Marjanov, Taro Tsuchiya, Konstantinos Ioannidis, Jack Hughes, Nicolas Christin, Alice Hutchings
Abstract
Stolen data acts as a catalyst for many cybercriminal activities, such as spam campaigns, spear phishing, and identity theft. Studying online communities that serve stolen data helps combat those criminal activities. While anonymous marketplaces and forums have traditionally been the primary venue for stolen data, the chat-based messaging application Telegram has emerged as a popular alternative. Given Telegram's increased accessibility to the general public, it remains unclear how stolen data communities adapt their operations to this platform, circumvent moderation efforts, and create resilient communities. In this work, we characterize: i) where stolen data communities appear within Telegram's ecosystem, ii) what types of stolen data they offer, iii) where they operate from, and iv) how they evade detection. This paper offers four main contributions. First, we provide one of the largest longitudinal datasets of Telegram stolen data channels. Over one year, we manually curate 1,521 channels and collect 14 million messages and 3.6 million shared files. We show that the stolen data communities are largely disjoint from other communities on Telegram. Second, we categorize the types of stolen data with the aim of understanding the potential cybercrime they enable. Third, while existing literature focuses on English-speaking communities, we find that many channels operate in non-English languages and source stolen data from non-English markets. Fourth, those communities deploy various techniques to evade regulation. Notably, "gateway channels" that provide links to other stolen data channels play a crucial role in increasing longevity and growth rate. We conclude by providing implications not only for academic researchers but also for Telegram and law enforcement agencies across different jurisdictions seeking to monitor and moderate those activities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0979bf21-eadd-42f4-a4fb-b4541b8694e2Builds on9
- The Anatomy of a Cryptocurrency Pump-and-Dump SchemeJiahua Xu, Benjamin LivshitsUSENIX Security 2019 · 146 citations
- Catching Phishers By Their Bait: Investigating the Dutch Phishing Landscape through Phishing Kit DetectionHugo L. J. Bijmans, Tim M. Booij, Anneke Schwedersky, Aria Nedgabat et al.USENIX Security 2021 · 61 citations
- Impersonation-as-a-Service: Characterizing the Emerging Criminal Infrastructure for User Impersonation at ScaleMichele Campobasso, Luca AllodiCCS 2020 · 24 citations
- SoK: Digging into the Digital Underworld of Stolen Data MarketsTina Marjanov, Alice HutchingsS&P 2025
- DarkGram: A Large-Scale Analysis of Cybercriminal Activity Channels on TelegramSayak Saha Roy, Elham Pourabbas Vafa, Kobra Khanmohamaddi, Shirin NilizadehUSENIX Security 2025
Related papers
- Characterizing and Detecting Propaganda-Spreading Accounts on TelegramKlim Kireev, Yevhen Mykhno, Carmela Troncoso, Rebekah OverdorfUSENIX Security 2025
- The Conspiracy Money Machine: Uncovering Telegram's Conspiracy Channels and their Profit ModelVincenzo Imperati, Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini et al.USENIX Security 2025
- Doxing-as-a-Service: Demystifying the Chinese Online Doxing EcosystemYiran Gao, Pengcheng Xia, Liu Wang, Tianming Liu et al.WWW 2026
- Sending Out an SMS: Characterizing the Security of the SMS Ecosystem with Public GatewaysBradley Reaves, Nolen Scaife, Dave Tian, Logan Blue et al.S&P 2016 · 68 citations
- On SMS Phishing Tactics and InfrastructureAleksandr Nahapetyan, Sathvik Prasad, Kevin Childs, Adam Oest et al.S&P 2024 · 30 citations
