Telegram Founder Pavel Durov Reveals AI Exploits and Extortion Scheme Behind Recent App Store RemovalFollowing the brief removal of Telegram from Apple’s global App Store over Child Sexual Abuse Material (CSAM) violations, founder Pavel Durov has issued a public statement addressing the root cause of the incident and exposing a sophisticated extortion scheme targeting major platforms.
While Telegram resolved the violation and restored the app within a few hours, Durov explained that bad actors had discovered a novel exploitation vector using artificial intelligence. According to Durov, malicious actors used automated AI tools to quietly edit legacy messages deep within historical chat archives. By altering older posts, the illicit content remained hidden from active group members, preventing standard community flags and user reports from triggering.
Once the modified content was embedded, the perpetrators attempted to extort money from Telegram under threat of exposure. When Telegram refused to comply, the actors immediately reported the targeted links directly to Apple. Because Apple's compliance enforcement acts swiftly on such reports, Telegram was temporarily delisted before the company was even given prior notification by Apple causing significant operational and reputational friction.
Durov noted that Apple’s automated enforcement mechanism unintentionally played into the hands of the extortionists. However, he confirmed that Telegram has since developed advanced counter-measures to handle similar AI-driven manipulation and warned other tech platforms that they may soon face identical extortion tactics.
The way malicious actors have shifted from posting new illegal content to modifying past information is evident. Many messaging platforms allow users to edit old messages without notifying chat participants again. By using AI scripts to automate and mask these edits in high-volume public channels, attackers deliberately circumvent traditional keyword filters and user reporting cycles, turning past database entries into hidden compliance vulnerabilities.
Durov's comments highlight how stringent third-party enforcement rules, such as Apple's App Store's security guidelines that don't condone any wrongdoing, can be weaponized by extortionists. By acting first and asking for clarification later, extortionists gain significant leverage over app developers. By bypassing developers and reporting directly to the marketplace owner, attackers force immediate app removals, creating artificial bargaining power for ransom.
To counter these strategies, platforms like Telegram must move beyond instant user notifications. Future content validation architectures will need to incorporate encrypted change tracking for message edits, automated deep data warehouse scanning, and AI-powered predictive principles that examine past message updates to detect sudden changes in security scores, closing vulnerabilities before external regulators intervene.
Source: Pavel Durov
Telegram Founder Pavel Durov Reveals AI Exploits and Extortion Scheme Behind Recent App Store RemovalFollowing the brief removal of Telegram from Apple’s global App Store over Child Sexual Abuse Material (CSAM) violations, founder Pavel Durov has issued a public statement addressing the root cause of the incident and exposing a sophisticated extortion scheme targeting major platforms.
While Telegram resolved the violation and restored the app within a few hours, Durov explained that bad actors had discovered a novel exploitation vector using artificial intelligence. According to Durov, malicious actors used automated AI tools to quietly edit legacy messages deep within historical chat archives. By altering older posts, the illicit content remained hidden from active group members, preventing standard community flags and user reports from triggering.
Once the modified content was embedded, the perpetrators attempted to extort money from Telegram under threat of exposure. When Telegram refused to comply, the actors immediately reported the targeted links directly to Apple. Because Apple's compliance enforcement acts swiftly on such reports, Telegram was temporarily delisted before the company was even given prior notification by Apple causing significant operational and reputational friction.
Durov noted that Apple’s automated enforcement mechanism unintentionally played into the hands of the extortionists. However, he confirmed that Telegram has since developed advanced counter-measures to handle similar AI-driven manipulation and warned other tech platforms that they may soon face identical extortion tactics.
The way malicious actors have shifted from posting new illegal content to modifying past information is evident. Many messaging platforms allow users to edit old messages without notifying chat participants again. By using AI scripts to automate and mask these edits in high-volume public channels, attackers deliberately circumvent traditional keyword filters and user reporting cycles, turning past database entries into hidden compliance vulnerabilities.
Durov's comments highlight how stringent third-party enforcement rules, such as Apple's App Store's security guidelines that don't condone any wrongdoing, can be weaponized by extortionists. By acting first and asking for clarification later, extortionists gain significant leverage over app developers. By bypassing developers and reporting directly to the marketplace owner, attackers force immediate app removals, creating artificial bargaining power for ransom.
To counter these strategies, platforms like Telegram must move beyond instant user notifications. Future content validation architectures will need to incorporate encrypted change tracking for message edits, automated deep data warehouse scanning, and AI-powered predictive principles that examine past message updates to detect sudden changes in security scores, closing vulnerabilities before external regulators intervene.
Source: Pavel Durov
Comments
Post a Comment