A listing posted on 8 September 2026 offers “120 million” Telegram records for download. Ransomnews obtained the 3.7 GB file and counted every row. It holds 63,099,746, not 120 million. Three quarters are Iranian phone numbers whose Telegram account IDs date them to before 2020, and the seller left a column in the file naming the separate leaks it was built from.
This is not a breach of Telegram. Telegram’s systems were not touched. It is a compilation of at least a dozen older datasets, merged badly enough that the file contradicts itself in 883,230 places, and sold under a headline number roughly double its real size.
How many records are actually in the file?
63,099,746 rows. Of those, 63,096,265 are well-formed and 3,481 have a broken field count. The advertised figure of 120 million overstates the file by a factor of 1.9.
What makes that look deliberate rather than careless is the seller’s own arithmetic. The listing includes a country-by-country breakdown running to 239 entries. Those numbers sum to 63,075,061, within 0.04% of the file’s real contents. His table is accurate. Only the headline is not.

The concentration is the next surprise. Iran accounts for 46,721,738 rows and Russia for 14,599,270. Together they are 97.2% of the entire dataset. Every other country on that 239-entry list, the United States, Germany, the United Kingdom, India, Brazil, shares the remaining 2.8% between them. The United States contributes 29,902 rows, which is 0.05% of the file.
Is this a breach of Telegram?
No, and the seller accidentally proves it himself. The last column of every row is labelled sources, and it is a merge log he forgot to strip before packaging the file.
Each record carries the provenance tags of the files it came from: idphone, d3|d5, d3|d4|d5, clean1|clean2|clean5|d1. There are 398 distinct source combinations in the file, built from around twelve separate inputs. A single export from a single system does not have twelve provenance tags.

The file is also physically block-ordered. Sampling it at 0%, 20%, 40%, 60% and 80% of its length lands in different source tags and different countries each time. It is a concatenation, not an export.
The three largest blocks account for 95% of the file: idphone at 27,052,868 rows, d3|d5 at 23,087,594, and d3|d4|d5 at 10,073,557. Cross-referencing those blocks against the country column shows the shape of the acquisition. The Iranian data arrived in two batches, 25,650,424 rows tagged idphone and 21,017,763 tagged d3|d5. The Russian data came mostly as d3|d4|d5, 9,893,061 rows.
How old is the data?
Most of it predates 2020, and the account IDs prove it. Telegram assigns user IDs in roughly sequential order, so the magnitude of an ID is a proxy for when the account was registered. Telegram’s own API documentation puts the current user ID space at 1 to 0xffffffffff, and the platform only moved to 64-bit IDs at API layer 133, which was communicated to developers in December 2021.
Splitting the two dominant blocks by ID magnitude gives two completely different pictures.
| Account ID range | Iran (46,721,738 rows) | Russia (14,599,270 rows) |
|---|---|---|
| Above 1 billion | 13,009 (0.03%) | 1,469,806 (10.1%) |
| Above 2 billion | 431 (0.0009%) | 189,845 (1.3%) |
| Above 5 billion | 187 (0.0004%) | 147,129 (1.0%) |
99.97% of the Iranian records sit below an account ID of 1 billion. The Russian block has a genuine modern tail, with a million and a half accounts above that line and 147,129 above 5 billion. The Iranian block has 187. It contains essentially no account created in the past five years.
That population has an obvious candidate. In March 2020, roughly 42 million records belonging to Iranian Telegram users were left exposed on an unsecured Elasticsearch cluster for about eleven days. The data did not come from Telegram but from unofficial Iranian forks of the app, Hotgram and Talagram, which existed because the official client had been blocked in Iran since December 2017. A Telegram spokesperson said at the time that the data “seems to have originated from third-party forks extracting user contacts”.
Same country, same era, same fields of account ID and phone number. Ransomnews cannot diff this file against the 2020 dataset without a copy of the original, so we are not calling it a confirmed match. The evidence is strongly consistent, and nothing in the file suggests a newer Iranian source.
What is actually in each record?
Far less than the listing promises. The advertised field list runs “phone, ID, first name, last name, etc”. Measured across the whole file:
- phone number: 100%
- account ID: 100%
- first name: 16,447,982 rows, 26.1%
- last name: 6,457,777 rows, 10.2%
- email address: 946,824 rows, 1.50%
- username: 223,667 rows, 0.35%
46,404,069 rows, 73.5% of the file, contain a phone number and a numeric ID and nothing else. No name, no username, no email. The single largest block is named idphone, which is what it holds.
The 0.35% username figure deserves attention on its own. A username is the one field a genuine Telegram-sourced dataset would be rich in, because it is public. In 63 million rows there are 223,667 of them.
Where did the email addresses come from?
Not from Telegram. Telegram does not hold an email address for an ordinary account. Email is used only as an optional recovery factor for two-step verification and is never exposed in user data, so a genuine Telegram export would contain none at all.
// Free tool
How does your own site score?
Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.
No signup. Nothing installed. We only request what your site already serves publicly.
The file has 946,824, and their domains say where they were sourced: mail.ru (384,203), gmail.com (253,239), yandex.ru (137,008), bk.ru (34,284), then list.ru, inbox.ru, rambler.ru, ukr.net and tut.by. There are also 27,500 addresses at a single niche Russian commercial domain, which is the signature of one site’s leaked user table being folded into the merge.
The split confirms it. Russian rows carry 711,781 of those emails, 4.9% of the Russian block. Iranian rows carry 6,250, or 0.013%. The email data was grafted on from Russian breach compilations and has almost nothing to do with the Iranian bulk of the file.
The file contradicts itself
The merge was done carelessly, and it is measurable.
There are 63,096,265 distinct phone numbers in 63,096,265 well-formed rows, so the file was deduplicated on phone. But there are only 62,213,035 distinct account IDs. That leaves 883,230 rows where one Telegram account ID is attached to more than one phone number, which cannot happen with real accounts. A Telegram ID belongs to exactly one account. That is a 1.4% self-contradiction rate baked into the product.
Beyond that, 3,481 rows have the wrong number of fields, and 16 carry an “account ID” above 10 trillion that is plainly a Russian mobile number shifted into the wrong column. Fragments of Russian CRM and chat data have bled into the sources column, including estate-agency messages and full names. Material that has nothing to do with Telegram was swept into the pile.
What is the actual risk?
Start with what the file cannot do. There are no passwords, no password hashes, no session keys, no two-factor secrets and no message content. Nobody’s Telegram account is compromised by this. The 2020 Elasticsearch exposure reportedly did include hashes and secret keys, so this is a reduced derivative that dropped them.
The real harm is deanonymisation, and it is concentrated in Iran. Every one of the 46.7 million Iranian entries is a mobile number: 46,709,417 of them fall in the 98 9xx mobile range, spread realistically across the operator allocations, with the 0912 block alone accounting for 4.8 million. Iranian SIM cards are registered against the holder’s national identity number. Irancell instructs subscribers to text their national ID to 3000150 to list every SIM registered in their name.
So in Iran a phone number is a strong pointer to a legally identified person, and this file adds the second half of the sentence: that person had a Telegram account. If the Iranian records did come from the fork apps, the list is narrower and more sensitive still, because it describes people who installed a workaround to reach an app the state had blocked.
Age does not defuse this. Phone numbers are long-lived, and numbers tied to a national identity record especially so. A 2020 mapping between a phone number and a messaging account is still largely valid in 2026. Being old makes the data less newsworthy, not less dangerous, which is the honest reason stale compilations still find buyers.
The fraud-grade portion is small. Only 946,822 rows carry an email address alongside a first name, and 499,988 carry an email with both first and last name. Those are the records usable for credential stuffing, account-recovery attacks and convincing phishing, and they are overwhelmingly Russian. For the 46.7 million Iranians in the file, there are 6,250 email addresses in total.
The genuinely new exposure here is not the Iranian data, which has been circulating for six years. It is the merge itself: roughly 950,000 people whose email address and name now sit in the same row as a Telegram account identifier, where previously those facts lived in separate leaks.
What should you do?
If you are an Iranian Telegram user who was active before 2020, assume your phone number and account ID are public and have been for years. Nothing in this file lets anyone into your account, but the association between your number and Telegram should be treated as known.
- Turn on two-step verification in Telegram. Settings, Privacy and Security, Two-Step Verification. A phone number and an account ID are the two things an attacker needs to start a SIM-swap or SMS-interception attempt, and a login password defeats both.
- Restrict who can find you by phone number. Settings, Privacy and Security, Phone Number. Set “Who can find me by my number” to “My Contacts”.
- Treat any SMS or Telegram message quoting your name or number as hostile until proven otherwise. A targeting list is exactly what this file is good for.
- If you are in the roughly 950,000 with an email in the file, change any password reused between that address and other services, and check your exposure with a tool like our Stealercheck.
- Longer-term hardening is covered in our 2026 privacy stack tutorial.
How we verified this
Ransomnews analysed the file offline, on an isolated machine. We did not query Telegram, resolve any account, contact any number or test any record against a live service. Every figure in this article comes from parsing the file itself.
The work was: a full-file row count and field-integrity pass; frequency analysis of the sources column; per-country fill rates for every field; account ID distribution by country and by source block; uniqueness testing on phone numbers and account IDs; and email domain analysis. The sample image above is masked. We publish no phone numbers, no account IDs, no names, no email addresses, no seller identity, no forum name and no download link.

This is the same method our breach verification desk applies to every dataset we are sent, whether it turns out real, as with the Condé Nast database sale, or mislabelled, as with the ticketing data sold as a Ticketmaster breach. Live leak-site activity is tracked on Ransomtracker.
What this means for anyone reading leak headlines
Record counts in listings are marketing, not measurement. A seller with 63 million rows titled his post 120 million, then published a country table that gave the real number away. Nobody had to break anything to catch it. Somebody just had to count.
The pattern is common enough to be worth naming. Old leaks get merged, renamed after a bigger brand than the one they came from, and re-sold. The brand in the title is the marketing; the provenance is in the data. In this case it was in a column the seller left behind.
Frequently asked questions
Was Telegram hacked?
No. Telegram’s systems were not breached. The file is a compilation of older datasets from other sources, including what appears to be a 2020 leak from unofficial Iranian Telegram forks, merged with Russian breach data.
Are there really 120 million Telegram records?
No. The file contains 63,099,746 rows. The seller’s own country-by-country breakdown sums to 63,075,061, which matches the file to within 0.04%, so the accurate number was available in his own listing.
Are Telegram passwords in this leak?
No. The file contains no passwords, no password hashes, no session keys, no two-factor secrets and no message content. It cannot be used to log into an account.
Who is affected by the Telegram data leak?
Overwhelmingly Iranian and Russian users. Iran accounts for 46,721,738 rows and Russia for 14,599,270, together 97.2% of the dataset. The United States contributes 29,902 rows and the United Kingdom 5,224.
How old is the data in the Telegram leak?
Most of it predates 2020. Telegram assigns account IDs sequentially, and 99.97% of the Iranian records have an ID below 1 billion, meaning the accounts were registered years ago. The Russian portion contains a smaller but genuine tail of recent accounts.
Is old leaked data still dangerous?
Yes. Phone numbers change slowly, and in Iran they are registered against a national identity number, so a six-year-old mapping between a number and a Telegram account is still largely accurate. The data is less newsworthy than it looks and more durable than people assume.
How can I protect my Telegram account?
Enable Two-Step Verification under Settings, Privacy and Security, which blocks SIM-swap and SMS-interception takeovers. Then set “Who can find me by my number” to “My Contacts” in the same menu.
Sources and further reading
- Telegram API documentation, user and dialog ID ranges
- Comparitech, 42 million Iranian Telegram user IDs and phone numbers exposed (March 2020)
- Decrypt, Telegram fork leaks data of 42 million users
- Irancell, checking SIM cards registered to your national ID
- Ransomnews breach verification desk
- Stealer logs explained: what they hold and how to check yours
Ransomnews holds no copy of this data beyond what was required for analysis, and publishes no personal data from it. Corrections and questions about individual records go to [email protected]. More about the people behind this work on our editorial team page.
The Ransomnews Monthly
One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.
Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.
