Someone Planted Fake Illegal Content in Telegram to Get It Kicked Off the App Store, Says Its CEO

Telegram founder Pavel Durov says the messaging app's brief removal from Apple's App Store was caused by an extortionist who secretly planted AI-modified illegal content inside a Telegram group chat and then flooded Apple with automated reports demanding payment. Durov laid out the allegations in a post on his X account Engadget.
Here is how the scheme reportedly worked. Telegram, like many chat apps, lets users edit their own messages after sending them. The attacker went back and edited an old message already sitting in an active group chat so that it displayed illegal content. Because the change happened to an existing message, group members did not see it appear in their feed as something new, so they had no chance to notice it or report it through Telegram's built-in moderation tools.
The extortion plan depended on volume. Durov alleged the attacker planned to use a large number of automated accounts to report the planted content to Apple, creating enough flags to trigger Apple's App Store review process. The message to Telegram was effectively: pay up, or the reporting campaign continues. Durov did not say whether a specific ransom amount was demanded.
Durov also criticized Apple's handling of the situation. He said Apple removed Telegram from the App Store before contacting Telegram about the flagged content. That meant Telegram had no chance to investigate, remove the material, or respond before being delisted. Apple's review guidelines give the company broad authority to remove apps that host illegal content, and the usual process is to act on user reports or automated detection.
The trick here is that the attacker exploited a gap between two separate systems. Telegram's own moderation depends on community members seeing bad content and reporting it. Apple's App Store reporting depends on receiving complaints about apps. By planting content that Telegram's community would never see, then mass-reporting that same content to Apple, the attacker made it look like Telegram was failing to moderate illegal material, when in reality no one inside Telegram had been given a chance to catch it.
Durov said the incident creates "a potential systemic risk for every mobile app that hosts user-generated content." Coming from the CEO of a platform with over 900 million monthly active users, that claim extends well beyond Telegram. Any app that lets users post, edit, or share content, and that distributes through Apple's App Store or Google Play, faces a version of the same problem: someone who understands both the app's content features and the app store's reporting process can turn the gap between them into a weapon.
The broader concern is what this means for how app stores operate. Apple's decision to remove Telegram before reaching out suggests the company prioritizes quickly pulling flagged illegal content over coordinating with the app's developers first. That approach makes sense from a safety perspective, since no one wants illegal content to stay available. But it also means that anyone who can create the appearance of a violation, and generate enough reports, can use Apple's own enforcement system as a threat. For app developers, the takeaway is that depending on an app store for distribution carries its own kind of risk, one that has nothing to do with hacking or code vulnerabilities.
Durov's account is still just one side of the story. He has an obvious interest in framing the delisting as an external attack rather than a failure of Telegram's own moderation. Apple has not publicly confirmed or denied Durov's version of events. What is known for certain is that Telegram was briefly removed from the App Store, later restored, and that Durov has now described a method that is technically plausible and ties together content manipulation with app store reporting abuse.


