Cybercrime-related discussions monitored on Telegram accounted for 45% of activity across seven tracked categories from January through May 2026, up from 28% across all of 2025, according to research from NordLayer Intelligence.
The analysis tracked monthly post volumes across 86 dark web forums and 1,890 Telegram channels between January 2024 and May 2026. It measured Telegram’s proportion of posts in each category separately, then averaged those proportions. The figures represent discussion volume in monitored sources, not confirmed criminal activity, attacks or victims.
For enterprise security teams, the shift may make threat intelligence and credential-exposure monitoring more important across both traditional underground forums and mainstream messaging platforms. The report points to phishing, credential theft, account-takeover attempts, denial-of-service-for-hire activity and deepfake-enabled fraud as threats that can be scaled quickly by actors with limited technical expertise.
NordLayer Intelligence cybersecurity expert Vakaris Noreika attributed part of the change to law-enforcement disruption of major dark web forums. When a forum is seized, sellers and buyers can lose established reputations and must rebuild trust in new communities. Telegram can offer a lower-friction alternative because it does not require specialized dark web access or the same forum-based registration and reputation-building process.
“Each time a dark web forum gets taken down, it fragments the market,” Noreika said. “The threat actor community that used the forum then scatters across other smaller forums, where the once-trusted sellers enter as new, unverified users, and find it challenging to find new potential buyers.”
The report does not conclude that cybercriminal operations are moving entirely off the dark web. Noreika said higher-value transactions are still less likely to occur on Telegram, where the platform’s accessibility and potential cooperation with law enforcement may make it less suitable for activities requiring greater operational security. Established dark web forums also retain vetting and reputation systems that can be important for high-risk transactions.
Instead, the research suggests Telegram may be serving as an accessible venue for newer actors and lower-value activity, including advertisements for criminal services. That could increase the volume of opportunistic attacks that rely on readily available tools rather than advanced expertise.
The distinction matters for enterprise defenders. A growth in discussion volume does not directly establish growth in successful attacks, but it can signal where security teams may need broader visibility. Organizations that focus monitoring only on dark web forums could miss indicators of compromised credentials, brand impersonation or emerging phishing campaigns shared through Telegram channels.
The study’s stated limitations are material for decision makers. The reported share is based only on the sources NordLayer Intelligence monitored, while the pool changed as forums emerged, were shut down or were seized. It should therefore be read as an indicator of activity in that monitored set, rather than a measurement of all cybercrime discussion on either platform.
The report recommends basic defensive measures, including unique passwords, multi-factor authentication, timely software patching and limiting publicly available personal information that could support social-engineering or deepfake schemes. It also recommends prompt action when credentials or sensitive information are exposed, such as changing passwords and revoking access from affected accounts.
NordLayer Intelligence noted that its findings are limited to the sources it monitors. Changes in the source pool—including forums that were shut down or newly identified—also affect year-over-year comparisons.

