Investigation: Russian network engineer Viktor Vedeneev controls thousands of Telegram IP addresses and maintains its servers; his companies have FSB links
INVESTIGATION — The technical infrastructure that underpins Telegram is controlled by a man whose companies have collaborated with Russian intelligence services. Bluesky: @kevincollier , @mikeeckel , @scoiattolo.mountainherder.xyz , and @mxbernhard Mastodon: @jwildeboer@social … , @rysiek@mstdn.social , and @josemurilo@mato.social Forums: Hacker News , r/privacy , r/cybersecurity , and Beehaw Bluesky: Kevin Collier / @kevincollier : The Organized Crime and Corruption Reporting Project reports today that Telegram's technical backbone is managed by a Russian network engineer with significant business ties to the FSB, Russia's counterpart to the FBI. Mike Eckel / @mikeeckel : Thousands of Telegram IP addresses, and maintenance of its servers, are controlled by a Russian network engineer — whose other companies have collaborated with the FSB, Russian defense companies, and other Russian govt agencies. occrp.org/en/investiga... via — @occrp.org @scoiattolo.mountainherder.xyz : Telegram uses a single, FSB linked company as their infrastructure provider globally. Telegram's MTProto protocol requires a cleartext identifier to be prepended to all client-server messages. — Combined, this makes it into a surveillance tool Max Bernhard / @mxbernhard : “Among their clients is the FSB intelligence agency; a secretive “research computing center” that helped plan the invasion of Ukraine and developed tools to deanonymize internet users; and a flagship state-owned nuclear research laboratory.” — www.occrp.org/en/investiga... Mastodon: @jwildeboer@social.wildeboer.net : The best time to stop using Telegram was before you installed it. The second best time to stop using #Telegram and #SwitchToSignal instead is now. — “Because of the way Telegram's encryption protocols work, even users who use its “end-to-end” encryption features are vulnerable to being tracked by anyone who can monitor its network traffic.” … @rysiek@mstdn.social : Remarkable investigation into Telegram by IStories (in Russian): — https://www.istories.media/... English version by OCCRP: — http://www.occrp.org/... tl;dr: — 👉 Telegram uses a single company with ties to the Russian FSB as their sole infrastructure provider, globally. … @josemurilo@mato.social : I've been warning about #Telegram for a long time. I think the app is even less trustworthy than anything from #Meta. New research proves this. — https://www.occrp.org/... Forums: Hacker News : Telegram, the FSB, and the Man in the Middle r/privacy : Telegram, the FSB, and the Man in the Middle r/cybersecurity : Telegram, the FSB, and the Man in the Middle English / Beehaw : Telegram is indistinguishable from an FSB honeypot
Context & Ripple Effects
Telegram’s lean operating model was previously described as having roughly 30 core employees and limited moderation, while its hands-off approach made it a major channel for Russia-Ukraine news as well as misinformation. The new reporting shifts attention from platform policy to the infrastructure beneath it, including its apparent dependence on a single provider.
The finding also fits prior coverage of Russian contractors building surveillance tools for the FSB and Telegram’s role in politically sensitive communications, including its use by democracy movements before extremists also migrated to the service.
First-order effects
- The report puts Telegram’s infrastructure concentration and privacy assurances under immediate scrutiny: traffic metadata may be exposed to parties able to monitor the network, given the described protocol design and provider relationships.
- Telegram users, particularly those relying on the service for sensitive communications, face a clearer infrastructure-level risk that is distinct from content moderation or app-source-code questions.
Second-order effects
- Telegram will face pressure to explain its hosting and routing arrangements, while security-conscious users and organizations may reassess whether its threat model fits their needs.
- The investigation increases the value of independent infrastructure audits and of messaging designs that minimize observable metadata, not merely encrypted message content.
Third-order effects
- If major communications platforms continue to rely on concentrated, politically exposed infrastructure, trust will increasingly hinge on operators, network paths, and metadata protections as much as on encryption claims.
- The case points toward a broader split between consumer-facing privacy branding and verifiable, geographically and operationally independent infrastructure—a divide regulators and high-risk users may scrutinize more closely.
The trend: Secure-messaging competition is moving beyond encryption features toward auditable control of infrastructure and the metadata generated in transit.