The latest findings from NordLayer Intelligence by NordStellar, a threat exposure management platform, reveal that cybercrime-related discussions are increasingly shifting to Telegram. Across seven tracked cybercrime categories on Telegram and dark web forums, the platform’s unweighted average share of discussions reached 45% in the first five months of 2026.
Telegram’s share for January-May 2026 is 61% higher than its 28% share across the whole of 2025, signaling that cybercrime chatter on the platform is escalating quickly.

According to Vakaris Noreika, a cybersecurity expert at NordLayer Intelligence, one reason for the increase in cybercrime discussions on Telegram may be the relentless dismantling of traditional dark web forums by law enforcement. High-profile seizures of large hacker forums like LeakBase could have pushed threat actors to look for alternatives.
“Dark web forums are essentially communities for threat actors, and they spend years building their reputation to prove the trustworthiness of their sellers,” explains Noreika. “Each time a dark web forum gets taken down, it fragments the market. The threat actor community that used the forum then scatters across other smaller forums, where the once-trusted sellers enter as new, unverified users, and find it challenging to find new potential buyers.”
He explains that even after threat actors join a new dark web forum, they’re well aware that it could potentially meet the same fate.
“Building credibility, and even getting accepted into a new dark web forum, requires time and effort, and with the increasing likelihood of it eventually getting shut down, some threat actors might deem the investment no longer worthwhile,” says Noreika. “Telegram operates without these complex re-registration and reputation-building processes, making it the simpler alternative.”
A more accessible entry point for emerging threat actors
Noreika emphasizes that navigating the complex dark web infrastructure is no easy feat, especially for newcomers. Telegram, on the other hand, is a mainstream messaging platform that requires no special software or invitation to access.
“Compared with the dark web forums, Telegram presents a much lower-friction environment,” says Noreika. “Even though the platform blocked over 20 million groups and channels this year according to their official safety report, cybercriminals are quick to regroup, just as they have long done on the dark web, and doing so is far easier on Telegram.”
He suggests that the current Telegram cybercriminal ecosystem is most likely populated by newcomers who are searching for automated, mass-volume attacks to get their foot into cybercrime without the necessary skillset as well as more experienced hackers who use the platform to advertise their services or carry out lower-value deals while still keeping their main operations on the dark web.
“Despite the risks posed by ongoing law enforcement operations, the dark web offers higher operational security, and threat actors aren’t likely to trust Telegram for high-value transactions,” says Noreika. “The reputation and vetting infrastructure exists on the dark web for a reason — it’s unlikely that threat actors would carry out highly expensive and risky deals in a messaging platform that should cooperate with law enforcement.”
Staying on high alert for scalable attacks
According to Noreika, the findings of increasing cybercrime discussions on Telegram illustrate that cybercriminals are quick to adapt and are a reflection of the changes in the current cyberthreat landscape, which has experienced an influx of newcomers deploying low-skill, yet high-volume attacks.
“This shift doesn’t necessarily signal a wave of more sophisticated attackers, but a growing number of lower-skilled threat actors using easily accessible tools to launch high-volume campaigns,” says Noreika. “That means staying on high alert for threats such as phishing, credential theft, account takeover attempts, denial-of-service-for-hire activity, and deepfake-enabled fraud, all of which can be scaled quickly and deployed with limited technical expertise.”
He recommends users and organizations re-evaluate their cybersecurity hygiene, ensuring that they use unique passwords for all accounts and don’t store them in built-in browser password managers, and that multi-factor authentication is enabled wherever possible. Software and systems should be kept up to date with the latest patches, and publicly available personal information should be kept to a minimum to reduce the material that attackers can use for social engineering or deepfake creation.
“If cybercriminals manage to get a hold of credentials or other sensitive information, it’s crucial to act as soon as possible,” says Noreika. “Deep and dark web monitoring can provide alerts of many instances of leaked data, allowing for the detection of leaks across both Telegram and multiple dark web forums. This visibility is key to initiating urgent responses — such as changing passwords, revoking access from compromised accounts, and staying on high alert for any signs of further escalation.”
Methodology: Nordayer Intelligence analyzed monthly post counts across dark web forums and Telegram channels monitored by the NordLayer Intelligence platform, covering seven popular cybercrime categories from January 2024 to May 2026. Between January 2024 and May 2026, 86 dark web forums and 1,890 Telegram channels were monitored. As new sources emerged and others were shut down or seized during this period, year-on-year comparisons reflect changes in activity alongside shifts in the source pool itself. “Share” refers to the average proportion of posts across the seven tracked cybercrime categories, calculated by measuring Telegram’s share of posts in each category separately and then averaging those figures. 2026 figures cover January–May only.
Findings are limited to NordLayer Intelligence’s monitored sources and are not representative of all activity on Telegram or the dark web. Post counts measure discussion volume, not confirmed criminal activity or victims. Only aggregate counts were analyzed; no personal user data was collected. For more information, visit NordLayer Intelligence’s blog post.
Disclaimer: This analysis is provided for general information only and does not constitute legal, security, or professional advice, nor any guarantee of security or outcome. It reflects activity detected within NordLayer Intelligence’s monitored sources during the stated period and describes aggregate patterns only – no conclusion is drawn about any identified individual or organisation. References to third-party platforms and services are for identification and factual reporting only and do not imply any wrongdoing by, endorsement by, or affiliation with those parties. All third-party trademarks remain the property of their respective owners.
Today Is Women’s Equality Day
Posted in Commentary with tags Women’s Equality Day on August 26, 2026 by itnerdSince 1971, Women’s Equality Day has been recognized every August 26, marking the anniversary of the certification of the 19th Amendment and women gaining the right to vote.
We’ve come a long way since then… But when you look at the tech industry, it’s pretty clear we still have work to do. Women make up just about a quarter of the global tech workforce. And while we talk a lot about getting more women interested in tech and bringing more women into the industry, experts argue that we need to talk just as much about what happens after they get here. Half of women in tech leave the industry by age 35. So, you can recruit all the talent in the world, but if people don’t see an opportunity to grow, contribute, lead, and build a career, you haven’t solved the problem.
Estelle Azemard, CEO of Leaseweb Canada, commented, “Today, just 26.7% of the global tech workforce are women. That’s not an opinion — it’s a fact, and it’s the result of decades of education, social conditioning, and systems that we all, women included, sometimes reproduce without realizing it. Equality isn’t women’s responsibility alone. It’s everyone’s work — men and women together.”
To her point… It’s on all of us. Companies need to look at the opportunities they’re creating, the people they’re developing, and the culture they’re building – are we giving talented people a reason to stay? Are we listening to them? Are we giving everyone the chance to take on bigger challenges and become leaders?
Getting more women through the door matters. But that’s only the beginning. Hard skills and soft skills don’t belong to one gender, one race, one religion, or one background. They’re developed through learning, experience, and opportunity.
The best companies recognize that talent can come from anywhere… and then make sure that talent has every opportunity to succeed.
Leave a comment »