Telegram's Weak Spot Is Your Phone Number

Telegram logins work by SMS: enter your number, receive a code, you're in. Convenient, but it means anyone who can read your SMS can become you. SIM swappers, malicious carrier insiders, and in several documented cases even state level actors intercepting SMS have taken over Telegram accounts this way. Once in, an attacker sees your chats (except secret chats), your groups, and can message every contact as you.

Two-step verification closes the hole. It adds a password (Telegram calls it a cloud password) required after the SMS code on every new device. An intercepted SMS alone gets an attacker nothing.

How to Enable Two-Step Verification

  1. Open Telegram and go to Settings.
  2. Tap Privacy and Security.
  3. Tap Two-Step Verification.
  4. Tap Set Password (or Set Additional Password).
  5. Create a strong password and an optional hint.
  6. Add a recovery email and confirm it via the link Telegram sends. Do not skip this step.

From now on, logging in on any new device needs the SMS code AND this password.

Choosing the Cloud Password

  • Make it unique. Not your email password, not a variation of it. Attackers who phish one password try it everywhere. A generated password from our free password generator stored in a password manager is ideal.
  • Or use a passphrase if you prefer memorising it: four or five random words beat any short clever password. Our passphrase guide shows the method.
  • Write the hint carefully. The hint shows to anyone trying to log in as you. "Same as my bank" is a confession, not a hint.

Why the Recovery Email Is Not Optional

Forget the cloud password without a recovery email set, and your options are grim: Telegram offers to reset the account, which means wiping all your chats, groups, and channels to let you back onto your number. With a recovery email, you reset the password through a link in seconds.

Naturally, that email account becomes part of your Telegram security. Lock it down with app based 2FA: our Gmail guide takes two minutes.

Telegram hijacks spike in waves by country, usually wherever SMS interception is cheapest. The victims almost always had no cloud password set. It's the single highest value setting in the app.

The Other Settings That Matter

  • Active Sessions: Settings → Devices shows every logged in session. Terminate anything unfamiliar immediately: this is also the kill switch if you're ever hijacked while still holding a session.
  • Login code security: Telegram sends login codes to your existing Telegram sessions, not just SMS. Never forward or read out a login code to anyone, including "Telegram support". Support never asks.
  • Privacy settings: Hide your phone number (Privacy and Security → Phone Number → Nobody) so scrapers and stalkers can't map your number to your profile.
  • Auto-delete and secret chats for genuinely sensitive conversations: secret chats are end to end encrypted and never touch Telegram's cloud. What that means technically: our end to end encryption explainer.

Two-Step Verification vs Regular 2FA

Telegram's model is unusual: the SMS code is the primary factor, and the password is the second. Most services do the reverse. The effect is the same as standard 2FA (two different proofs required), but it's worth understanding that the password is what protects you from number based attacks: the exact threat covered in our SIM swapping explainer. Telegram doesn't support TOTP authenticator codes; the cloud password fills that role.

Frequently Asked Questions

I forgot my Telegram cloud password. What now?

If you set a recovery email, use "Forgot password" and reset through the link. If not, and you're still logged in on a device, you can change the password from Settings there. Logged out with no email set: the only path is the account reset, which erases your data. Set the recovery email today.

Does two-step verification protect my existing sessions?

It protects new logins. Existing sessions stay valid, which is why the Active Sessions list matters: hijackers who got in before you enabled the password keep access until you terminate their session there.

Can I use an authenticator app with Telegram?

No, Telegram doesn't support TOTP codes. The cloud password is its second factor. Your authenticator app still earns its keep on your email, socials, and everything else: see our authenticator app roundup.

Someone is logging into my Telegram right now. What do I do?

Open Settings → Devices and terminate all other sessions, then set or change your two-step verification password immediately. Warn your contacts if the attacker had time to message anyone. If you lost access entirely, log in with your number, and if a wait period is shown (Telegram delays resets on protected accounts), let it run rather than resetting the account.

Is Telegram Premium needed for any of this?

No. Two-step verification, sessions management, and all security settings are free for every account.

Shoyeb Akter

Written by

Security Tools Developer and creator of 2FA Fast — a privacy-first browser-based authenticator and security tools platform.