Telegram CEO says extortionist tricked Apple into App Store ban
Telegram CEO Pavel Durov says a 'takedown extortionist' tricked Apple into briefly removing Telegram from the App Store by injecting AI-modified illegal content into a public group. The app returned after about 40 minutes once Telegram removed the material.
Intelligence analysis by Llama

Pavel Durov alleges attackers used a 'technical trick' to get Telegram removed from Apple's App Store for roughly 40 minutes, framing the episode as extortion aimed at group owners rather than a moderation failure. Apple has not confirmed the extortion claim but reinstated Telegram after the content was removed.
Telegram got kicked off Apple's app store for 40 minutes because someone snuck bad pictures into a chat group using a clever trick. The bad person wanted to scare the group owner into paying them money. Telegram says this could happen to any app that lets people post things.
Analysis
The Takedown Extortion Playbook
Telegram's Pavel Durov has framed the brief removal of his app from Apple's App Store as the work of a 'takedown extortionist' — a specific kind of bad actor who weaponizes platform-reporting pipelines. According to the article, these actors use automated accounts to seed illegal content into public groups, then report the communities to Apple in an effort to force the group owner to pay a ransom. In this case, the attacker allegedly edited an old message in an active group to insert AI-modified CSAM, exploiting the fact that members never saw the edit and therefore could not flag it. Telegram's moderation tools were effectively blind to the hidden change. Durov's narrative is explicit: this is a commercialized form of sabotage, not a moderation failure, and the planted content is the ransom note.
Apple's Speed vs. Process
The most striking operational detail is the speed: Apple pulled Telegram from the App Store for roughly 40 minutes on a Monday night before, according to Durov, ever contacting the company. Apple, in its own statement, said a content review found child sexual abuse material that violated App Store guidelines and noted that Telegram 'promptly removed the content and banned the user,' which led to the app's return. The asymmetry is notable. A single CSAM detection — whether legitimately discovered or, as Durov claims, planted by an attacker — was enough to trigger a near-instant global takedown of an app used by hundreds of millions of people. Apple has not commented on Durov's extortion allegation, leaving a factual gap that neither side has closed. The episode puts a fine point on how App Store enforcement, designed to be decisive against genuinely harmful apps, can be turned into a vector for abuse.
A Warning Shot for User-Generated Content
Durov cast the incident as a 'potential systemic risk for every mobile app that hosts user-generated content,' not just Telegram. That framing is harder to dismiss than usual because the alleged mechanism — editing historical messages to inject hidden illegal material — is platform-agnostic. Any group-chat product, social network, or community forum that lets users edit prior posts faces a version of the same vulnerability. The story also sits next to Australia's separate legal action against Telegram over alleged pro-terror material referenced in the article, suggesting the company is under simultaneous pressure from regulators and bad actors. The combination sharpens a question for the wider industry: how do platforms verify the provenance of a flagged message fast enough to push back on a malicious report in the minutes it takes Apple or Google to act?
Key points
- Telegram was removed from Apple's App Store for about 40 minutes after CSAM was detected in a public group
- CEO Pavel Durov alleges a 'takedown extortionist' planted the content to extort group owners into paying a ransom
- The attacker edited an old message so group members never saw the content and could not report it
- Apple reinstated Telegram after the company removed the offending post and banned the user
- Apple has not commented on Durov's extortion claim
- Durov warned the technique poses a systemic risk for any app that hosts user-generated content
If Durov's extortion claim gains traction, it could push Apple and other gatekeepers to build in a short verification window before emergency takedowns of major apps, giving platforms time to contest malicious reports. The episode may also accelerate industry adoption of shared signals for known takedown-extortion patterns, hardening moderation pipelines against coordinated abuse.
If the pattern spreads, any platform hosting public groups becomes a soft target for paid takedowns, eroding trust in app store enforcement and forcing platforms to over-remove content defensively. The incident may also be cited by regulators as further justification for mandatory scanning or backdoors in messaging apps, even though the underlying cause is abuse of reporting channels rather than a moderation gap.


