Background
Telegram account security has become a practical digital governance issue where messaging platforms are used for personal communication, public outreach, and commercial contact. Account compromise can enable impersonation, unauthorized messaging, and fraud conducted through existing contact networks, making platform security settings relevant to broader cyber safety and online trust.
Two-step verification is a user-level security control that adds a password requirement beyond a one-time login code. Active session management allows users to review which devices are connected to an account and terminate unauthorized access. In Cambodia, public digital-safety advisories issued by government technology and media bodies form part of a preventive approach to online fraud awareness rather than a formal regulatory instrument.
Key Developments
The General Department of Digital Technology and Media stated that its technical team had recently observed victims whose Telegram accounts were taken over by malicious actors. According to the notice, those accounts were then allegedly used to impersonate the victims for offenses carried out through social media.
The guidance advises users who suspect unauthorized use of their Telegram accounts to check Settings > Devices in order to review active sessions. If an unfamiliar device appears, users are instructed to use Terminate Session or Terminate All Other Sessions to end suspicious access.
Operational Implications
The advisory recommends several protective measures to strengthen account security. Users are told to enable Two-Step Verification through Settings > Privacy and Security > Two-Step Verification and set an additional password. The notice also recommends enabling Passcode Lock and biometric access controls such as Face ID to reduce the risk of unauthorized access from a person holding the device directly.
The department further warns users not to click links from unclear sources, especially links requesting phone numbers or one-time passwords. This reflects a common fraud pattern in which attackers attempt to capture login credentials or verification codes through deceptive messages.
Compliance Implications
The notice identifies several signs that may indicate account compromise, including messages sent without the user’s knowledge, unexplained joining of unfamiliar groups or channels, messages marked as read even when unopened, and repeated receipt of Telegram login codes. These indicators are presented as practical warning signs for users monitoring account integrity.
The department also notes that terminating unauthorized sessions should be followed immediately by activation of two-step verification. That sequence is intended to reduce the risk that a malicious actor can regain access after a suspicious session has been removed.
Official Source
General Department of Digital Technology and Media, Facebook post published on 25 April 2026: source.

