Anticoruptie.md is the first online platform in the Republic of Moldova for reporting cases of corruption and related crimes.

Follow us

Blog

The Telegram Paradox: Moldova's Self-Inflicted Vulnerability

Share
uploads/blog/2025/09/08/553(810,455).png
Pexels

Moldova’s persistent use of Telegram as a communication platform, despite its documented security vulnerabilities, has enabled sophisticated Russian disinformation campaigns that threaten the country’s democratic institutions.

The Technical Foundation of Telegram’s Vulnerabilities

In June 2025, the Organized Crime and Corruption Reporting Project (OCCRP) published a detailed investigation into Telegram’s infrastructure, revealing that user traffic is routed through Global Network Management (GNM), a company managed by Vladimir Vedeneev with documented contracts serving Russia’s Federal Security Service (FSB). This creates an “infrastructure-level compromise potential.” When messaging traffic passes through servers controlled by entities with intelligence service ties, cryptographic protections, if any, become largely irrelevant.

Unlike platforms like Signal, which employs end-to-end encryption by default, Telegram’s architecture compounds its vulnerabilities. Its default messaging and all group chats use server-client encryption, meaning that approximately 95% of communications exist in plaintext on Telegram’s servers during processing. For intelligence agencies, this setup provides a “lawful intercept” capability—access to communications metadata and content through infrastructure control rather than endpoint compromise. When servers are managed by entities with documented FSB connections, this creates a fundamentally compromised security model, exposing user data to potential surveillance and manipulation.

The Mechanics of Modern Influence Campaigns

The recent investigations exposed the operational sophistication of Russia’s “digital army,” coordinated through Telegram under Ilan Șor’s “Victory” Bloc. The campaign employs advanced techniques that leverage Telegram’s architectural weaknesses:

- Dual-Layer Coordination Architecture: The operation uses private Telegram channels for recruitment and strategic coordination, while public broadcast channels amplify narratives. This structure ensures operational security for coordinators while maintaining plausible deniability for participants, as the public-facing content appears disconnected from the private planning.

- Cultural Authenticity via Local Recruitment: Rather than relying on automated bot networks, the campaign recruits local Moldovan activists under the guise of “personal branding” training. This approach provides cultural authenticity, making disinformation more relatable and harder to detect, while financial incentives, directly funded from Moscow, sustain participation.

- Cross-Platform Amplification Networks: Content coordinated on Telegram is systematically propagated across platforms like Facebook and TikTok, creating the illusion of organic grassroots engagement. This centralized narrative control ensures consistent messaging while mimicking decentralized, authentic discourse.

These tactics demonstrate how Telegram’s infrastructure enables both secure coordination and widespread dissemination, making it an ideal platform for influence operations.

Institutional Failures and the Security Paradox

Screenshot MNotify

 

As of September 2025, Moldova’s government continues to use Telegram for official services, despite its documented role as the primary coordination platform for Russian influence campaigns targeting the country. This creates multiple layers of institutional vulnerability:

- Intelligence Collection Risk: Government communications conducted through Telegram, which lack end-to-end encryption, risk exposing sensitive citizen data to adversaries. This could provide real-time intelligence on Moldovan citizens, compromising national security.

- Legitimacy Transfer Problem: By using Telegram for official purposes, the government implicitly endorses its security, encouraging public adoption. This increases the platform’s reach among populations vulnerable to disinformation, amplifying the effectiveness of influence campaigns.

The government’s failure to act on previous cybersecurity findings reflects a broader issue: cybersecurity is treated as a secondary concern rather than a cornerstone of democratic governance. Administrative convenience—Telegram’s ease of use and widespread adoption—consistently takes precedence over security considerations, even when the platform demonstrably undermines national interests.

The Compliance and Accountability Vacuum

The absence of systematic threat assessment and mitigation within Moldovan institutions is deeply concerning. The OCCRP’s technical analysis provided actionable intelligence about Telegram’s vulnerabilities, yet government agencies have continued to rely on the platform without implementing countermeasures. This inaction creates a legitimacy framework that enables adversaries to conduct sophisticated influence operations against Moldova’s democratic institutions.

On July 31, 2025, following President Maia Sandu’s public acknowledgment of Telegram as the “primary source used for destabilization and electoral corruption,” I submitted a formal public information request through Moldova’s e-democratie platform to the Service for Information Technology and Cyber Security (STISC). The request was redirected to the Center for Strategic Communication and Combating Disinformation. Filed under Law No. 982 of May 11, 2000, it sought details on:

- Legal frameworks governing Telegram administrators and users

- Moldova’s jurisdictional authority over Telegram accounts

- Official communications with Telegram as a company

- Measures implemented during the 2024 elections to counter disinformation

- Partnership strategies with Romania for combating disinformation

- Strategic objectives for addressing hybrid threats in the 2025 elections

Despite a legal requirement for a response within 15 working days, the request remains unanswered after over 30 calendar days, with follow-up communications to both the Center and the Presidency (which oversees counter-disinformation efforts) ignored. This lack of transparency underscores a critical governance failure, particularly given the urgency of the documented threats.

Moldova’s experience highlights the transnational scalability of infrastructure-enabled influence campaigns. The European Union’s Digital Services Act (DSA) provides regulatory frameworks for platform accountability, but its focus on content moderation rather than infrastructure vulnerabilities limits its effectiveness. Telegram’s architecture—centralized coordination through private channels paired with distributed amplification across multiple platforms—requires infrastructure-level interventions, not just content-based responses. The sophistication of these operations, from culturally authentic recruitment to cross-platform amplification, reflects the maturation of influence warfare capabilities.

The Strategic Cost of Inaction

The Ziarul de Gardă investigation’s findings were entirely predictable based on the OCCRP’s earlier technical analysis. The operational sophistication—local recruitment for authenticity, financial incentives, and cross-platform coordination—demonstrates how adversaries exploit Telegram’s infrastructure to refine their capabilities. Each month of delayed remediation allows these actors to expand recruitment networks, deepen infrastructure dependencies, and enhance their operational reach, making disruption increasingly difficult.

When the government prioritizes administrative convenience over cybersecurity rigor, it create conditions for systematic democratic subversion. The same infrastructure that enables efficient communication becomes a conduit for sophisticated influence operations designed to erode trust in democratic processes.

The window for effective remediation is narrowing. Each day of reliance on compromised infrastructure provides adversaries with operational advantages that compound over time. Moldova must overcome institutional inertia to prioritize security over convenience. Failure to do so risks further erosion of democratic integrity, particularly as the 2025 electoral cycle approaches, offering adversaries another opportunity to exploit Telegram’s vulnerabilities. The infrastructure for democratic subversion already exists; the question is whether Moldova can develop the cybersecurity governance capabilities to defend against it in time.

 

image

Textele de pe pagina web a Centrului de Investigații Jurnalistice www.anticoruptie.md sunt realizate de jurnaliști, cu respectarea normelor deontologice și sunt protejate de dreptul de autor. Preluarea textelor știrilor și a investigațiilor jurnalistice se realizează în limita maximă de 500 de semne. În mod obligatoriu, în cazul paginilor web (portaluri, agenții, instituţii media sau bloguri) trebuie indicat şi linkul direct la articolul preluat de pe www.anticoruptie.md în primul alineat, iar în cazul posturilor de radio și TV – se citează obligatoriu sursa. Preluarea integrală a textelor se poate realiza doar în condiţiile unui acord prealabil semnat cu Centrul de Investigații Jurnalistice.

Tags Blog

Subscribe