Cartoon hacker peeking from a computer server with a red robotic eye, surrounded by phones and doxxing documents, symbolizing cybercrime.
Farsi Version
Download PDF
Accessibility
Text Size
100%

Channels, Bots, and Extortion: The Architecture of Doxxing on Persian-Language Telegram

Doxxing on Persian-language Telegram is not a collection of isolated, unrelated incidents. It constitutes a multilayered ecosystem in which the disclosure of personal information has simultaneously become a tool of political repression, gender-based violence, and profit-driven extortion. This ecosystem consists of primary channels, groups, bots, administrator accounts, payment routes, and backup channels. Together, these components collect, supplement, and publish victims’ information, enlist users in identifying and harassing them, and, in some cases, make the removal of published images and information conditional on payment.

Data from the Miaan Digital Security Help Desk between January 2026 and July 2026 shows that women and opponents of the Islamic Republic are the primary targets of these networks. Women are targeted through the publication of private images, phone numbers, and sexual content, while information about protesters, journalists, students, and Iranians living abroad is published to intimidate or identify them, or to facilitate their arrest. In intersectional cases, women who oppose the government face political accusations and gender-based violence at the same time.

After a channel is removed, these networks can continue operating through bots and replacement channels. Publishing home addresses, employment information, and family details can carry pressure from the online sphere into victims’ offline lives. Removing one component does not necessarily eliminate content from the rest of the network, as the content often remains available elsewhere, with users redirected to replacement channels, groups, or bots.. In practice, Telegram has therefore become a platform for organizing collective harassment and reproducing political and gender-based violence.

Key Findings

  • The largest network comprised 41 channels, groups, bots, and accounts, with a combined audience of more than 100,000. Other documented networks included one with 28 components, another with eight channels, and one consisting of a primary channel, two groups, a backup channel, and a bot.
  • Seventy-seven percent of the cases targeted political opponents, protesters, activists, journalists, and Iranians living abroad.
  • Twenty-five percent targeted women and girls, while at least 7 percent combined gender-based violence with political targeting. These categories overlap.
  • In at least seven cases, users were encouraged to identify victims, submit additional information, report them to security agencies, or harass them directly.
  • In one network, the removal of private information and images was made conditional on payment.

Infographic about doxing in Persian-language Telegram channels, highlighting largest network, targets, women’s share, and participation stats.

What Is Doxxing?

Doxxing is the deliberate collection, publication, or republication of an individual’s personal or identifying information without their consent, particularly when intended to identify, intimidate, threaten, extort, or facilitate online or offline harassment. This information may include a person’s full name, photograph, phone number, home or workplace address, national identification number, date of birth, social media accounts, professional and financial information, details about family members, and private images or videos.

The data used in this investigation was collected from two primary sources: reports and requests submitted to the Miaan Digital Security Help Desk, and field data collected and documented by Filterwatch researchers through monitoring Telegram channels, groups, bots, administrator accounts, and backup channels.

These examples are not representative of all doxxing activity on Persian-language Telegram. They reflect only a portion of the cases reported to or identified by Filterwatch.

Infographic about Doxing in Persian-language Telegram channels showing four patterns with icons and blue description panels.

The Architecture of the Doxxing Ecosystem

Filterwatch’s findings show that doxxing on Persian-language Telegram is rarely limited to the publication of information on a single channel. In a significant proportion of cases, networks of channels, groups, bots, administrator accounts, and backup channels are involved in different stages of collecting, publishing, and redistributing personal information. This multilayered structure expands access to the content, makes it more difficult to identify the primary operators, and enables activity to continue after one component of the network has been removed.

Collecting and Supplementing Information

The first layer of this ecosystem involves collecting information about victims. Some channels publish initial details, such as a person’s name or photograph, and ask users to find and submit their phone number, address, workplace, family information, or social media accounts. In politically motivated cases, users have been encouraged to identify protesters and report them to the Islamic Revolutionary Guard Corps, the judiciary, or other security agencies. Users are therefore not merely consumers of the content; they actively contribute to building information profiles on victims.

According to information obtained by Filterwatch, some of the images published by Telegram doxxing channels in one of Iran’s western provinces had initially been taken from friends-and-family groups on domestic messaging platforms, including Eitaa, and subsequently reposted on Telegram. This example shows how information-gathering chains can extend across multiple platforms, transferring content shared in restricted or trusted groups into public networks of harassment and exposure.

Publication on the Primary Channel

The primary channel generally serves as the network’s public-facing platform. Collected information is published in posts containing photographs, names, phone numbers, addresses, national identification numbers, employment information, or details about family members. These disclosures are often accompanied by insults, accusations, threats, or calls for action against the targeted individual. Political opponents are labelled “traitors” or “spies,” while women are targeted with gender-based slurs and sexual content.

Distributing Content Through Groups and Bots

Groups and bots form the network’s distribution and user-routing layer. Groups enable users to participate, submit new information, and coordinate harassment. Bots can direct users to private images, videos, or personal information, while chains of links make access to the original content more dispersed and difficult to trace.

In one of the largest documented examples, 41 channels, groups, bots, and accounts—with more than 100,000 members and followers—were involved in distributing a victim’s private images. Another documented network comprised 28 components and had a combined audience of approximately 70,000. In a locally focused network, a primary channel, two groups, a backup channel, and a bot were used to publish women’s phone numbers and encourage users to harass them.

Turning Audiences into Agents of Harassment

Publishing personal information is rarely the end of the process. In at least 16 percent of cases, network operators directly asked users to identify victims, submit additional information about them, call published phone numbers, or report targeted individuals to security agencies. Within this structure, a single channel can turn thousands of users into potential agents of harassment, transforming an attack from a centrally managed operation into a form of collective participation.

This participation can also have offline consequences. Publishing a victim’s address, workplace, or family information increases the risk of surveillance, arrest, and pressure on their relatives. Publishing women’s photographs and phone numbers—particularly in areas with a history of so-called honor-based violence—can heighten the risk of physical and social harm.

Extortion Through Content Removal

In part of this ecosystem, doxxing has developed into an extortion model. In one network, after publishing private images and personal information, operators announced that they would remove the content in exchange for payment. Users were directed to the private material through multiple bots and links, while victims were pressured to pay to stop its distribution.

Filterwatch’s data shows that some networks published bank account numbers, Iranian IBANs (Sheba numbers), or cryptocurrency wallet addresses to receive payments. These details are not merely payment mechanisms; they can also provide a financial trail for investigating connections among channels, administrators, and financial flows. The appearance of the same bank account, Sheba number, or wallet address across several seemingly independent channels may indicate shared management or financial links.

Yet, these payment methods do not have equal evidentiary value. Bank accounts and Sheba numbers are generally connected to identity information held by banks and can be more readily attributed during a lawful investigation. A cryptocurrency wallet address does not, on its own, identify its owner. However, transaction analysis and links to identity-verified exchanges, bank accounts, or other wallets may provide additional leads.

Payment also does not guarantee an end to the abuse. The content may already have been downloaded or reposted, may remain available through bots and backup channels, or may be republished later.

Backup Channels and Network Reconstitution

Backup channels form the final layer of this ecosystem’s architecture. They may be created before the primary channel is removed or begin operating after its removal. In one case, after the primary channel was shut down, a backup channel with similar content was created and continued publishing information about Iranians living abroad. The primary channel also reappeared several days later, although it had no content or followers when observed.

This pattern demonstrates that removing a channel does not necessarily dismantle the network. As long as bots, administrator accounts, groups, or replacement channels remain active, operators can redirect their audiences and republish removed content. Effective action against doxxing therefore requires examining the connections among all components of a network rather than responding to each channel or post in isolation.

Gender-Based Doxxing

Twenty-five percent of the cases reviewed involved the targeting of women and girls. In these cases, the publication of personal information was accompanied by gender-based slurs, sexual humiliation, the distribution of private images and videos, and calls for users to harass victims. Women’s phone numbers, photographs, addresses, and private content were published without their consent, while some channel operators encouraged users to contact and harass them.

This pattern was also observed in local and provincial networks. One network consisted of a primary channel, two groups, a backup channel, and a bot, and distributed information about women and girls in one area to an audience of approximately 10,000. Channels in Kurdistan, Lorestan, and Khuzestan also published women’s photographs and phone numbers alongside abusive and sexualised language.

Victims’ social and geographical circumstances can heighten the risks they face. Some of these networks operated in marginalised areas or provinces where so-called honor-based violence has been reported. Domestic media reported that, in one western province, the publication of women’s images had led some of them to die by suicide. A human rights lawyer also told Filterwatch that three women in another province died by suicide after their images were published on these channels.

In more severe examples, doxxing was accompanied by the distribution of sexual content without consent. One network disseminated private images and videos through dozens of channels, groups, bots, and accounts. In another case, a video depicting the rape of a student was published alongside victims’ phone numbers, addresses, and private images. This pattern demonstrates how gender-based doxxing can become a tool of digital sexual violence, public humiliation, and the social control of women.

Political Doxxing

Approximately 77 percent of the cases reviewed involved political targeting. Victims included protesters, student and civil society activists, journalists, human rights defenders, opponents of the Islamic Republic, and Iranians living abroad. Published information included photographs, phone numbers, addresses, national identification numbers, employment details, and information about family members.

Some channels openly sought to turn scattered information into dossiers that could be used by security agencies. Photographs of protesters were published, and users were asked to identify them and report them to the Islamic Revolutionary Guard Corps for arrest. Another channel claimed that it was identifying protesters using drones and other unmanned aerial vehicles. University-focused networks also published student activists’ addresses, phone numbers, photographs, identification numbers, and relatives’ names.

This practice extended beyond Iran. Channels published information about Iranians living abroad alongside accusations such as “treason” and “espionage,” and threatened them with property confiscation, pressure on family members, or retaliatory action. In Spain, one channel published Iranian residents’ national identification numbers, dates of birth, current and former addresses, workplaces, and family information, while asking users to submit further details about them.

These findings demonstrate that political doxxing is not intended solely to shame victims or subject them to online harassment. The organised publication of personal information can facilitate identification, arrest, surveillance, pressure on families, and cross-border reprisals against political opponents.

The Intersection of Political Repression and Gender-Based Violence

Approximately 7 percent of the cases reviewed were intersectional, combining gender-based violence with political targeting. In these cases, women who opposed the Islamic Republic or were associated with protests were subjected to the disclosure of personal information alongside gender-based slurs, sexual threats, or the publication of private content.

Infographic about the intersection of political repression and gender-based violence, with a logo, a left-column female icon and dense text blocks on both sides.

In these attacks, gender is integral to the mechanism of repression. Attackers use sexualized stigma, threats of rape, the publication of private images, and the risk of familial or social violence to raise the cost of women’s political participation.

Sexual Discrediting as a Tool of Repression

In these cases, gender-based violence forms part of the political repression of women. Attackers use sexualized insults and threats, publish private images, or falsely attribute sexual content to victims in order to discredit them and drive them out of public life—regardless of whether the content is authentic, fabricated, or merely alleged to depict them.

The disclosure of personal information also turns victims’ families and social environments into instruments of pressure, potentially increasing the risk of social ostracism, domestic violence, or so-called “honor”-based violence. This pressure may also be extended to women activists living abroad through their families in Iran.

Distributing an attack across channels, groups, and bots enables content to be recirculated and additional information to be collected. The consequences extend beyond the direct victim: witnessing the price paid by women activists may discourage other women from participating in political and civic life.

Networks Re-emerging After Removal

Removing a channel does not necessarily dismantle a doxxing network. The multilayered architecture of these networks allows operators to distribute their content, audiences, and activities across primary channels, groups, bots, and backup channels. As a result, even after one component is removed, other parts of the network may remain active or be used to redirect users to a new destination.

Filterwatch’s  data documents at least one clear sequence of removal, re-emergence, and replacement. In this case, the primary channel, which published information about Iranians living abroad, was disabled after being reported to Telegram. Several days later, the same channel reappeared, although it had no content or followers when observed. Meanwhile, a backup channel began operating with similar content and continued publishing the photographs, names, and employment information of targeted individuals. The backup channel was also removed after being reported to Telegram.

This pattern illustrates three distinct forms of operational continuity: the re-emergence of the same channel, the creation of a replacement channel, and the survival of other network components. In networks comprising multiple bots, groups, and channels, removing the primary channel may only block direct access to one segment of the content. Victims’ images and information may already have been stored or republished elsewhere in the network and can become accessible again after removal.

Telegram’s partial response may also contribute to a network’s survival. In some cases, one channel was removed entirely, while Telegram deleted only certain posts from other channels. Under such circumstances, administrator accounts, audiences, communication links, and the network’s capacity to collect and republish information remain intact.

Text Size
100%