Fake Drawing Votes Target Telegram Accounts, Ukraine Warns

Daniel Zimmermann
6 Min Read
A children’s drawing becomes a trapdoor for a chat bubble in a Telegram voting scam.
A request to support a drawing can conceal an account-login trap.

A request to vote for a child’s drawing can end with someone else using your Telegram account. Ukraine’s Center for Countering Disinformation warned on September 21 that messages promoting a supposed international drawing contest lead people from a voting page to a fake Telegram sign-in. The borrowed account can then carry the same invitation to the victim’s contacts. [1]

The critical change is easy to miss: you start by choosing a picture, but the site asks you to authorize access to a messaging account. If you received that request from a friend, confirm it through a separate call or another service before doing anything with the link.

A vote becomes an account sign-in

The Center describes a purpose-built contest website where visitors choose a participant. Only after that choice does the page redirect them to a counterfeit Telegram authorization form, asking for account details and confirmation of a login. It has not published a victim count, a start date for the activity, or evidence of a vulnerability in Telegram itself.

That sequence gives the login request a misleading purpose. The visitor thinks the next step records a vote; the attacker wants it to grant account access. The competition provides a reason to click, and the familiar sender provides a reason to trust. Once an account is compromised, that trust can be reused for the next recipient.

Example: “Could you vote for a child in this drawing competition? Here is the link.” The wording can change. The warning sign is the transition from supporting a contestant to supplying a Telegram login code or approving an unexpected sign-in.

An older screenshot shows the same switch

This technique predates the latest warning. On May 23, 2025, the National Bank of Ukraine’s Cybersecurity Center documented a children’s drawing-contest lure that asked for a phone number and a one-time code sent by SMS or Telegram. Its report described compromised accounts being used to send further phishing messages. [2]

Fake vote-confirmation page requesting a phone number, published by the NBU in May 2025.
Historical example, May 23, 2025: the page presents a phone-number request as a voting-fairness check. Source: National Bank of Ukraine, Cybersecurity Center.

In that historical screenshot, the page calls itself a vote-counting system and says confirmation keeps the voting fair. Beneath that explanation is a phone-number field. This is the mechanism in miniature: account authentication is presented as a contest rule. The image documents the 2025 report; it does not establish that the same domain is being used in September 2026.

A code arriving inside Telegram does not make a contest trustworthy. Telegram distinguishes codes for third-party services from login codes for the Telegram account itself; it says account login codes should never be shared with another service or app. [3] Read what the notification authorizes, rather than accepting the explanation on the voting page.

Check the session, not the vote result

If you only opened the page, close it and decline any login confirmation you did not initiate. The warning describes an authorization trap; opening a link alone is not evidence that your account was taken over.

If you entered a Telegram login code or approved an unexpected login, use the genuine Telegram app on a device where you are still signed in. Open Settings → Devices, or Privacy and Security → Active Sessions, and terminate unfamiliar sessions. Turn on or review Two-Step Verification under Privacy and Security. Enabling that password is a separate measure from ending an already active session.

Warn contacts through another channel if your account has sent the voting request. If access is already lost, use Telegram’s own login and recovery flow; do not give another code to someone offering to “recover” the account. Our Telegram scam guide covers other fake-account, bot, and recovery approaches.

The request may sound generous, and the sender may be someone you know. Neither makes an unrelated account login a necessary part of voting for a drawing.

References

  1. Center for Countering Disinformation. “Шахраї маскують фішингову схему під «голосування за дитячі малюнки».” September 21, 2026. Official warning.
  2. National Bank of Ukraine, Cybersecurity Center. “Шахрайська схема «Конкурс дитячого малюнка».” May 23, 2025. Historical advisory and screenshots.
  3. Telegram. “FAQ”: login codes, active sessions, and Two-Step Verification. Accessed September 22, 2026. Official account-security guidance.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?