Hackers recently obtained the mobile phone numbers of 15 million users in Iran. The hack was carried out through the Telegram messaging app, and they also gained access to more than a dozen accounts. This, security researchers claim, was achieved by monitoring the SMS verification codes of each phone number.

The danger here is that encryption could potentially be used against governments. In this case, the hacking was done by a cyberespionage. The group had some connection to the Iranian government and managed to track down 15 million Iranian Telegram users.
Telegram reported the attacks in a blog post but downplayed their significance. It also said that information about which accounts are linked to which phone numbers should be public. Otherwise, users would not be able to communicate with their friends or anyone they want through the app.

The company is aware that Telegram accounts can be compromised by hackers who breach SMS, but this is not a new problem. Last year, it introduced an optional two-factor authentication feature that combines SMS codes and passwords. The company encouraged users in some countries to enable this feature if they were concerned that could be monitoring SMS codes. This feature theoretically does not allow an attacker to do anything. Telegram was asked to translate the feature into Farsi so that Iranian users use it more easily.
The US National Institute of Standards and Technology is considering removing SMS as a second factor of verification (two-factor authentication) for securing government information and communications systems.
