Home Cyber Security News Many Private WhatsApp And Telegram Group Invite Links Are Appearing On Search Engines

Many Private WhatsApp And Telegram Group Invite Links Are Appearing On Search Engines

by Abeerah Hashim
WhatsApp Telegram group invite links exposed

A critical issue might have exposed your WhatsApp or Telegram group to the public. As discovered by a researcher, many WhatsApp and Telegram Group invite links appeared on various search engines. Not only has this exposed legit private groups but also some illegal groups.

WhatsApp Telegram Group Invite Links Exposed

Researcher Jordan Wildon discovered that many search engines have indexed various messenger apps’ group invite links. With the search engines showing up WhatsApp and Telegram group invite links publicly. This includes visibility of the links on all major search engines such as Google, Yahoo, Bing, and Yandex.

Wildon revealed his findings via a tweet.

He further elaborated that this public exposure of the links not only allowed unwanted people to join such groups. Rather it also empowered potential attackers to find other active chats via brute forcing.

What’s worrisome is that another researcher had already found and reported this issue to Facebook authorities earlier. However, at that time, they expressed their inability to address this matter.

This flaw not only ruined the privacy of private WhatsApp and Telegram groups but also made many illegal groups publicly accessible.

The same could also allow data mining since an adversary could directly access phone numbers after joining the groups. Because of this issue, around 450,000 groups were exposed online.

Google Addressed The Matter, But…

Recently, WhatsApp has seemingly rectified the issue by removing the group invite link listings from Google. They also added a ‘noindex’ meta tag to prevent recurrent indexing in the future.

Google has also addressed the issue by removing all WhatsApp group links from indexing. However, other search engines are yet to follow.

Nonetheless, Wildon has shared a quick way for Group admins to mitigate the problem. He recommends resetting the group invite link.

While the matter seems partially resolved for WhatsApp, Telegram groups’ links may still appear in search engine results. Thus, until complete rectification of the matter, WhatsApp and Telegram group admins need to remain vigilant about incoming members.

Let us know your thoughts in the comments.

You may also like

Latest Hacking News

Privacy Preference Center


The __cfduid cookie is used to identify individual clients behind a shared IP address and apply security settings on a per-client basis.

cookie_notice_accepted and gdpr[allowed_cookies] are used to identify the choices made from the user regarding cookie consent.

For example, if a visitor is in a coffee shop where there may be several infected machines, but the specific visitor's machine is trusted (for example, because they completed a challenge within your Challenge Passage period), the cookie allows Cloudflare to identify that client and not challenge them again. It does not correspond to any user ID in your web application, and does not store any personally identifiable information.

__cfduid, cookie_notice_accepted, gdpr[allowed_cookies]


DoubleClick by Google refers to the DoubleClick Digital Marketing platform which is a separate division within Google. This is Google’s most advanced advertising tools set, which includes five interconnected platform components.

DoubleClick Campaign Manager: the ad-serving platform, called an Ad Server, that delivers ads to your customers and measures all online advertising, even across screens and channels.

DoubleClick Bid Manager – the programmatic bidding platform for bidding on high-quality ad inventory from more than 47 ad marketplaces including Google Display Network.

DoubleClick Ad Exchange: the world’s largest ad marketplace for purchasing display, video, mobile, Search and even Facebook inventory.

DoubleClick Search: is more powerful than AdWords and used for purchasing search ads across Google, Yahoo, and Bing.

DoubleClick Creative Solutions: for designing, delivering and measuring rich media (video) ads, interactive and expandable ads.



The _ga is asssociated with Google Universal Analytics - which is a significant update to Google's more commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page request in a site and used to calculate visitor, session and campaign data for the sites analytics reports. By default it is set to expire after 2 years, although this is customisable by website owners.

The _gat global object is used to create and retrieve tracker objects, from which all other methods are invoked. Therefore the methods in this list should be run only off a tracker object created using the _gat global variable. All other methods should be called using the _gaq global object for asynchronous tracking.

_gid works as a user navigates between web pages, they can use the gtag.js tagging library to record information about the page the user has seen (for example, the page's URL) in Google Analytics. The gtag.js tagging library uses HTTP Cookies to "remember" the user's previous interactions with the web pages.

_ga, _gat, _gid