A private Telegram group or channel can be entered through an invite link held by a recipient. The link can be forwarded beyond the original audience, so 'private' is an entry rule, not a confidentiality guarantee. Telegram says revoking a link stops it working immediately, while existing members remain members until removed. If a link reaches a public page or a compromised chat, treat the link and the membership list as separate cleanup tasks.
Before you start
Confirm you have administrator rights to manage invites and members. Record where the leaked link appeared, when it was shared and which legitimate people still need access. If the group holds sensitive material, coordinate with other administrators before rotating a link and consider whether content already seen requires a separate response.Do it step by step
- Open the group's info or management page and inspect invite links. Identify the leaked link rather than deleting a different campaign or moderator's invitation.
- Revoke the exposed link. Telegram's invite API and app controls support revocation; a new link can be generated for an approved audience with expiry, use limit or join approval where available.
- Review recent joins and the current member list. Remove an unauthorized member and preserve evidence if abuse occurred. Revocation does not expel anyone who joined before it was revoked.
- Inspect administrator roles and permissions. An admin who can create links may have produced another public route; coordinate a single controlled invitation process.
- Send the replacement link only through a trusted channel to named recipients. Avoid posting it on public social media and then relying on the word 'private' in the group label.
- Test that the old link no longer joins and that the new link's limits work as intended. Monitor join requests and member changes for a period after the incident.