Telegram allows several devices to use the same account at once, so an unfamiliar session can read cloud chats without taking your phone away. The Devices screen is the starting point, but the cause may be a shared computer, stolen phone, reused login code or compromised SIM. Terminating a session stops that device's account access; it does not retract messages already read or downloaded. Work through the account and carrier in a deliberate order.
Before you start
Use a device you still control and do not share a login code with anyone who calls about the incident. Record the suspicious session's device label, approximate location and last activity for your notes; location can be inaccurate. If there is immediate danger or financial pressure in messages, preserve evidence and contact the relevant service or local help independently.Do it step by step
- Open Telegram Settings, Devices; some versions place Active Sessions under Privacy and Security. Identify your current phone and any desktops, tablets or web sessions you recognize.
- Terminate the unfamiliar session. If several are unknown, use Terminate All Other Sessions after confirming the phone in your hand is the trusted current one. Do not mistake a device label alone for proof of an intruder.
- Enable or change Two-Step Verification in Settings, Privacy and Security. Choose a strong unique password and secure its recovery email, because control of that inbox can undermine recovery.
- Review recent cloud-chat messages, group invitations, contact changes and messages sent from your account. Tell contacts through a trusted route if the account was used to request money or codes.
- If the phone was lost or the SIM may be compromised, contact the carrier to block or replace the SIM. Use the platform's lost-device controls; Telegram session termination is not a remote wipe of phone storage.
- Recheck Devices after new sign-ins and confirm only expected sessions remain. Avoid entering codes on a site reached from a chat, even if it claims to be Telegram support.