Explainable Platform Risk Scoring for Post-Compromise Analysis of Credential Leaks from Telegram

  • Dewi Holilah Universitas Pamulang
Keywords: Credential leaks, Cyber Threat Intelligence, Telegram, Risk scoring, Explainable AI

Abstract

Credential leaks pose a major threat to cybersecurity because they often lead to follow-up attacks such as credential stuffing and account takeovers. Beyond dark web forums, Telegram has emerged as a prominent platform for the open distribution of leaked credentials. However, existing studies largely focus on descriptive analysis or threat detection, providing limited support for transparent and measurable post-compromise risk assessment. This study proposes an Explainable Platform Risk Scoring (XPRS) framework to support post-compromise decision-making in Cyber Threat Intelligence (CTI). Credential leak data are collected from public Telegram channels and processed through preprocessing stages to mitigate duplication and remove irrelevant records. Technical vulnerability is quantified using Shannon entropy, while platform risk is estimated by integrating platform impact and leak characteristics. Explainable Artificial Intelligence (XAI) employs SHapley Additive exPlanations (SHAP) to clarify risk indicators. The evaluation utilizes rank-based statistical analysis to examine the correlation between platform frequency and associated risk scores. The results indicate that XPRS consistently generates and interprets platform-level risk prioritization, offering practical support for transparent cybersecurity in post-compromise contexts. The findings demonstrate that the frequency of leaks is not the primary determinant of risk; instead, platforms in critical sectors such as Identity & Access Management (IAM), government, and financial services consistently exhibit the highest risk scores despite lower leak volumes. This underscores that systemic impact and credential quality are more significant in post-compromise risk assessment than the sheer quantity of leaks.

Downloads

Download data is not yet available.

References

Alzakari, S. A., Aljebreen, M., Ahmad, N., Alahmari, S., Alrusaini, O., Alqazzaz, A., Alkhiri, H., & Said, Y. (2025). Explainable artificial intelligence- based cyber resilience in internet of things networks using hybrid deep learning with improved chimp optimization algorithm. Scientific Reports, 15(25), 33260. https://doi.org/10.1038/s41598-025-15146-x

Arikkat, R. D., B. T., S., Nicolazzo, S., Nocera, A., P., V., Rehiman K. A., R., & R., K. (2025). CTI Dataset Construction from Telegram. ArXiv E-Prints (ArXiv:2509.20943). https://doi.org/https://doi.org/10.48550/arXiv.2509.20943

Borjigin, S. (2024). Systematic Solutions to Login and Authentication Security Problems : A Dual-Password Login-Authentication Mechanism. ArXiv. https://doi.org/https://doi.org/10.48550/arXiv.2404.01803

Jaeckel, L., Spranger, M., & Labudde, D. (2025). Forensic Science International : Digital Investigation Forensic analysis of Telegram Messenger on iOS smartphones. Forensic Science International: Digital Investigation, 52. https://doi.org/doi:10.1016/j.fsidi.2025.301866

Mirani, S., Kaoudis, K., & Sultanik, E. (2025). Preventing Account Takeovers on Centralized Cryptocurrency Exchanges. https://github.com/trailofbits/publications

Mustaqeem, M. M. El, Abdul, M. N. H., & AlDahoul, N. (2025). Enhancing Password Security Through a High- Accuracy Scoring Framework Using Random Forests. ArXiv. https://arxiv.org/abs/2511.09492

National Institute of Standards and Technology. (2012). Guide for Conducting Risk Assessments (Issue September).

Rabzelj, M., & Sedlar, U. (2025). Beyond the Leak : Analyzing the Real-World Exploitation of Stolen Credentials Using Honeypots. Sensors, 25(12), 3676. https://doi.org/https://doi.org/10.3390/s25123676

Roy, S. S., Vafa, E. P., Khanmohamaddi, K., College, S., Nilizadeh, S., Symposium, U. S., & Roy, S. S. (2025). DarkGram : A Large-Scale Analysis of Cybercriminal Activity Channels on Telegram. The USENIX Security Symposium. https://www.usenix.org/conference/usenixsecurity25/presentation/roy

Roy, S. S., Vafa, E. P., Khanmohammadi, K., & Nilizadeh, S. (2025). DarkGram: A Large-Scale Analysis of Cybercriminal Activity Channels on Telegram. Proc. 34th USENIX Security Symposium. https://arxiv.org/abs/2409.14596v3

Shi, Y., Yang, M., Zhong, K., Yang, G., Yang, Y., Zhang, X., & Yang, M. (2025). The Skeleton Keys : A Large Scale Analysis of Credential Leakage in Mini-apps. Network and Distributed System Security (NDSS) Symposium. https://doi.org/https://dx.doi.org/10.14722/ndss.2025.230273

Uptycs Threat Research Team. (2023). Stealers are Organization Killers. https://www.uptycs.com/hubfs/White-Paper_Stealers.pdf?utm_source=chatgpt.com

Xia, L., Baghaie, S., & Sajadi, S. M. (2024). The digital economy: Challenges and opportunities in the new era of technology and electronic communications. Ain Shams Engineering Journal, 15(2), 102411.

Published
2026-02-09