
Emilis Klybas
·

Between May 22 and August 7, 2026, collony.ai moderated just over 250,000 messages across Telegram and Discord communities and recorded 11,600 moderation incidents. This post is what that data says about how scams and spam actually behave in 2026, with the numbers stated plainly so admins and researchers can use them.
The headline numbers
85.7% of removed messages contained no blocklisted keyword
76.2% of bad actors were flagged on their very first message
7.5 seconds median time from message to flag
36.9% of incidents landed between midnight and 8am UTC
1 in 4 flagged accounts involved impersonation
0.3% of flagged accounts were ever seen in a second community
86% of what we removed contained no blocklisted keyword
The single most important number in the dataset: of 10,760 removed messages with text content, 9,217 had zero hits against standard keyword blocklists. A keyword bot would have missed 85.7% of what our behavioral system removed. This is a conservative approximation, and it matches what we argued from first principles in rule-based bots vs AI moderation: modern spam is written to pass filters, and the signal has moved from words to behavior.
Three quarters of bad actors are caught on their first message
Of 6,036 users who were eventually struck, 76.2% were flagged on their very first message, with a median of 18 seconds between first message and first strike. Detection itself runs at a median of 7.5 seconds from message to flag, with the 95th percentile under 45 seconds. The tail matters too: for the accounts that were not caught immediately, the 90th percentile was 4.2 hours, which is the sleeper pattern of accounts that behave until they activate.
37% of incidents happen while your admins sleep
Incidents spread across every hour of the day, with 36.9% landing between midnight and 8am UTC. There is no safe hour: the quietest hour of the day still logged 242 incidents over the period, roughly a third of the busiest. Any moderation plan that depends on a human being awake has an eight-hour hole in it every single day.
Scammers burn accounts, they do not reuse them
Of 6,354 flagged accounts, only 0.3% appeared in more than one community. Cross-community blocklists of known bad accounts, the backbone of older anti-spam systems, are structurally obsolete: accounts are cheap enough that operators use a fresh set per target. Reputation has to be computed from behavior in the moment, not looked up from history.
What the scams actually are
By broken rule, the biggest categories were scams, phishing and impersonation at the top, followed closely by romance-bait bot accounts, DM solicitation pushing members off-platform, and get-rich-quick recruitment spam. Impersonation alone appears in 24.6% of flagged accounts, which is why impersonation checks run on profiles, not just messages. In flagged links, t.me invite links dominate everything else by an order of magnitude, with WhatsApp funnels second and a long tail of freshly registered scam domains that no blocklist had seen.
Attacks arrive as waves, not trickles
The largest single wave in the dataset: 783 incidents from 54 accounts in one community over roughly five hours. Waves of this shape are why per-message moderation fails at the worst moment, the queue grows faster than humans clear it. Coordination detection that treats 54 accounts as one event is what turns five hours of firefighting into an automated response.
The error rate, stated honestly
Of 11,647 total incidents, admins forgave 39 and 2 were logged as our mistakes, a combined 0.35%. Severity skews heavy: 57% of incidents were classified critical. The actions behind them: 14,339 message deletions, 5,465 bans, 4,831 mutes, with under 1.5% of actions later revoked.
Methodology
Data covers production Telegram and Discord communities moderated by collony.ai from May 22 to August 7, 2026. Community identifiers are anonymized. Scam categories are proxied by which community rule a message broke. The keyword-miss figure compares removed message text against standard public blocklists and is stated conservatively. We will rerun this analysis as the message base grows.
Frequently asked questions
What percentage of scams do keyword filters miss?
In our production data, 85.7% of removed messages contained no blocklisted keyword. Scam copy is written and rotated specifically to pass word filters, so the majority of modern scam content is invisible to keyword moderation.
How fast should moderation catch a scammer?
Our production median is 7.5 seconds from message to flag, and 76% of bad actors are caught on their first message. Speed matters because scam DMs and links do damage in the first minutes, not hours.
When do scammers attack communities?
Around the clock. 37% of incidents in our dataset landed between midnight and 8am UTC, and the quietest hour still carried a third of the volume of the busiest. Any hole in your coverage is exactly what operators schedule around.
Do scammers reuse accounts across communities?
Almost never. Only 0.3% of flagged accounts appeared in more than one community, because accounts are cheap and burned per target. Shared blocklists of known bad accounts no longer work, behavior-based detection does.



