June 11, 2019 By David Bisson 1 min read

Malicious actors are threatening to ruin websites’ reputations and get them blacklisted as part of a new extortion scam campaign.

According to Bleeping Computer, this extortion campaign involves fraudsters using websites’ contact forms to reach out to site owners. These emails typically have the subject line “Abuse and lifetime blocking of the site – example.com. My requirements.” The message warns the recipient that the fraudsters will destroy the site’s reputation unless they pay 0.3 bitcoin — currently worth approximately $2,400 — as a ransom.

The fraudsters also say they’ll prey upon the site by sending 30 offensive messages to 13 million sites, sending 300 aggressive advertising messages to another 9 million web locations, and spamming for the site on blogs, forums and other websites. Such actions, the malefactors note in their message, will ultimately prompt users to leave negative reviews and feedback about the site and ultimately get the site blacklisted for distributing spam.

The Evolution of an Extortion Scam Campaign

Back in July 2018, Krebs on Security came across the first iteration of this scam in a series of sextortion emails that used people’s compromised passwords to trick them into paying as much as $1,400 for the supposed preservation of their privacy.

A few months later, Bleeping Computer uncovered a scam campaign that used a fake bomb threat to extort recipients. Around the same time, the firm found a similar operation using the threat of a hit man to prey upon organizations.

Awareness Is Critical to Prevent Cyber Extortion

Security professionals can help their employees avoid extortion scam campaigns by conducting regular awareness training, establishing strict policies and implementing email security solutions to defend against phishing attacks. Companies should complement this investment with regular phishing tests to measure how well this three-pronged strategy works in a simulated phishing attack.

More from

The major hardware flaw in Apple M-series chips

3 min read - The “need for speed” is having a negative impact on many Mac users right now. The Apple M-series chips, which are designed to deliver more consistent and faster performance than the Intel processors used in the past, have a vulnerability that can expose cryptographic keys, leading an attacker to reveal encrypted data. This critical security flaw, known as GoFetch, exploits a vulnerability found in the M-chips data memory-dependent prefetcher (DMP). DMP’s benefits and vulnerabilities DMP predicts memory addresses that the…

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today