June 11, 2019 By David Bisson 1 min read

Malicious actors are threatening to ruin websites’ reputations and get them blacklisted as part of a new extortion scam campaign.

According to Bleeping Computer, this extortion campaign involves fraudsters using websites’ contact forms to reach out to site owners. These emails typically have the subject line “Abuse and lifetime blocking of the site – example.com. My requirements.” The message warns the recipient that the fraudsters will destroy the site’s reputation unless they pay 0.3 bitcoin — currently worth approximately $2,400 — as a ransom.

The fraudsters also say they’ll prey upon the site by sending 30 offensive messages to 13 million sites, sending 300 aggressive advertising messages to another 9 million web locations, and spamming for the site on blogs, forums and other websites. Such actions, the malefactors note in their message, will ultimately prompt users to leave negative reviews and feedback about the site and ultimately get the site blacklisted for distributing spam.

The Evolution of an Extortion Scam Campaign

Back in July 2018, Krebs on Security came across the first iteration of this scam in a series of sextortion emails that used people’s compromised passwords to trick them into paying as much as $1,400 for the supposed preservation of their privacy.

A few months later, Bleeping Computer uncovered a scam campaign that used a fake bomb threat to extort recipients. Around the same time, the firm found a similar operation using the threat of a hit man to prey upon organizations.

Awareness Is Critical to Prevent Cyber Extortion

Security professionals can help their employees avoid extortion scam campaigns by conducting regular awareness training, establishing strict policies and implementing email security solutions to defend against phishing attacks. Companies should complement this investment with regular phishing tests to measure how well this three-pronged strategy works in a simulated phishing attack.

More from

ISC2 Cybersecurity Workforce Study: Shortage of AI skilled workers

4 min read - AI has made an impact everywhere else across the tech world, so it should surprise no one that the 2024 ISC2 Cybersecurity Workforce Study saw artificial intelligence (AI) jump into the top five list of security skills.It’s not just the need for workers with security-related AI skills. The Workforce Study also takes a deep dive into how the 16,000 respondents think AI will impact cybersecurity and job roles overall, from changing skills approaches to creating generative AI (gen AI) strategies.Budgets…

Why do software vendors have such deep access into customer systems?

4 min read - To the naked eye, organizations are independent entities trying to make their individual mark on the world. But that was never the reality. Companies rely on other businesses to stay up and running. A grocery store needs its food suppliers; a tech company relies on the business making semiconductors and hardware. No one can go it alone.Today, the software supply chain interconnects companies across a wide range of industries. Software applications and operating systems depend on segments of the software…

How CTEM is providing better cybersecurity resilience for organizations

4 min read - Organizations today continuously face a number of fast-moving cyber threats that regularly challenge the effectiveness of their cybersecurity defenses. However, to keep pace, businesses need a proactive and adaptive approach to their security planning and execution.Cyber threat exposure management (CTEM) is an effective way to achieve this goal. It provides organizations with a reliable framework for identifying, assessing and mitigating new cyber risks as they materialize.The importance of developing cybersecurity resilienceRegardless of the industry, all organizations are subject to certain…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today