HomeSecurityScammers demand ransom for fake site breaches

Fraudsters demand ransom for fake website breaches

websites

Cybercriminals are targeting website owners by sending them ransom messages demanding between $1,500 and $3,000 in bitcoin . The blackmailers claim to have the databases websites’ in their possession , which they threaten to expose if the ransom is not received. This could cause major problems for the website owners, while also damaging their reputation.

The scammers claim to have exploited a vulnerability in the sites' software, which allowed them to obtain the credentials . With these credentials, they stole the databases. However, these claims are false.

The extortionists threaten that if the ransom is not received, they will expose or sell the “stolen” databases of the sites. They will also ’ customers and partners victims about the breach, in order to destroy their reputation.

Finally, to further scare targets, the blackmailers say they will remove the sites from search engines using “blackhat” SEO techniques.

The deadline for paying the ransom is 5 days.

What makes this scam special is not the extortion technique it uses, but the well-written ransom note (it doesn't have any particular grammatical errors, as is usually the case).

Below is an excerpt from the message the victims received :

“We have hacked your website [website URL] and extracted your databases.

How did this happen?

Our team has found a vulnerability within your site that we were able to exploit. After finding the vulnerability we were able to get your database credentials and extract your entire database and move the information to an offshore server.

What does this mean?

We will systematically go through a series of steps of totally damaging your reputation. First your database will be leaked or sold to the highest bidder which they will use with whatever their intentions are. Next if there are e-mails found they will be e-mailed that their information has been sold or leaked and your site [website URL] was at fault thusly damaging your reputation and having angry customers/associates with whatever angry customers/associates do. Finally any links that you have indexed in the search engines will be de-indexed based off of blackhat techniques that we used in the past to de-index our targets.

How do I stop this?

We are willing to refrain from destroying your site's reputation for a small fee. The current fee is [ransom amount] USD in bitcoins (BTC).

If you decide not to pay, we will start the attack at the indicated date and uphold it until you do, there's no counter measure to this, you will only end up wasting more money trying to find a solution. We will completely destroy your reputation among google and your customers”.

ransom

Don't pay the ransom, it's just a scam

So far, WebARX researchers who discovered the scam have found several Bitcoin wallets being used to collect the ransom. Also, many site owners have reported the incident on the help page Blogger , the WordPress support forum , and StackOverflow .

Fortunately, almost none of the site administrators and owners fell for the hackers. Only two payments appear to have been made since mid-April, when the first reports of this scam emerged.

However, scammers are still quite active and are still trying to scam victims, as evidenced by user reports on the BitcoinAbuse platform .

The most important thing when you receive such an email is to check if it contains any proof that site has actually been hacked.

Also, look up the Bitcoin address embedded in the emailin the Bitcoin Abuse Database. There you can see if this address has been or is being used by scammers and extortionists. Another user may have already reported it. So you should always consult the platform.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS