{"id":547,"date":"2021-03-16T11:44:39","date_gmt":"2021-03-16T18:44:39","guid":{"rendered":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/?p=547"},"modified":"2021-03-16T11:44:39","modified_gmt":"2021-03-16T18:44:39","slug":"notification-your-emailuvic-ca-extortion-messages","status":"publish","type":"post","link":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/2021\/03\/16\/notification-your-emailuvic-ca-extortion-messages\/","title":{"rendered":"Notification &#8220;your email@uvic.ca&#8221; &#8211; Extortion messages"},"content":{"rendered":"<p>Over several years now we have seen various versions of extortion type emails where the criminal attempts to scare you into thinking they have some sort of damaging or embarrassing piece of information about you. Over the weekend we saw a such emails, that happen to be in French and reporting they have hacked your system, stole your photos etc and are using a Bitcoin Exchange to have you reply to their ransom. The included link is a link to a bitcoin exchange service.<\/p>\n<p>These weekend versions also spoof\/fake your email address and lead you to believe that perhaps your email account was hacked or is being misused. It can happen, yes, but those we&#8217;ve seen in this run are fake messages that only look like they were sent via your email address.<\/p>\n<p>These two examples are only some of the variants you may see. Next week they may be in English or another language. Sometimes they capture an old password you used from old password breaches and scare you by putting a copy of that password in the subject line.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-548\" src=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/03\/frexportion.png\" alt=\"\" width=\"1006\" height=\"608\" srcset=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/03\/frexportion.png 1006w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/03\/frexportion-300x181.png 300w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/03\/frexportion-768x464.png 768w\" sizes=\"auto, (max-width: 1006px) 100vw, 1006px\" \/><\/p>\n<p><strong>Important: If you ha<\/strong><strong>ven&#8217;t changed your passwords in<\/strong><strong> a long time and you reuse, please change them now to longer and unique passphrases for every service.<\/strong><\/p>\n<p>It is scary to see that someone has discovered an old password but less scary when you know you are now practicing better passphrase and account management.<\/p>\n<p>Second sample email and English translation below:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-551\" src=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/03\/frextortion2.png\" alt=\"\" width=\"714\" height=\"424\" srcset=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/03\/frextortion2.png 714w, https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-content\/uploads\/sites\/4983\/2021\/03\/frextortion2-300x178.png 300w\" sizes=\"auto, (max-width: 714px) 100vw, 714px\" \/><\/p>\n<p>English Translation:<\/p>\n<pre><span class=\"VIiyi\" lang=\"en\"><span class=\"JLqJ4b\" data-language-for-alternatives=\"en\" data-language-to-translate-into=\"auto\" data-phrase-index=\"0\">Dear victim.<\/span><\/span>\r\n\r\n<span class=\"VIiyi\" lang=\"en\"><span class=\"JLqJ4b\" data-language-for-alternatives=\"en\" data-language-to-translate-into=\"auto\" data-phrase-index=\"0\"> I hacked your computer and your smartphone for a period of 3 months, I followed your activities well and I recorded a lot of things about you, even your intimate moments and other sexual stuff, I copied all of them your friends and family contacts, I want you secret to stay between you and me, but you would have to pay me for that <\/span><\/span>\r\n\r\n<span class=\"VIiyi\" lang=\"en\"><span class=\"JLqJ4b\" data-language-for-alternatives=\"en\" data-language-to-translate-into=\"auto\" data-phrase-index=\"0\">Send me 1500 \u20ac by BitCoin to this address: bc1q9mzfz7kg6gefn057c82gdmprd5rmda4m5p25xu <\/span><\/span>\r\n\r\n<span class=\"VIiyi\" lang=\"en\"><span class=\"JLqJ4b\" data-language-for-alternatives=\"en\" data-language-to-translate-into=\"auto\" data-phrase-index=\"0\">This Bitcoin address is automatically linked to the storage server to give you (Your photos and videos) After receiving the funds, all your data will be deleted on my server automatically, you have a 48 hour deadline to send the money, if you exceed this deadline my server will automatically share all your data with your contact list and directory, and your photos and videos will automatically be published on pornography sites, and on social networks (Facebook, Instagram, Twitter, Snapchat, TikTok, ...). <\/span><\/span>\r\n\r\n<span class=\"VIiyi\" lang=\"en\"><span class=\"JLqJ4b\" data-language-for-alternatives=\"en\" data-language-to-translate-into=\"auto\" data-phrase-index=\"0\">here is where to buy bitcoin https:\/\/&lt;redacted&gt;==============================<\/span><\/span><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Over several years now we have seen various versions of extortion type emails where the criminal attempts to scare you into thinking they have some sort of damaging or embarrassing piece of information about you. Over the weekend we saw a such emails, that happen to be in French and reporting they have hacked your &hellip; <a href=\"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/2021\/03\/16\/notification-your-emailuvic-ca-extortion-messages\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Notification &#8220;your email@uvic.ca&#8221; &#8211; Extortion messages<\/span><\/a><\/p>\n","protected":false},"author":968,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"image","meta":{"footnotes":""},"categories":[1],"tags":[6,8,7],"class_list":["post-547","post","type-post","status-publish","format-image","hentry","category-uncategorized","tag-extortion","tag-scare-tactic","tag-spoofed-email","post_format-post-format-image"],"_links":{"self":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/547","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/users\/968"}],"replies":[{"embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/comments?post=547"}],"version-history":[{"count":4,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/547\/revisions"}],"predecessor-version":[{"id":554,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/posts\/547\/revisions\/554"}],"wp:attachment":[{"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/media?parent=547"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/categories?post=547"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/onlineacademiccommunity.uvic.ca\/phishbowl\/wp-json\/wp\/v2\/tags?post=547"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}