Extortion schemes expand, threatening consumers and businesses with data leaks

Hackers threaten to expose users' personal data if they’re not paid

Ransomware authors are not the only cybercriminals who use extortion tactics to make money from users and companies. Data thieves are also increasingly resorting to intimidation.

The FBI's Internet Crime Complaint Center (IC3) has received many reports from users whose data was stolen in various high-profile breaches and then received emails threatening to publicly disclose their personal information, including phone numbers, home addresses and credit card information.

The ransom amount asked by the extortionists ranged from 2 to 5 bitcoins or approximately $250 to $1,200, IC3 said in an advisory Wednesday.

In some cases, the attackers claim to have sensitive information about users' lives stolen from their online accounts and threaten to send it to their friends, employers and family.

“If you would like to prevent me from sharing this information with your friends and family members (and perhaps even your employers too) then you need to send the specified bitcoin payment to the following address,” one email shared by the IC3 reads. “If you think this amount is too high, consider how expensive a divorce lawyer is. If you are already divorced then I suggest you think about how this information may impact any ongoing court proceedings. If you are no longer in a committed relationship then think about how this information may affect your social standing amongst family and friends.”

It's not clear if the attackers actually have the information that they claim to have, but the extortion emails are typically sent shortly after high-profile data breaches. It's not hard to imagine that some users of compromised adult dating services would be willing to pay in order to avoid being associated with those sites.

"The FBI does not condone the payment of extortion demands as the funds will facilitate continued criminal activity, including potential organized crime activity and associated violent crimes," IC3 said.

In a separate report last week, security researchers from IBM warned that companies are also the target of extortion attempts by hackers who exploit vulnerabilities in their systems and steal data.

The attackers try to pass themselves as ethical bug hunters, even though the victim companies don't have bug bounty programs, and ask significant amounts of money to disclose the vulnerabilities that they exploited to obtain the data.

"While the attacker doesn’t explicitly threaten to release the data or attack the organization again, it leaves a lot of questions for the victims," the IBM researchers said.

In addition to ransomware, other forms of online extortion observed over the past year include asking for money under the threat of distributed denial-of-service (DDoS) attacks or stealing nude pictures, typically from women, and then asking them for more under the threat of making those pictures public -- an attack known as sextortion.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Lucian Constantin

Lucian Constantin

IDG News Service
Show Comments

Essentials

Cygnett 2500 ChargeUp Pocket Lightning Portable Power Bank

Learn more >

Mobile

Exec

Budget

Back To Business Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?