Scams

Posted March 24, 2024 · Updated September 23, 2026

Internet/Phone Scams

Blackmail scam going around

I occasionally receive emails to two or three different email addresses with the message below.

The threat is same in all cases except the email and passwords stated are unique to the recipient. In both cases the passwords were, in fact, actual passwords I sometimes used. But since I always use an email alias the address they claimed to have hacked was given as the alias which does not exist as an actual email account. The compromised passwords were only used on unimportant sites such as to post a comment to a forum or news article. All logins of any critical value each have strong and unique passwords. Basically I know I have no worries.

Actual hacking is involved to some extent given they had real passwords but only email alias used as part of logins to inconsequential sites. It was not my machine that had been hacked, it was the forums I subscribed to that were hacked thus the emails and passwords they had. No loss to me. there!

If you can, you should always use an email alias that is NOT used to log into your actual email account and never use the actual account's email for this very reason. If you use a different password everywhere you will more easily spot these kinds of scams.

If you use a password manager using unique passwords is easy. I suggest BitWarden for this as it is free and very secure.

 

They are spoofing your email which is easy just by editing the reply-to to make it appear as if it came from your own email...chances are small it actually did. In each case the messages I received came from forged IP addresses, not from the IP of my mail server. Also note the reference to "my web cam"...I have no web cam on my desktop computer and I disable webcame in laptop in hardware settings.  ( Do that...you can always enable it if you need it )

  • Nothing in this should concern you unless...well you really have something to hide and they really did get into your accounts.

  • Check your provider but don't send any money !

  • Change your passwords!

  • Use email alias only as your reply to email.


Consider a free, secure email account such as www.tutanota.com

Here is the text of the scam/blackmail threat complete with their typos and errors in English . Don't fall for it.

 

Hello! I'm a member of an international hacker group. As you could probably have guessed, your account [your email] was hacked, I sent message you from it.

Now I have access to you accounts! You still do not believe it? So, this is your password: [password] , right?

Within a period from July 5, 2018 to September 21, 2018, you were infected by the virus we've created, through an adult website you've visited. So far, we have access to your messages, social media accounts, and messengers. Moreover, we've gotten full damps of these data.

We are aware of your little and big secrets...yeah, you do have them. We saw and recorded your doings on porn websites. Your tastes are so weird, you know..

But the key thing is that sometimes we recorded you with your webcam, syncing the recordings with what you watched! I think you are not interested show this video to your friends, relatives, and your intimate one...

Transfer $700 to our crypto wallet: 1DzM9y4f___8647___x4HupbE5Q5r4y ( The wallet key was altered to make it unusable) I guarantee that after that, we'll erase all your "data" :D

A timer will start once you read this message. You have 48 hours to pay the above-mentioned amount.

Your data will be erased once the money are transferred. If they are not, all your messages and videos recorded will be automatically sent to all your contacts found on your devices at the moment of infection.

You should always think about your security. We hope this case will teach you to keep secrets. Take care of yourself.

 

A few other common variants of this exact scam

The wording changes, the threat is always the same. Recognize the pattern even if the exact phrasing you got doesn't match word-for-word:

"I have access to your operating system and I got full control over your device... I installed a Trojan virus on your OS through an adult website you visited. If you are not familiar with this, I will explain. Trojan virus gives me full access and control over a computer or other device..."

"Your account has been hacked! We need to talk. Your account was hacked, and I have compromising footage recorded through your webcam. You have 24 hours to send [amount] in cryptocurrency or I release it to everyone in your contact list..."

"This is not a joke or scam. Someone has access to your devices and has been watching your activity. I have deployed a malicious software (RAT) into all your devices..."

Every version uses the same three ingredients: a claim of total access, an old or reused password as "proof," and a payment deadline. None of it means they're actually in your accounts - the same advice applies regardless of the exact wording: don't pay, don't engage, change any reused passwords, and move on.

New scams keep showing up - the pretext changes, the goal doesn't.

The blackmail email above is one flavor, but scammers constantly cycle through new hooks designed to get you to click, reply, or pay before you think it through. Common ones making the rounds recently:

  • "Your mailbox is full" - a fake storage-quota warning with a link to a spoofed login page designed to steal your email password.
  • "You have a document to sign" - a fake e-signature request (DocuSign, Adobe Sign, etc.) that either steals credentials or installs malware.
  • "Delivery failed, reschedule now" - a fake shipping notification (USPS/FedEx/UPS-style) with a link asking for payment info to "release" a package.
  • "Unusual sign-in detected" - a fake security alert meant to panic you into entering your real password on a lookalike site.
  • AI voice-cloning calls - a caller who sounds exactly like a relative in trouble; see our Deep Fake AI article for how to protect yourself against this specifically. This overlaps with an older trick you may already know: the "Hello? Can you hear me?" call. It was originally understood as an attempt to get you to say "yes" on a recording for billing fraud - it works just as well now to harvest a voice sample for cloning. Same advice either way: don't respond, don't ask "who is this," just hang up.

The pattern is always the same: urgency, a link or a phone number they provide, and pressure not to verify independently. Before you click, reply, or call:

  • Go to the actual company's site or app directly instead of using the link in the message.
  • Call back using a number you already have, not one from the message.
  • When in doubt, wait a day - real deadlines from real companies rarely disappear in 24 hours; fake ones are built to rush you.

An ounce of prevention folks.

Tips from the FTC on avoiding scams

Want to check what's currently going around? BBB Scam Tracker is a free, searchable, crowdsourced database of reported scams across the US and Canada - filterable by keyword, scam type, location, and date, with a live heatmap of what's trending where.