Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen
Bomb Threat - A new wave of blackmail mails is in circulation!
Offensive Security

Bomb Threat - A new wave of blackmail mails is in circulation!

A new wave of blackmail mails is in circulation. In these mails bombs are threatened to get the ransom money. You should react like this!

Vincent Heinen Vincent Heinen Abteilungsleiter Offensive Services
Updated: October 2, 2024 2 min read read
OSCP+ OSCP OSWP OSWA

TL;DR

A new email extortion campaign targets companies with bomb threats, demanding 20,000 euros in Bitcoin within 80 hours to prevent an alleged building attack. Like most blackmail emails, time pressure is a key tactic to stop recipients from thinking critically. The police advise never paying and instead collecting all evidence - emails, headers - on a USB stick and filing a report at the nearest police station. More reports from different companies increase the chances of identifying the criminals.

Table of Contents (2 sections)

Already in the past we had to report about blackmail mails that are currently in circulation. A new and very current campaign is a blackmail email that claims that without the ransom money a bomb will explode.

Bomb threat - This is what the message looks like

Criminals try again and again to reach different persons or companies with blackmail emails in order to get the ransom money. In the current campaign, primarily companies are addressed, since the content is about attacking a commercial building with a bomb. 20000€ should be transferred within 80 hours, so that the bomb will not explode. As with almost all email blackmailing, Bitcoin is demanded as a means of payment. By this crypto-currency it is possible for the criminals to remain unrecognized, without the need to use a bank account with an associated name. On a well-known web page which informs about current fraud scams we can find the blackmail mail, which we show in the following: blackmailmail

3 days time is given to the victims to transfer the money. This kind of time pressure is common for blackmail mails. This blackmail mail shows many familiar patterns, which we have already had to report in the past. A good example is the scam in which victims are called by an alleged Microsoft employee. A common feature between the fraud scam described here and the call fraud scam is that in both cases time pressure is applied. In general pressure is a component that occurs in almost every blackmail mail, so that the victims do not have much time to think logically about the written content.

Handling of such blackmail mails

If you or other employees in your company have received this mail or a comparable blackmail mail, you should not simply delete it. The police advises you not to comply with the demands under any circumstances! Instead, all evidence, e.g. emails, should be stored on a USB stick and handed in at the next police station with a report against unknown persons. The threats of the criminals are not without consequences, so the police tries to catch the criminals as soon as possible. The more evidence can be collected from different companies, the more likely it is to find a mistake the criminal has made in a case.

Next Step

Our certified security experts will advise you on the topics covered in this article — free and without obligation.

Free · 30 minutes · No obligation

Share this article

About the author

About the Author

Vincent Heinen
Vincent Heinen

Abteilungsleiter Offensive Services

E-Mail

M.Sc. IT-Sicherheit mit über 5 Jahren Erfahrung in offensiver Sicherheitsanalyse. Leitet die Durchführung von Penetrationstests mit Spezialisierung auf Web-Applikationen, Netzwerk-Infrastruktur, Reverse Engineering und Hardware-Sicherheit. Verantwortlich für mehrere Responsible Disclosures.

OSCP+ OSCP OSWP OSWA
Certified ISO 27001ISO 9001AZAV