Blackmail email
Author
Discussion

rival38

Original Poster:

505 posts

161 months

Wednesday 18th May 2022
quotequote all
Sorry if covered elsewhere, search did not reveal anything relevant.

Long story short.

I am getting emails to my work email address - shared on 5 networked PC’s. It is an admin@…….co.uk address,
The incoming emails (appear to be sent) from our own email. They detail how our own address will be used to embarrass us if we do not make a blackmail payment.

Apart from the small office network (cloud based / managed by local IT support firm) no other devices have ever logged onto our work email accounts.

I have copied the blackmail emails to out IT support providers……but in the meantime, has anybody else had this sort of thing? Ignored it? Defeated it?

Perhaps we just need to re set our email account ( outlook ) log ins? Can it be that simple?

rival38

Original Poster:

505 posts

161 months

Wednesday 18th May 2022
quotequote all
Duplicate post deleted

anonymous-user

70 months

Wednesday 18th May 2022
quotequote all
Spoofing an email address is child's play, it's unlikely your account has been compromised, but if you feel it could have been then you should get professionals to look at it.

https://dylan.tweney.com/2017/10/25/how-to-fake-an...

Carsie

936 posts

220 months

Wednesday 18th May 2022
quotequote all
Std stuff. Mark as spam and block sender. Change passwords , update anti virus and malware if not done so already . Clear cache and re-boot.

Report here

https://www.actionfraud.police.uk/

Sleep easy wink

QJumper

3,238 posts

42 months

Wednesday 18th May 2022
quotequote all
In the meantime you might also want to put a hold on whatever it is you're doing that you could be blackmailed for.

Zoon

6,999 posts

137 months

Wednesday 18th May 2022
quotequote all
Are you being asked for payment in bitcoin?
If so it's a well-worn scam and nothing to worry about.

dundarach

5,723 posts

244 months

Wednesday 18th May 2022
quotequote all
QJumper said:
In the meantime you might also want to put a hold on whatever it is you're doing that you could be blackmailed for.
smile

Countdown

44,946 posts

212 months

Wednesday 18th May 2022
quotequote all
rival38 said:
They detail how our own address will be used to embarrass us if we do not make a blackmail payment.
Just curious - how will they use your email address to embarrass you?

Zoon

6,999 posts

137 months

Wednesday 18th May 2022
quotequote all
Countdown said:

Just curious - how will they use your email address to embarrass you?
I suspect it's along the lines of they will forward videos of the owner masturbating to porn to all contacts in their address book.

StevieBee

14,283 posts

271 months

Wednesday 18th May 2022
quotequote all
Zoon said:
Countdown said:

Just curious - how will they use your email address to embarrass you?

I suspect it's along the lines of they will forward videos of the owner masturbating to porn to all contacts in their address book.
I actually replied to one of these once (prompted, I think by someone here) along the lines "fill yer boots, mate. None of my contacts would be the least bit surprised and think I may have done the same by mistake anyway!' smile

Ham_and_Jam

3,137 posts

113 months

Wednesday 18th May 2022
quotequote all
Been getting these for years, usually addressed to admin@, sales@, etc…

The format / style changes with current trends, but are usually designed to frighten you that they have intimate, financial or personal details about you that they will exploit should you not pay a ransom.

I’ve just binned them, mark as spam.

Australiam

277 posts

145 months

Wednesday 18th May 2022
quotequote all
Carsie said:
Std stuff. Mark as spam and block sender. Change passwords , update anti virus and malware if not done so already . Clear cache and re-boot.

Report here

https://www.actionfraud.police.uk/

Sleep easy wink
This.

However, it sounds like you are using the same email account on 5 machines. If this means multiple users are using the same email account, it is not the best way to do it, for a number of reasons, not least security, and the ability to audit your own staff. Best practice would be for each user to have their own account, then set 'Admin' up as a mailbox or alias. Your IT provider should be able to advise.

rival38

Original Poster:

505 posts

161 months

Wednesday 18th May 2022
quotequote all
All done, thank you.

IT chaps say it is a ‘spoofing’ email - the sender does not have the ability to get into our email system, but can try and spoof us with a one time email that seems to be sent by ourselves.

Anyway - the IP address it was sent from has been included with our report. No doubt it will be in Belarus or similar - but we have done what we can.

extraT

1,864 posts

166 months

Wednesday 18th May 2022
quotequote all
You have to tell us how that ended/ what they replied with!!

rival38

Original Poster:

505 posts

161 months

Wednesday 18th May 2022
quotequote all
Countdown said:
rival38 said:
They detail how our own address will be used to embarrass us if we do not make a blackmail payment.
Just curious - how will they use your email address to embarrass you?
It could be anything : The porn threat is not a real worry, but immagine the hassle if all customers were sent a ‘inflation busting offer, all booked work will be discounted with a 25% price reduction’ …..immagine the headache & accusations that perhaps some customers were getting that and others were being disadvantaged. Many might decide to disbelieve that the email was a fraud, but that it had been sent to them by mistake….it would be a total pain & very damaging to credibility………much more than some dodgy pics.

Anyway - IT people have sorted it I think, the claim that our email / recipient cache is compromised was not taken seriously by them, this is aparently a ‘spoofing’ scam.

ecs0set

2,487 posts

300 months

Wednesday 18th May 2022
quotequote all
rival38 said:

Anyway - IT people have sorted it I think, the claim that our email / recipient cache is compromised was not taken seriously by them, this is aparently a ‘spoofing’ scam.
If you have an SPF record (see Google) and email filtering, you should not be getting spoofed emails. I hope your IT people are taking steps to investigate and prevent this from happening again.

You might not be falling for the spoof but maybe one of your colleagues could in the future.

Mr_Megalomaniac

1,013 posts

82 months

Wednesday 18th May 2022
quotequote all
DarkTrace is also good at helping prevent this in advance. Good luck OP on defeating the blackmailers.
Offer to meet them in person, go with a shotgun wink

vikingaero

11,959 posts

185 months

Wednesday 18th May 2022
quotequote all
I regularly get spam/spoof emails at home and at work claiming I am visiting pron sites, have been recorded on my webcam masturbating and to send money to their Bitcoin wallet.

Well work block all pron, I have no webcam on my desktop and I think the ladies sitting opposite me would have complained if I Tommy Tanked in front of them.

At home, there is unlimited access to pron but no webcam on my desktop.

They have been getting better with their emails - sometimes including titbits: " I know you live in xxx town".

They get their stuff from sites you've visited that have been compromised:

https://haveibeenpwned.com/

LooneyTunes

8,317 posts

174 months

Wednesday 18th May 2022
quotequote all
rival38 said:
All done, thank you.

IT chaps say it is a ‘spoofing’ email - the sender does not have the ability to get into our email system, but can try and spoof us with a one time email that seems to be sent by ourselves.

Anyway - the IP address it was sent from has been included with our report. No doubt it will be in Belarus or similar - but we have done what we can.
Likely to be spoofing but should still be checking for unusual logon or email forwarding activity in case someone has succumbed to a phishing attack. Some of these aren’t immediately obvious but some will be exploited by setting up forwards to third party accounts that then monitor for the right time to try to make some £.