There’s a new scam going around that would terrify most people if it ever landed in their inbox.
The emails are slightly different depending on who’s being attacked, but they all have a few similar features:
- The subject line includes a password that you probably have used at some point.
- The sender says they have used that password to hack your computer, install malware, and record video of you through your webcam.
- They say they will reveal your adult-website habits and send video of you to your contacts unless you send them bitcoin, usually $1,200 or $1,600 worth.
Here’s one example of these scam emails, sent in the past month:
The hacker just have to know the email and no need to know the password. They also can use script to send email without to key in the email password. Example here : https://www.youtube.com/watch?v=t_jCdSTlr8E
The password was probably included in one of the big leaks in the past few years – databases have been stolen from LinkedIn, Yahoo, and eBay, for example. You can check whether your password is in one of these leaked databases over at the website Have I Been Pwned.
Basically, the attackers don’t actually have video of you or access to your contacts, and they haven’t been able to install malicious code on your computer. In reality, they’re taking a password from a database that’s available online, sending it to you, and hoping you’re scared enough to believe their story and send them bitcoin.
Some scammers have even made over $50,000 from the blackmail scheme, based on an analysis of bitcoin wallets, Bleeping Computer reported.
As Brian Krebs, a leading security journalist, writes, this scam is probably automated, meaning you haven’t been specifically targeted:
“It is likely that this improved sextortion attempt is at least semi-automated: My guess is that the perpetrator has created some kind of script that draws directly from the usernames and passwords from a given data breach at a popular Web site that happened more than a decade ago, and that every victim who had their password compromised as part of that breach is getting this same email at the address used to sign up at that hacked Web site.”
For now, the scammers seem to be using really old passwords – maybe one you haven’t used in years. But as the scam develops, there’s a good chance it may include credentials from a fresh breach, according to Krebs.
Other good ideas to keep yourself safe: use long and strong passwords, get a password manager to ensure each account has a unique password, and turn on two-factor authentication on your important accounts. The FBI also recommends you turn off or cover any web cameras when you’re not using them to prevent sex-based extortion schemes, even if this kind of scam ends up being a hollow threat.
And no matter what you do, don’t send bitcoin to the scammers.