Recently, another kind of email scam comes to our attention like this –
It mentioned one of your password used in the past (may be 2 years or more..)
(Below example one is NOT our password)
from Google search results, there were some similar cases available in community forum, e.g. –
- https://www.reddit.com/r/privacy/comments/9klc1q/so_i_received_a_data_blackmail_email/
- https://answers.microsoft.com/en-us/protect/forum/protect_other-protect_scanning-windows_10/email-hacked/6e4da88e-4e56-4a86-9a71-3683cc183c8c
- https://www.itsc.cuhk.edu.hk/en-gb/it-announcement/is-alerts-news-and-events/2018/884-phishing-20180928b
- https://productforums.google.com/forum/#!topic/gmail/rt8oTc1rYy0
- https://linustechtips.com/main/topic/975917-first-of-the-ncix-leaked-info-scam-letters-going-out/
- https://www.linkedin.com/pulse/criminal-has-access-my-personal-data-i-dont-know-morris-cotterill
- https://answers.yahoo.com/question/index?qid=20181023123410AA7zaIh
We believe it is a email fraud (Phishing).
Perhaps, one of the 3rd party web service you registered may be compromised and leaked the password.
(There were some reports that large cloud service provider leaked 68 million username and password)
Anyway, for your reminder – the sender address can always be fraud.
As a general guideline, for enhanced security, you may consider to
- regularly change password, and
- use strong password, and
- use SSL/TLS encrypted connection (settings refer to email notice around the end of Aug 2018), and
- use antivirus to scan and protect your desktop/notebook/tablet/mobile
- use different passwords for different purposes (e.g. email password/website registration/apps registration/…)
When SpamAssassin recognizes Bitcoin-related fake email, it will add BITCOIN_SPAM and/or BITCOIN_EXTORT scores to Spam Score.
Users can consider to add mail-rules in Outlook
If the email header or email content contains the words BITCOIN_SPAM or BITCOIN_EXTORT, then (for example) move the email to trash.
(Note: 100% accuracy is impossible for automatic detection, users can check the contents of the trash when needed)