The link between passwords and sextortion

1 September 2018 Editor's Choice, Information Security

In recent weeks we have seen a massive increase in the number of sextortion attempts with SA’s press shining a spotlight on this increasing social media scourge.

Trusting people, looking for the perfect match, bored partners, or undercover porn viewers are being increasingly targeted by groups of people who work on insecurities, naïvety and poor cybersecurity behaviour to coerce unsuspecting victims into parting with their money in order to prevent public humiliation and embarrassment.

I have seen several versions of the attack, some via WhatsApp and other via email.

The WhatsApp variety is very common; boy meets girl by swiping right. The match is made and introductory texts are exchanged. Almost immediately the beautiful girl shares intimate pictures and asks for the same in return. There is an almost aggressive exchange to ensure that the unsuspecting victim sends compromising photos that include showing their face.

Almost immediately the attacker reveals his/her true intentions and threatens to put the risqué nudes on the Internet, being sure to name the victim’s family members and work colleagues with whom they intend to share the photos. Using information gathered from the texting – they identify victims’ social media accounts and in certain instances, use these details to compromise or hack their accounts. Once the bait is taken they move quickly to reel in their prey.

The tone is menacing and becomes increasingly urgent as they intimidate with threats of exposure and public humiliation. The modus operandi is pretty much always the same – demands for money in order to delete victims’ photos, mostly through eWallet or untraceable money transfers performed at retail stores.

Another alarming trend is for attackers to use compromised and leaked passwords that are easily available on the dark web and cyber underground. The would be attacker then utilises a free email service to deliver the news that they have the victim’s password and have accessed their online activities. This becomes a problem if the attacker has not only accessed the victim’s activities on an adult website or recorded adult videos but has also activated their webcam. The next step is extortion or face public exposure via videos of the victim watching porn.

These messages are mostly poorly written, lack basic grammar and for the most part are identical. It only takes a very small hit rate to ensure a lucrative return. Once you make the payment – they get rid of the pay as you go sim card and move to the next victim.

An extract of one of these emails is below:

Let’s get directly to the point. Nobody has paid me to check about you. You may not know me and you’re most likely wondering why you are getting this mail?

Well, I actually installed a malware on the xxx streaming (adult porn) web-site and you know what, you visited this website to experience fun (you know what I mean). While you were viewing video clips, your Internet browser started operating as a Remote Desktop with a keylogger which gave me access to your display screen as well as Web camera. Just after that, my software gathered all of your contacts from your Messenger, FB, and e-mail account. After that I made a double-screen video. 1st part shows the video you were viewing (you’ve got a nice taste : )), and 2nd part shows the recording of your cam, and it is you.

You have just two choices. Why don’t we check out each of these solutions in aspects?

1st choice is to dismiss this email message. In this instance, I am going to send your tape to almost all of your contacts and also just consider about the shame that you receive. Furthermore should you be in a romantic relationship, precisely how it is going to affect?

Number 2 option should be to pay me $1000. We are going to think of it as a donation. In this situation, I will instantaneously delete your video. You will keep going on daily life like this never occurred and you will never hear back again from me.

You’ll make the payment by Bitcoin (if you don’t know this, search “how to buy bitcoin” in Google).

There are numerous ways to combat this, the simplest being to ensure that you stay far away from any illicit websites and another is to ensure that you change your passwords regularly and please do not use the same password on every site, platform and computer.

But above all never take compromising selfies, because, like passwords, they should never be shared.

For more information contact J2 Software, +27 87 238 1870, [email protected], www.j2.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Data resilience at VeeamON
Technews Publishing SMART Security Solutions Infrastructure Information Security
SMART Security Solutions attended the VeeamON Tour in Johannesburg in August to learn more about data resilience and Veeam’s initiatives to enhance data protection, both on-site and in the cloud.

Read more...
Get the AI fundamentals right
Technews Publishing SMART Security Solutions Leaderware Editor's Choice Surveillance AI & Data Analytics
Much of the marketing for CCTV AI detection implies the client can just drop the AI into their existing systems and operations, and they will be detecting all criminals and be far more efficient when doing it.

Read more...
SMART Surveillance Conference in Johannesburg
Arteco Global Africa Technews Publishing SMART Security Solutions Axis Communications SA neaMetrics Editor's Choice Surveillance Security Services & Risk Management Logistics (Industry) AI & Data Analytics
SMART Security Solutions hosted its annual SMART Surveillance Conference in Johannesburg in July, welcoming several guests, sponsors, and speakers for an informative and enjoyable day examining the evolution of the surveillance market.

Read more...
Secure data protection without hardware lock-in
Infrastructure Information Security News & Events
New Veeam Software Appliance empowers IT teams to achieve instant protection with Veeam’s fully preconfigured, software-only appliance, delivering enterprise-ready simplified deployment and operational efficiency, robust cyber resilience.

Read more...
South African fire standards in a nutshell
Fire & Safety Editor's Choice Training & Education
The importance of compliant fire detection systems and proper fire protection cannot be overstated, especially for businesses. Statistics reveal that 44% of businesses fail to reopen after a fire.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
LidarVision for substation security
Fire & Safety Government and Parastatal (Industry) Editor's Choice
EG.D supplies electricity to 2,7 million people in the southern regions of the Czech Republic, on the borders of Austria and Germany. The company operates and maintains infrastructure, including power lines and high-voltage transformer substations.

Read more...
Standards for fire detection
Fire & Safety Associations Editor's Choice
In previous articles in the series on fire standards, Nick Collins discussed SANS 10400-T and SANS 10139. In this editorial, he continues with SANS 322 – Fire Detection and Alarm Systems for Hospitals.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.