Ransomware criminals are now sending their demands...by snail mail?

Image of laptop infected with malware
(Image credit: © Unsplash / Michael Geiger)

  • A company's executives received an extortion letter in the mail
  • It claims to have come from ransomware operators BianLian
  • The senders warned about stealing the company's sensitive files

The security world appears to have come full circle, as spam mail has once again gotten physical with scammers sending their victims snail mail.

Cybersecurity outlet GuidePoint Security recently came across a couple of these letters sent to members of the target organization’s executive team.

The letters are not your typical extinct spam, either - but claim to have been sent by the BianLian ransomware group.

There is no ransomware

“I regret to inform you that we have gained access to [REDACTED] systems and over the past several weeks have exported thousands of data files, including customer order and contact information, employee information with IDs, SSNs, payroll reports, and other sensitive HR documents, company financial documents, legal documents, investor and shareholder information, invoices, and tax documents,” the letter reads.

“Your network is insecure and we were able to gain access and intercept your network traffic, leverage your personal email address, passwords, online accounts and other information to social engineer our way into [REDACTED] systems via your home network with the help of another employee.”

The researchers said that the attacks are as fake as the letters. There is no evidence of any compromise whatsoever, and the letter’s contents bear no resemblance to the BianLian ransomware operation. Even the wording of the message is inconsistent with ransom notes BianLian was seen sending in the past, they said.

In any case, the scammers were demanding $250,000 to $350,000, to be paid in Bitcoin, within ten days. The letter also included a QR code leading to the Bitcoin address, but it’s freshly generated so it’s impossible to determine if it really belongs to BianLian or not.

The return address for the letters is in Boston, USA, and according to The Register, points to a real address for an office building.

Via The Register

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
Shutterstock.com / kanlaya wanon
Microsoft Teams abused in Russian email bombing ransomware campaign
A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag
China government-linked hackers caught running a seriously dangerous ransomware scam
Ransomware
Lee Enterprises blames cyberattack for encrypting critical systems as US newspaper outages drag on
Shopping scams
New wave of sextortion scams uses personal details and images to intimidate targets while bypassing traditional security measures
Ransomware
Healthcare firms targeted by all-new ransomware strain
Ransomware
Top ransomware gang's internal chat logs leaked online
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before