Skip to content

Scam warning: fake 'abuse department' extortion

General Discussion by tomhider 3 replies 140 views
#1

The abuse deparmtent emial looked soo real man. Got this thing sayin my servver was hostin phishing and I had 24hrs to pay 0.5BTC or theyd termiante the acccount. The headeres looked legit tho, came from sum abuse@ thing that looked like my host. I almsot panicked but then I was like waiit I dont even have a server at that host lol. The whole thing was sent to my gmails so howd they get that. Anyway I forwaded it to the real host and they said yea its fake but weve seen a bunch of these. Be careful out tere. No I wont fix typos you figure it out

[code]Received: from mx-backup3.example.com (mx-backup3.example.com [203.0.113.47])
By mail-gateway with ESMTP id 4A2B1C
For <[email protected]>; Thu, 02 Jan 2026 09:14:22 +0000
Received: from unknown (HELO abuse-alert.local) (10.244.16.88)
By mx-backup3.example.com with ESMTP; Thu, 02 Jan 2026 09:12:07 +0000
From: "Abuse Department" <[email protected]>
Reply-To: "Urgent Response" <[email protected]>

#2

I GOT ONE OF THESE TOO AND I ALMOST FELL FOR IT EXCEPT I REMEMBERED THAT I HAD OATMEAL WITH BLUEBERRIES FOR BREAKFAST THAT MORNING AND MY CAT MR WHISKERS WAS SITTING ON THE KEYBOARD LIKE HE ALWAYS DOES WHEN IM TRYING TO WORK AND THE WEATHER WAS FREEZING COLD WITH THAT WET SNOW THAT GETS EVERYWHERE AND I THOUGHT TO MYSELF WAIT A MINUTE I DONT EVEN HAVE AN ACCOUNT WITH THESE PEOPLE AND I STARTED LOOKING AT THE HEADERS AND I NOTICED THE REPLY-TO WAS DIFFERENT AND THE SPF FAILED AND I WAS SO MAD BECAUSE I SPENT LIKE AN HOUR ON THIS WHEN I SHOULD HAVE BEEN FIXING MY ACTUAL SERVER WHICH IS AT CONTABO https://contabo.com AND THEYRE FINE BY THE WAY AND I TRIED TO TELL MY NEIGHBOR WHO ALSO HAS A WEBSITE AND SHE DIDNT EVEN READ THE WHOLE THING SHE JUST SAID OH THATS NICE AND WALKED AWAY AND I WAS LIKE YOU DIDNT EVEN READ IT DID YOU AND SHE SAID NO AND I GOT SO FRUSTRATED BECAUSE I WROTE ALL OF THAT FOR A REASON AND THE THING IS THESE SCAMMERS ARE GETTING BETTER AND BETTER AND THEYRE USING REAL COMPROMISED SERVERS AS RELAYS SO THE FIRST FEW HOPS LOOK LEGITIMATE AND THATS WHAT MAKES IT SO DANGEROUS AND PEOPLE NEED TO CHECK THE REPLY-TO AND THE RETURN PATH AND VERIFY INDEPENDENTLY AND NOT JUST CLICK LINKS IN EMAILS AND I CANT BELIEVE I HAVE TO SAY THIS BUT HERE WE ARE AND MY CAT IS STILL STARING AT ME JUDGMENTALLY LIKE HE KNOWS I TYPED ALL OF THIS

#3

This is very good analysis. I am check check my headers now. The scammers are using compromised server as relay is very clever but we are more clever. I make a test with my email and the SPF is fail too. Thank you for the warning. Everyone must to check the reply-to. Is very important!

ping so high I wave back
#4

Last week I receive this same thing, is it? I go go check my account and I am seeing I dont even have service with them. Now now I will tell my brother to watch out. These people are doing too much. The header trick is very wicked thing.

your margin is my opportunity

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft