Fake "Interpol" Email Delivers Ransomware to Small Businesses

A wave of ransomware is currently targeting small businesses in Europe, starting with an email that appears to be sent by Interpol and claims that the company is under criminal investigation. Bitdefender has documented the campaign, and the pattern is easy to recognize once you know what to look for.

The message has an alarming subject line, referring to the “Interpol Cybercrime Investigation Unit,” and vaguely accuses you of suspicious activities. The vagueness is intentional: it pushes you to seek clarification quickly, without verifying the sender. The promised “evidence” is stored via a Proton Drive link, in a .rar archive whose password is written right in the email—and inside there are no files, just an executable disguised as a video clip that encrypts the company’s computers.

This combination—an accusation, a sense of urgency, and a password-protected file attached to the message—is the campaign’s hallmark. Here’s what a small business can actually do on the same day:

  • Establish a simple rule for the team: no legitimate authority sends “evidence” via password-protected links. Delete such an email; do not open it.
  • Explain the pattern to people, not just the specific case: an accusation plus a sense of urgency plus a password-protected file in the message equals a lure.
  • Check to see if you have a recent, working backup. Whether ransomware becomes a problem that lasts a few hours or a few weeks depends entirely on the answer to this question.

Fear is their tool, and a quick check can defuse it. If you’d like someone from outside the company to review your email filters and company backups, you can email us at [email protected] or call us at +40 712 605 222.

Source: Bitdefender, via Infosecurity Magazine | https://www.infosecurity-magazine.com/news/cybercriminals-pose-interpol/

This article was generated with AI assistance.

Request a quote

← All news