Don't Fall for This FBI Email Scam

One would think that cybercriminals would be smart enough to avoid deliberately antagonizing an organization dedicated specifically to taking them down, and yet here we are.

Credit: Mandel Ngan/AFP/Getty

(Image credit: Mandel Ngan/AFP/Getty)

A new scam going around features email messages claiming to be from the FBI, and while the scam is not particularly hard to avoid, you have to marvel at the sheer audacity of it.

This information comes from — you guessed it — the actual Federal Bureau of Investigation, courtesy of its Internet Crime Complaint Center (IC3). Users receive an email message entitled “RE: Internet Crime Victim Restitution” from an organization claiming to be the IC3. (The FBI did not specify an email address from which the scam originates, but it’s not hard to spoof something to look like a government communication.)

Interestingly, the scam doesn’t try to accuse the user of owing money or performing some kind of unlawful action, like the ubiquitous IRS scam. Instead, the bogus message claims that the FBI has caught a prominent Nigerian scammer, and that the user may be entitled to restitution from the man who chopped their dollars. (A variation on the scam simply suggests that the user may be a victim of “federal cyber crime.”) All the user has to do is download a form, fill it out and return it.

MORE: Protect Your Computer with This One Simple Trick

The form appears to be an attached .TXT file, but — surprise — it’s just malware. The FBI didn’t specify what kind (or how a simple text file can have malware embedded), but most modern malware either logs your keystrokes, gives a remote user control of your machine, drafts your computer into a botnet, uses your computer's CPU to "mine" cryptocurrency or locks up your hard drive and demands a ransom; take your pick. The bottom line is that you don’t want it.

The only interesting flourish is that some of the emails link to legitimate websites that document real-life FBI cybercrime busts. It’s an interesting way to build a reader’s confidence in the message, but the stilted grammar and shaky grasp of American legality will probably still raise a few eyebrows.

If anything, it’s a little disappointing that a scam that aims so high is really just another way to spread run-of-the-mill malware among credulous email checkers. Still, the FBI is not amused that cybercriminals are leveraging its good name to do the very thing that the organization tries to prevent. The FBI encourages anyone affected by the scam to log a complaint at the IC3 website, which could help its investigators track down the perpetrators.

The lesson, as usual, is to not download attachments from email addresses you don’t know, even (especially!) if they claim to be government agents. I am not familiar with any government organization that sends unsolicited emails with attachments, and while the FBI probably has your best interest in mind, it’s not about to start paying with recovered scammer assets.

TOPICS
Marshall Honorof

Marshall Honorof is a senior editor for Tom's Guide, overseeing the site's coverage of gaming hardware and software. He comes from a science writing background, having studied paleomammalogy, biological anthropology, and the history of science and technology. After hours, you can find him practicing taekwondo or doing deep dives on classic sci-fi. 

Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
  • cleavisnowell
    The other malware scam that is making the rounds is phony surveys pretending to be for Amazon offering $50.00 to $100.00 for completing it. I hate Amazon and have clicked at least 20 such scams as spam the last month.
    Reply