Attack Type: Extortion

Extortion attacks use fear and intimidation to pressure you into paying money or handing over sensitive information. These emails often claim the sender has access to private data, recordings, or control over your systems and threaten to release it unless you comply. The goal is to scare you into acting quickly, usually by demanding payment in cryptocurrency.
Sextortion is a common version, where attackers claim to have recorded you through your webcam and threaten to share the footage unless you pay. To make the threat more believable, they might include a password from an old data breach or refer to a personal detail scraped from the web.
Other versions can be more extreme, such as threats of physical harm, fake hitman contracts, or warnings that your company will be taken offline in a DDoS attack. While most of these messages are completely fake, they’re designed to feel personal and urgent. Even when they’re not real, they can cause real anxiety. That’s why it’s important to report them and avoid responding or paying.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Extortion / sextortion (untrusted sender)
20h ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-untrusted-sender-265913eb
Potential prompt injection attack in body HTML
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/potential-prompt-injection-attack-in-body-html-5fb24736
Suspicious Links to Cloudflare R2 and Edge Services
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/suspicious-links-to-cloudflare-r2-and-edge-services-5dd3e5c8
Attachment: Legal themed message or PDF with suspicious indicators
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-legal-themed-message-or-pdf-with-suspicious-indicators-19133301
Service Abuse: GoDaddy infrastructure
16d ago
Jan 7th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-godaddy-infrastructure-8a2dd357
Brand impersonation: Vanguard
4mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-vanguard-3bd048fe
Extortion / sextortion in attachment from untrusted sender
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-in-attachment-from-untrusted-sender-3cb8d32c
Encrypted Microsoft Office files from untrusted sender
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/encrypted-microsoft-office-files-from-untrusted-sender-eb7b26e7
Mismatched links: Free file share with urgent language
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/mismatched-links-free-file-share-with-urgent-language-478334c8
Brand impersonation: WeTransfer
5mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-wetransfer-e37885ad