Attack Type: Extortion

Extortion attacks use fear and intimidation to pressure you into paying money or handing over sensitive information. These emails often claim the sender has access to private data, recordings, or control over your systems and threaten to release it unless you comply. The goal is to scare you into acting quickly, usually by demanding payment in cryptocurrency.
Sextortion is a common version, where attackers claim to have recorded you through your webcam and threaten to share the footage unless you pay. To make the threat more believable, they might include a password from an old data breach or refer to a personal detail scraped from the web.
Other versions can be more extreme, such as threats of physical harm, fake hitman contracts, or warnings that your company will be taken offline in a DDoS attack. While most of these messages are completely fake, they’re designed to feel personal and urgent. Even when they’re not real, they can cause real anxiety. That’s why it’s important to report them and avoid responding or paying.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: Legal themed message or PDF with suspicious indicators
7d ago
Feb 5th, 2026
Sublime Security
/feeds/core/detection-rules/attachment-legal-themed-message-or-pdf-with-suspicious-indicators-19133301
Extortion / sextortion (untrusted sender)
21d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-untrusted-sender-265913eb
Suspicious Links to Cloudflare R2 and Edge Services
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/suspicious-links-to-cloudflare-r2-and-edge-services-5dd3e5c8
Potential prompt injection attack in body HTML
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/potential-prompt-injection-attack-in-body-html-5fb24736
Service Abuse: GoDaddy infrastructure
1mo ago
Jan 7th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-godaddy-infrastructure-8a2dd357
Brand impersonation: Vanguard
4mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-vanguard-3bd048fe
Brand impersonation: WeTransfer
6mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-wetransfer-e37885ad
Encrypted Microsoft Office files from untrusted sender
6mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/encrypted-microsoft-office-files-from-untrusted-sender-eb7b26e7
Extortion / sextortion in attachment from untrusted sender
6mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/extortion-sextortion-in-attachment-from-untrusted-sender-3cb8d32c
Mismatched links: Free file share with urgent language
6mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/mismatched-links-free-file-share-with-urgent-language-478334c8