AI-Forged DDoS Extortion Scam: Impersonating Hackers to Launch Paralysis Tests and Force Small and Medium Enterprises to Pay Protection Fees
Victims are primarily SMEs that lack dedicated cybersecurity teams and rely heavily on online businesses or digital infrastructures, such as cross-border e-commerce sellers, independent website developers, and local service organizations. Their psychological vulnerabilities stem from a lack of understanding of underlying technical details, severe panic when business suddenly paralyzes, and limited IT emergency response capabilities. Prompted by extortion letters written with generative AI that are highly misleading, they often prefer to pay the so-called defense fee to avoid business shutdowns and reputational damage caused by customer data leaks.
Key Fields
FIELD STAMPSWho Gets Targeted
Victims are primarily SMEs that lack dedicated cybersecurity teams and rely heavily on online businesses or digital infrastructures, such as cross-border e-commerce sellers, independent website developers, and local service organizations. Their psychological vulnerabilities stem from a lack of understanding of underlying technical details, severe panic when business suddenly paralyzes, and limited IT emergency response capabilities. Prompted by extortion letters written with generative AI that are highly misleading, they often prefer to pay the so-called defense fee to avoid business shutdowns and reputational damage caused by customer data leaks.
骗局怎么运作
- Attackers use generative AI tools to automatically crawl and analyze public information of potential target enterprises, including their business system IP addresses, server architectures used, and exposed security vulnerabilities, subsequently generating a customized threat analysis report targeting the enterprise's weaknesses to provide data support and messaging for subsequent precision extortion.
- Attackers send extortion letters to enterprise heads via anonymous email channels, disguising the emails as well-known overseas hacker organizations. The letters are generated by AI in multiple language versions to increase realism. They claim to have controlled the enterprise's core servers and obtained sensitive data, attaching AI-generated system screenshots or forged stolen data samples as evidence.
- To prove that the attack capability is not a bluff, criminals mobilize botnets to launch short but intensive DDoS paralysis tests against the victim enterprise's servers, causing severe lagging or even short-term downtime on the enterprise's official website or core business, thereby creating substantive panic and forcing the enterprise to confirm the authenticity of the threat.
- After creating panic, attackers demand enterprises pay cryptocurrency within a limited time as a defense fee or data protection fee. The emails embed detailed cryptocurrency wallet addresses and payment guides, threatening that if payment is refused, an unbearable large-scale DDoS attack will be launched or the stolen database will be publicly leaked on hacker forums.
- Attackers use AI to generate collection emails with countdown mechanisms to continuously exert psychological pressure, claiming that only a few hours remain before the system is completely paralyzed. Once victims pay the first fee, criminals often continue to extort them under names such as system cleanup fees or complete data destruction fees, falling into an endless vicious cycle.
红旗信号(看到这些快跑)
- 🚩 Receiving strange English emails claiming to be well-known hacker organizations, with body content that is highly specialized and features stiff phrasing generated by AI translation, claiming to have invaded the system and mastered the core database.
- 🚩 Extortion letters accurately mention the enterprise's real existing server IP addresses, recent system error logs, or partial real customer data to corroborate their network penetration lies.
- 🚩 Demanding ransom to be paid via cryptocurrencies such as Bitcoin or Tether within a very short time, with amounts set just within what the enterprise can barely afford to prompt a quick compromise.
- 🚩 Experiencing severe website access lagging or temporary server downtime around the time the email is received, followed immediately by a secondary extortion letter under the name of a defense test.
- 🚩 Attackers refuse to communicate through regular security audit channels, providing only a single cryptocurrency wallet address and threatening to immediately upgrade attack destructiveness if help is sought from police or security vendors.
真实案例
- According to a report by People's Daily in August 2026, SMEs in multiple regions received extortion emails disguised as overseas hackers. The other party claimed to have mastered the enterprise database and conducted DDoS attack tests, demanding several Bitcoins as a defense fee. A development company fell into panic due to short-term server paralysis and was forced to transfer cryptocurrency worth over twenty thousand dollars to a designated wallet.
- According to disclosures by Tencent Cloud Developer Community, a small software service provider encountered extortion in 2026 by someone claiming to be a well-known cybercrime syndicate. The other party used generative AI to send a highly customized threat letter, claiming to have implanted a mining trojan and ready to launch DDoS attacks at any time, forcing the enterprise to pay protection fees monthly to maintain system stability.
- According to a security early warning notice by Ningbo Network in August 2026, multiple domestic enterprises encountered new types of ransomware and bullying activities accompanied by DDoS threats. An e-commerce enterprise received an AI-customized extortion letter attached with system vulnerabilities, and the other party claimed that if the defense fee was not paid, continuous attacks would be launched. The enterprise preserved evidence and reported it to public security cyber security departments.
- In June 2020, Pan, a technician from a company in Beijing, threatened to continue network attacks if Bitcoin was not paid, sending extortion emails to multiple victimized units and launching cyberattacks. The victim units were forced to buy Bitcoin, suffering a total loss equivalent to 234,961 yuan. The Haidian Court sentenced him to 3 years in prison for extortion and fined him 5,000 yuan. (Source: [https://m.thepaper.cn/newsDetail_forward_7709407](https://m.thepaper.cn/newsDetail_forward_7709407))
- In December 2015, Europol announced the crackdown on the DD4BC gang that extorted Bitcoin using Distributed Denial of Service attacks. The cybercrime division of the Metropolitan Police Service in London tracked and confirmed that key members of the organization were hiding in Bosnia and Herzegovina, and finally arrested two criminal suspects on December 15 and 16, 2015, with one identified as the mastermind and a large amount of evidence seized. (Source: [https://www.aeys.org/1735.html](https://www.aeys.org/1735.html))
Official Stance
- In July 2026, the National Computer Network Emergency Response Technical Team issued a cybersecurity early warning, pointing out that ransomware and DDoS extortion attacks targeting Linux servers happen frequently, and strongly recommending SMEs to strengthen network-layer protection and regular data backups.
- In August 2026, Xinhuanet jointly with cybersecurity departments across multiple regions issued a security early warning, reminding enterprises to guard against a new type of ransomware called Sorry and extortion activities accompanied by DDoS threats, and not to trust transfer requests easily.
- In July 2026, Kaspersky released a security report pointing out that in 2026, malware attacks targeting SMEs disguised as AI services surged fivefold, including a large number of new cyber extortion cases utilizing generative AI tools to customize extortion letters.
How to Protect Yourself
- ✅ Do not panic and pay when receiving an extortion email; immediately isolate affected servers and check system network logs to confirm whether there are actual data leaks or substantial system intrusion traces.
- ✅ Deploy basic high-defense IP or DDoS native protection services from cloud service providers, set traffic scrubbing thresholds, and ensure automatic interception of abnormal traffic when facing business peaks or small paralysis tests.
- ✅ Perform cold backups and off-site disaster recovery backups of core business data regularly, and verify the availability of backup data to ensure system operations can be restored in a short time even when facing extreme extortion attacks.
- ✅ Conduct employee cybersecurity awareness training, establish a standardized emergency response SOP for extortion incidents, retain email evidence at the first instance when encountering similar situations, and contact professional cybersecurity institutions to assist with investigations.
- https://www.cnr.cn/mspd/sywzl/20260818/t20260818_527780724.shtml
- https://www.cert.org.cn/publish/main/10/2026/20260727185721857549342/20260727185721857549342_.html
- https://news.iresearch.cn/yx/2026/07/559959.shtml
- https://cloud.tencent.com/developer/article/2694148
- http://society.people.com.cn/n1/2026/0804/c1008-40773509.html
- http://news.cnnb.com.cn/system/2026/08/10/030802544.shtml