Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

InfoSecure AI Fake Vulnerability Notification Scam: Coerced Purchase of Annual Protection Services

The victims are technical and security leads of small and medium-sized enterprises, particularly IT procurement managers who lack internal security resources, have limited awareness of AI tools, and fear the liabilities associated with high-risk vulnerabilities. Upon receiving forged vulnerability report emails containing CVE identifiers not found in public databases and urgent messaging demanding an 'immediate subscription upgrade,' they often choose to pay rather than verify. A typical loss involves being forced to purchase so-called annual security services—for instance, a local financial enterprise was defrauded of 3 million RMB. Additionally, downloading 'patch packages' may lead to remote control and data leakage.

SCAM

Key Fields

FIELD STAMPS
IndustryContent / Creator Economy
RegionChina(China)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The victims are technical and security leads of small and medium-sized enterprises, particularly IT procurement managers who lack internal security resources, have limited awareness of AI tools, and fear the liabilities associated with high-risk vulnerabilities. Upon receiving forged vulnerability report emails containing CVE identifiers not found in public databases and urgent messaging demanding an 'immediate subscription upgrade,' they often choose to pay rather than verify. A typical loss involves being forced to purchase so-called annual security services—for instance, a local financial enterprise was defrauded of 3 million RMB. Additionally, downloading 'patch packages' may lead to remote control and data leakage.

骗局怎么运作

  • Send forged vulnerability report emails attached with fake vulnerability scanner reports in official vendor formats, claiming high-risk vulnerabilities have been discovered and providing remediation guidelines.
  • Embed fake links in the emails to trick recipients into downloading 'patch packages' or opening links, which are actually remote control or information-gathering programs.
  • Subsequently offer 'aggregated protection' under the pretext of an urgent need for annual security services, emphasizing that 'the newly updated AI platform has just been compromised and subscriptions must be upgraded immediately.'
  • Use AI text generation to create forged technical white papers and guarantees to enhance credibility, claiming partners possess government security certifications.
  • After receiving payment, delete or tamper with the report contents while continuing to provide 'technical support' to help the client deploy 'official patches' within internal systems—which is actually an ongoing extortion tactic.

红旗信号(看到这些快跑)

  • 🚩 Report attachments use trademarks or official logos, but the domain names do not match official ones.
  • 🚩 Emails contain a vast amount of technical details whose sources cannot be verified through public channels.
  • 🚩 The mentioned vulnerability numbers or CVE IDs are not cataloged in public databases.
  • 🚩 The service fee breakdown differs drastically from regular security vendor pricing, yet claims to be 'instantly recovered through successive revisions' without providing itemized billing.
  • 🚩 The sender address is from a randomly generated domain or uses regulatory agency domain spoofing occasionally employed by mainland threat intelligence platforms.

真实案例

  • In February 2025, the Supreme People's Court released 6 typical cases of punishing cyber extortion crimes according to law. Among them, the case of Luo et al. showed that between November 2019 and February 2022, Luo registered a company and conspired with others to extort money by publishing negative enterprise news via self-media. Between March and July 2022, they published negative posts about 6 internet enterprises and threatened not to delete them unless business cooperation fees were paid, extorting a total of 296,000 RMB from the victim units. The court convicted Luo of extortion, sentencing him to three years and ten months in prison and a fine of 50,000 RMB. (Source: [https://www.court.gov.cn/zixun/xiangqing/454581.html](https://www.court.gov.cn/zixun/xiangqing/454581.html))
  • Typical cyber extortion cases released by the Supreme People's Court in February 2025 also include the case of Xiang et al.: Between January 2021 and April 2023, defendant Xiang purchased food on multiple online delivery platforms, planted foreign objects in them, and subsequently took photos to report to the platforms and merchants. Threatening complaints if compensation was not paid, Xiang successively extorted a total of 3,169 RMB from 4 catering shops. The court ruled that this behavior constituted the crime of extortion. (Source: [https://www.court.gov.cn/zixun/xiangqing/454581.html](https://www.court.gov.cn/zixun/xiangqing/454581.html))
  • Typical cyber extortion cases released by the Supreme People's Court in February 2025 also include the case of Zhao et al.: Between July and August 2020, defendant Zhao added over 40 minor females aged 14 to 18 as friends on QQ, threatened to go to the victims' schools and homes with knives to stab them, and demanded money for medical treatment. Zhao successively extorted a total of 18,964 RMB from 4 victims. After the case came to light, Zhao returned the illegal gains and obtained forgiveness. The court ruled that this behavior constituted the crime of extortion. (Source: [https://www.court.gov.cn/zixun/xiangqing/454581.html](https://www.court.gov.cn/zixun/xiangqing/454581.html))

Official Stance

  • Issued the 'Notice on Risk Prevention of Fake Cybersecurity Vulnerability Reports'
  • Released the 'Cybersecurity Red Alert Announcement' emphasizing not to pay annual security service fees to untrusted institutions
  • Published the 'Cyber Fraud Case Tracking Report' containing cases of fake vulnerability report scams

How to Protect Yourself

  • ✅ Verify whether email senders genuinely originate from known security vendors, and use official channels to check report sources.
  • ✅ Cross-reference CVE numbers, impact scopes, and remediation methods in received vulnerability reports against public databases.
  • ✅ Adopt multi-factor authentication and email security gateways to filter suspicious attachments and links.
  • ✅ Establish internal vulnerability assessment processes to avoid responding to 'immediate patching' demands with direct payments.
  • ✅ Regularly audit procurement contracts to confirm that service terms align with technical specifications.