Spanish cybersecurity snafu: fake police emails target victims with €5,670 extortion
A sophisticated phishing scam is preying on Spanish citizens and businesses, leveraging the authority of national law enforcement agencies – the Policía Nacional and Guardia Civil – to extract thousands of euros. Cybersecurity experts at ESET have been tracking this evolving threat for years, noting a sharp increase in its complexity and believability.
The bait: a falsified investigation
The scam begins with a carefully crafted email, impersonating a probe into the recipient's activities. The sender, seemingly originating from a Junta de Andalucía address (though a clear case of spoofing), claims that the recipient or their company is under investigation. A seemingly official document is attached, promising further details, drawing victims in with the suggestion of legal repercussions.
But this document is a meticulously constructed deception. It references real-world cybersecurity operations like Europol's “Operation Endgame” and tools used in digital forensics, such as Magnet Axiom. The inclusion of Pikabot, a known botnet, further amplifies the illusion of legitimacy. Experts at ESET explain that this deluge of technical jargon is designed to overwhelm and intimidate, prompting a panicked response.
The key tactic is fear. The email’s purpose isn't to provide information; it’s to create a sense of urgency and dread, compelling the recipient to contact the provided email address – a fraudulent gateway to the perpetrators.

The hook: a 'resolution' with a steep price
Upon contacting the fraudsters, victims are presented with a seemingly straightforward solution: pay €5,670 for a “technical and legal audit” to clear their name and avoid legal action. The attached document reiterates the gravity of the situation, referencing legal consequences and potential criminal charges. This reinforces the pressure to comply.
The con artists then request a bank transfer to a Parisian resident’s account, assuring the recipient that it will halt any “special intervention groups” from taking action. A receipt is requested to confirm the transaction. The trail, however, leads to a likely “mule” – an individual unwittingly facilitating the transfer of funds to the true perpetrators, possibly believing they're engaged in legitimate work.
What's particularly unsettling is the level of preparation. This isn’t a clumsy, poorly executed phishing attempt. The fraudsters have clearly invested significant time and effort in crafting a believable narrative, demonstrating a worrying escalation in their operational sophistication.
“It’s a stark reminder that even the most technically savvy individuals can fall victim to these scams,” cautions ESET. Authorities like the Policía Nacional and Guardia Civil urge anyone receiving a similar email to report it immediately, rather than attempting to verify its authenticity themselves.
The investigation continues, but one thing is clear: the cost of complacency in the digital age is measured not just in euros, but in the erosion of trust and the constant vigilance required to navigate an increasingly treacherous online landscape.
