I hate to use my holiday newsletter to alert you all to a scam, but I have literally had a dozen calls about this email, so I want you to ALL know that,
although it is scary and there are some steps you should take, the email itself is a lie.
I've seen a few versions of this mail, but they all
appear to come from your own email address, and pretty much read like this (typos and all):
"Subject: Security Alert. You account has been hacked. Password (xxxxx) must be need changed.
I'm a programmer who cracked your email account and device about half year ago.
You entered a password on one of the insecure site you visited, and I catched it.
Your password from xxx on moment of crack: (xxxx)
Of course you can will change your password, or already made it.
But it doesn't matter, my rat software update it every time.
Please don't try to contact me or find me, it is impossible, since I sent you an email from your email account.
Through your e-mail, I uploaded malicious code to your Operation System.
I saved all of your contacts with friends, colleagues, relatives and a complete history of visits to the Internet resources.
Also I installed a rat software on your device and long tome spying for you.
You are not my only victim, I usually lock devices and ask for a ransom.
But I was struck by the sites of intimate content that you very often visit.
I am in shock of your reach fantasies! Wow! I've never seen anything like this!
I did not even know that SUCH content could be so exciting!
So, when you had fun on intime sites (you know what I mean!)
I made screenshot with using my program from your camera of yours device.
After that, I jointed them to the content of the currently viewed site.
Will be funny when I send these photos to your contacts! And if your relatives see it?
BUT I'm sure you don't want it. I definitely would not want to ...
I will not do this if you pay me a little amount.
I think $817 is a nice price for it!
I accept only Bitcoins.
My BTC wallet: xxxxxxx
You have 2 days (48 hours) for make a payment.
If this does not happen - all your contacts will get crazy shots with your dirty life!
And so that you do not obstruct me, your device will be locked (also after 48 hours)
Do not take this frivolously! This is the last warning!
Various security services or antiviruses won't help you for sure (I have already collected all your data).
Here are the recommendations of a professional:
Antiviruses do not help against modern malicious code. Just do not enter your passwords on unsafe sites!
I hope you will be prudent.
Bye."
If you get an email like this, please understand it is
all lies - EXCEPT for the fact that
a legit password of yours has been associated with your email address. The internet security community thinks that this occurred due to a
LinkedIn hack, but it could be any other of the myriad hacks that have made the news in the last few years.
The most important thing you can do is to change your password at any site that uses the password referenced in the letter.