Bitcoin Scam Attempt: How a Script Kiddy Tried to Extort Me for $200
Online scams are everywhere - phishing emails, fake logins, ransomware, and extortion schemes. Sometimes the attackers aren't sophisticated cybercriminals. Sometimes they're just script kiddies - amateurs who copy tools they don't fully understand.
Here's the story of how one of them tried to extort me for $200 in Bitcoin, what happened to a friend who tested the file in a VM, and what you can do to stay safe.
The Bitcoin extortion email
"you have to pay 200 dollars if you want ur stuffs back and stay alone"
The sender called themselves yakuza haha. Instead of panicking, I replied with short, unhelpful answers like "why?" or "I have to go back to work." The intimidation fell apart quickly - there was no real leverage behind the threats.
Inside the extortion emails
Here's a snapshot of the actual exchange I had with the scammer:
Scammer: "You have to pay 200 dollars if you want your stuffs back and stay alone."
Me: "Why?"
Scammer: "Are you going to pay or not?"
Me: "I have to go back to work."
That was the entire level of sophistication. No technical detail, no leverage - just repetition and pressure. It shows how these scams work: they hope fear will do the job for them.
When my friend got caught anyway
One of my friends did get scammed by the same person. He opened the malicious file inside a virtual machine (VM) - a sandbox many tech folks use to test suspicious software - and still ran into issues. He trusted me. So he ran it on his own computer because on the VM it wasn't working.... Moral of the story: even if you're being careful, things can go wrong. You really gotta be careful. Don't trust your friends online with files!
What is a VM?
A Virtual Machine is basically a computer inside your computer. It creates a sandboxed environment where software runs isolated from your main system. It helps - but it isn't a silver bullet. Some malware can detect VMs or exploit misconfigurations. Learn more on Wikipedia.
Lessons learned
- Don't panic, don't pay. Fear is the whole playbook. Paying once marks you as a target.
- Harden accounts. Use a password manager, unique passwords, and 2FA everywhere.
- Backups win. Regular offline backups beat ransomware and extortion.
- VMs are magic. Useful, yes. Perfect, no. Treat them as one layer of defense.
- Document everything. Save emails, headers, screenshots, and file hashes if possible.
Tracking the scammer
The attacker wasn't very smart about covering their tracks. From my account security logs, I could see a successful sign-in from Turkey (IP address: 88.230.180.122, using Chrome on Windows). They even passed part of a password reset challenge - proof this wasn't just empty threats.
I reported the incident to the police, but unfortunately, nothing came of it. The case went nowhere.
The Turkish Police told me to contact the Turkish Consulate, which then told me to contact Turkish lawyers… it was never-ending. Lawyers never replied, and this is where it stands today: unreplied e-mails.
I warned my friends, so they removed my accounts from Discord and put me on silence on various platforms. If you get hacked on one platform, make sure you can still reach your friends on others - that way you can alert them, secure your account, and protect others from being scammed by your compromised profile.
On the bright side, I also reported the fake website hosting their malicious application, and the hosting provider did take it down. At least one door was closed on this scammer.
Final thoughts
In my case, the scammer failed. But my friend's experience is a reminder: even clumsy attacks can waste time or cause damage. Stay skeptical, keep things simple, and secure the basics - they matter the most.