I get these once in a while - emails from admin@domain.com
Question asked by Michael Luer - Today at 1:12 PM
Unanswered
Once in a while I get fishing emails and hacker threats.  I don't think they have legitimate access but they seem to be able to send emails to admin addresses. emails like this one:

Hi there!
 
I am a professional hacker and have successfully managed to hack your operating system.
 Currently I have gained full access to your account. 

In addition, I was secretly monitoring all your activities and watching you for several months. 
The thing is your computer was infected with harmful spyware due to the fact that you had visited a website with porn content previously. 
  
 
Let me explain to you what that entails. Thanks to Trojan viruses, I can gain complete access to your computer or any other device that you own.
 It means that I can see absolutely everything in your screen and switch on the camera as well as microphone at any point of time without your permission. 
In addition, I can also access and see your confidential information as well as your emails and chat messages.
 
You may be wondering why your antivirus cannot detect my malicious software. 
Let me break it down for you: I am using harmful software that is driver-based, 
which refreshes its signatures on 4-hourly basis, hence your antivirus is unable to detect it presence.
 
I have made a video compilation, which shows on the left side the scenes of you happily masturbating, 
while on the right side it demonstrates the video you were watching at that moment..
.
 
All I need is just to share this video to all email addresses and messenger contacts of people you are in communication with on your device or PC. 
Furthermore, I can also make public all your emails and chat history.
 
I believe you would definitely want to avoid this from happening. 
Here is what you need to do - transfer the Bitcoin equivalent of 850 USD to my Bitcoin account 
(that is rather a simple process, which you can check out online in case if you don't know how to do that).
 
Below is my bitcoin account information (Bitcoin wallet): bc1qhsqy6h0hyc2f2ss77numuks6m00qpm3lku8x8g
 
Once the required amount is transferred to my account, I will proceed with deleting all those videos and disappear from your life once and for all. 
Kindly ensure you complete the abovementioned transfer within 50 hours (2 days +). 
I will receive a notification right after you open this email, hence the countdown will start.
 
Trust me, I am very careful, calculative and never make mistakes.
 If I discover that you shared this message with others, I will straight away proceed with making your private videos public.
 
Good luck!

================

its from and to it'self.  example: admin@mike.com to admin@mike.com  There use to be emails directly to people from esample: admin@mike.com to mike@mike.com but that stopped a year ago.  Only this combination identified above recently.   

Any thoughts?  do they have access?  I changed all the passwords out of caution and have authentication turned on for sending emails.    Like I said I don't think they have access but these are still coming in .  

Thanks,
Mike

Zach Sylvester Replied
Employee Post
Hey Michael,

Could you share the header from that email?

Thank you.

Zach Sylvester

Software Developer
SmarterTools Inc.
Michael Luer Replied
Received: from 46-10-251-32.ip.btc-net.bg (46-10-251-32.ip.btc-net.bg) by mail.elinkworld.com with SMTP;
   Wed, 2 Sep 2026 11:46:47 -0700
From: <admin@johnluerstudios.com>
To: <admin@johnluerstudios.com>
Subject: Your personal data has leaked due to suspected harmful activities.
Date: Wed, 2 Sep 2026 14:34:45 -0700
Message-Id: <CF3DF43CDA06F512E029E107DB28CF3D@GXJDMCAJ>
MIME-Version: 1.0
Content-Type: multipart/alternative;
    boundary="----=_NextPart_000_01ED_01DD3AEB.262A39D0"
X-Priority: 3
X-MSMail-Priority: normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MessageSniffer-ResultCode: 53
X-CTCH-RefID: str=0001.0A2D033E.6A986F24.0057,ss=4,re=0.000,recu=0.000,reip=0.000,pt=R_50590271,cl=4,cld=1,fgs=0
Authentication-Results: spool.www.elinkworld.com; iprev=pass (46.10.251.32); spf=neutral reason="[no matches for 46.10.251.32]; all result of Neutral observed"; dkim=none; dmarc=pass
X-SmarterMail-SpamAction: None | NoAction
X-SmarterMail-TotalSpamWeight: 0 (Trusted Sender - System)
X-SmarterMail-SpamDetail: 1.2 BODY_URI_ONLY Message body is only a URI in one line of text or for an image
X-SmarterMail-SpamDetail: 0.3 PDS_BTC_MSGID Bitcoin ID with T_MSGID_NOFQDN2
X-SmarterMail-SpamDetail: 2.6 DOS_OE_TO_MX Delivered direct to MX with OE headers
X-SmarterMail-SpamDetail: 0.5 BITCOIN_XPRIO Bitcoin + priority
X-SmarterMail-SpamDetail: 3.0 BITCOIN_DEADLINE BitCoin with a deadline
X-SmarterMail-SpamDetail: 0.0 URI_ONLY_MSGID_MALF URI only + malformed message ID
X-SmarterMail-SpamDetail: 0.0 TVD_RCVD_IP Message was received from an IP address
X-SmarterMail-SpamDetail: 0.0 HTML_MESSAGE HTML included in message
X-SmarterMail-SpamDetail: 2.4 RDNS_NONE Delivered to internal network by a host with no rDNS
X-SmarterMail-SpamDetail: 0.2 ADVANCE_FEE_5_NEW Appears to be advance fee fraud (Nigerian 419)
X-SmarterMail-SpamDetail: 0.0 MIMEOLE_DIRECT_TO_MX MIMEOLE + direct-to-MX
X-SmarterMail-SpamDetail: 0.5 PDS_BTC_ID FP reduced Bitcoin ID
X-SmarterMail-SpamDetail: 0.6 XPRIO Has X-Priority header
X-SmarterMail-SpamDetail: 0.0 HDR_ORDER_FTSDMCXX_DIRECT Header order similar to spam (FTSDMCXX/boundary variant) + direct-to-MX
X-SmarterMail-SpamDetail: 0.0 HDR_ORDER_FTSDMCXX_NORDNS Header order similar to spam (FTSDMCXX/boundary variant) + no rDNS
X-SmarterMail-Spam: DMARC [passed]: 0, Reverse DNS Lookup [Passed]: 0, Null Sender: 0, Cyren [Confirmed]: 40, CyrenIP [LOW]: 0, Message Sniffer [code:53]: 30, ISpamAssassin [raw:11.3]: 17, SPF [Neutral]: 0, DKIM [None]: 5, _ARC: none, Spamhaus - PBL, Spamhaus - PBL2, Spamhaus - SBL, Spamhaus - XBL, Spamhaus - XBL2: 0, UCEProtect Level 1: 1, SORBS - Abuse, SORBS - Dynamic IP, SORBS - Proxy, SORBS - Socks: 0, UCEProtect Level 2: 2, UCEProtect Level 3: 0, HostKarma - Blacklist, HostKarma - Brownlist, HostKarma - Whitelist: 0, SpamCop: 0, URIBL, URIBL: 0, SURBL: 0
X-MessageSniffer-Identifier: D:/SmarterMail/Spool/SubSpool3/1475751877110.eml
X-GBUdb-Analysis: 0, 46.10.251.32, Ugly c=0 p=0 Source New
X-MessageSniffer-Scan-Result: 53
X-MessageSniffer-Rules: 53-2386360-395-433-m
    60-2149822-396-433-m
    60-2573797-972-994-m
    53-2212980-969-1032-m
    53-1818669-2584-2602-m
    60-2573797-3752-3774-m
    53-2212980-3749-3812-m
    53-1818669-8208-8226-m
    53-2386360-0-11544-f
X-SpamFoo-Classification: primary
X-Forwarded-To: webmaster@elinkworld.com
X-OriginalSender: admin@johnluerstudios.com
X-ForwardingAddress: admin@johnluerstudios.com
Thread-Index: AQOgWLjD9+nxxlmi8PkmnrfINc+97g==
X-OlkEid: 0000000024CFEC6AF596E543A6C0FFF85624B2BE0700C3B68E10F77511CEB4CD00AA00BBB6E600000000000C000028314191619394458CA04AAFE80F91B4000000000449000056113706EF1BFD48B53F6B18B372B062
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180

Reply to Thread

Enter the verification text