With the rapid development of the internet, the global community has faced the issue of data security. After all, the internet is essentially an unregulated environment, which is quite loosely governed by the laws of individual countries, opening up numerous opportunities for cybercriminals.
This is precisely why developed countries today pay significant attention and allocate millions of dollars to improve cybersecurity systems and immediate responses to cyberattacks.
However, not all companies can guarantee a high degree of data protection — it's quite expensive. Not to mention ordinary users who have no understanding of cybersecurity at all.
In this article, I want to share situations from my practice and personal experience, where even with quite serious legal support, it is impossible to protect oneself from scammers and their extortions.
Key Issues of Information and Cybersecurity
Ensuring cybersecurity is a process, not a one-time solution. While specialists deal with already known problems like viruses, ransomware bots, and zero-day threats, cybercriminals are developing new, more sophisticated, and effective tools.
Here are some of them:
- Jailbreaking — installing malicious software on smartphones with modified firmware.
- Ghostware — a virus that infiltrates the system with the aim of stealing data and self-destructs after completing its task.
- "Two-faced" viruses — programs that mimic system files and, after successfully passing antivirus checks, begin the data theft process.
And there are dozens, if not hundreds, of similar tools. Even in the most "ideal" protection, vulnerabilities are discovered that a skilled hacker can exploit to leak confidential data. Leaks periodically occur even in the Pentagon, one of the most protected structures in the world in terms of cybersecurity.
Can search engine algorithms be used to blackmail users?
But to see information security problems, one only needs to open a browser. The fact is that the amount of indexable information on the internet doubles every 1.5 years.
, by the end of 2020, the total volume of data on the internet will reach 44 zettabytes (44 billion terabytes), and search engines are already processing tens of thousands of queries per second.
Malicious actors skillfully exploit this data overload, where nearly all data is processed by the search engine without human involvement.
Here’s how it often looks.
- A fraudster creates a website aimed at tricking users out of their money. The methods can vary widely: foolproof investments, promising jobs with a 'deposit', or selling goods at rock-bottom prices. Or simply a one-page site that infects computers with a virus.
- The fraudster siphons money from trusting individuals for an average of 2 to 6 months — that’s how long it takes for search engine managers to identify the problem and ban the site.
- But this doesn't help, as on the same day, the fraudster can create a new site with similar content, continuing their criminal activities.
This is just one possible way that scammers can exploit search engine functionality, as long as a site doesn't have materials that directly violate rules (for example, plagiarized content), the site can be indexed by the search engine without issues.
Combatting such fraudsters meets with variable success. Here, the aim is to obtain small amounts of money from as many people as possible.
A completely different format is fraud targeting specific individuals. This is gaining popularity today, because it is significantly harder to curb — and not all victims of extortion know how to deal with it. Typically, the target is a fairly public businessman, whose successful operations require a crystal-clear image. These are mostly lawyers, private doctors (most often plastic surgeons), and high-paid professionals in the digital field (programmers, designers, authors).
How is this done?
- The fraudster creates dozens of identical articles with negative reviews, portraying their victim as a scammer and a poor, unreliable professional. The materials can even be generated using a bot — the quality is completely irrelevant. The key is for the search engine to index them.
- Then these reviews and materials are posted on second-rate platforms where it is easy to publish reviews and articles about anything.
- Reviews are indexed and appear in searches based on keywords. The main key is "PROFESSION FIRST NAME LAST NAME". For example, "designer Ivan Petrov" or "lawyer Petr Ivanov". Most people check information about a specialist online before starting work with them. The results are predictable — a bunch of negative reviews like "Ivan Petrov is a fraud". In most cases, a potential client is hesitant to begin cooperation.
- Then, after a month or two, when the target clearly feels the impact of black PR, they receive an email demanding a certain amount of money be paid to a bitcoin wallet or another financial service that guarantees anonymity, and then the extortionists will remove the articles (but this is not guaranteed). If they refuse to pay, the scammers promise to significantly increase the number of negative reviews.
At this point, many targets of extortion do not know what to do. There are several options:
- Contact the police. But if the perpetrator did not leave any clear evidence (such as your bank card number), the case will quickly become a deadlock.
- Contact the owners of the sites where the reviews are posted. It takes a tremendous amount of time — there could be dozens of portals. Moreover, the effectiveness is close to zero. It is far from certain that even upon hearing your arguments, the owners will agree to delete the defamation from their site. And it is not guaranteed that the owners will even respond to your request.
- Contact the support service of the search engine. Google and Yandex specialists work slowly — it can take up to several months to remove defamation, but today this is the fastest available way to combat such scammers. Yet even in this case, it is far from certain that such reviews will be deleted. Below I will explain why.
We conclude that even in the best case, the reputation of the entrepreneur will suffer serious damage, which will undoubtedly impact their income level. The scammers, while remaining anonymous, risk nothing. They only spend time generating and posting materials.
How I was blackmailed in this way
Why I even touched on this topic — just recently I was blackmailed in a similar way.
In the spring of 2018, I discovered that there were too many insults about me, my family, and my work appearing on the internet. The nasty comments were quite trivial — "everyone is being deceived", "does not fulfill obligations", "unprofessional".
Naturally, there was no evidence — just a stream of emotions and insults from "deceived clients".
Besides being unpleasant for me as a person, such "reviews" severely affected my reputation. The mechanism was simple: a person types "Yuri Mosha" into the search engine, and the first page shows a couple of sharp negative reviews. They move on, and it's just more garbage. A person might not even click on the links, just reading the headlines. That’s enough to form a "necessary" impression.
At first, I thought it was a competitor's order, but it turned out to be more mundane. In September, I received an email demanding $20,000 — and then they would delete the texts. If I refused, the scammers promised to create even more similar reviews.
Of course, I didn't pay. I contacted the support services of Google and Yandex asking to disable the indexing of these pages.
The results varied widely.
After a month of communication with Google support, the specialists confirmed that this content is defamatory and violates the rules for indexing web pages. The false articles were removed from the search results. Thanks to the Google managers for that.
But there are also complications. Nothing stops the criminal from creating more articles later on — they too will be indexed by the search engine and appear in the results. As the Google specialists I spoke with said, to disable indexing for specific keys (like "Yuri Mosha scammer" or "Yuri Mosha fraudster"), a court decision is required that recognizes the above phrases as untrue.
The situation with Yandex is much more complicated. The managers took the position of "not my problem" right from the start of our communication. They stated that they are not responsible for the content indexed by the search engine and are not obliged to monitor it.
It's true — a search engine should not monitor content. However, there is a caveat — it shouldn't, as long as it does not involve criminal offenses, which include defamation and blackmail.
Nonetheless, the support service made it clear that they do not intend to resolve the issue.
In this regard, I studied the legislation and filed a lawsuit against Yandex, as their outright refusal to remove illegal content from search results essentially makes the company an accomplice to the crime.
In Russia, the case was lost. Still, Russian legislation regarding cybercrime is very immature and does not allow for full protection of user rights, even despite the existence of the law on ‘Information, Information Technologies and Information Protection’:
According to the provisions of Article 10.3, the operator of a search engine distributing advertisements on the Internet aimed at attracting consumers located in the territory of the Russian Federation is obliged, upon request from a citizen (individual), to cease the dissemination of information about the website's page indicator on the Internet that provides access to information about the applicant, distributed in violation of Russian legislation, that is inaccurate, as well as outdated, having lost significance for the applicant due to subsequent events or actions by the applicant, with the exception of information about events containing signs of criminal offenses, the limitation periods for which have not yet expired, and information about a citizen committing a crime for which the conviction has not been lifted or erased.
The case in the Moscow court was lost due to procedural inaccuracies. The evidence base was in order.
Therefore, I decided to sue in an American court. The lawsuit against Yandex is currently in the Federal District Court for the Southern District of New York (case 1:18-CV-05444-ER).
I have already had experience with successful litigation in the USA, so this option seems more promising for me in terms of restoring justice.
Today, the case is awaiting a court decision. The parties have already presented their arguments, and my lawyers are anticipating a favorable outcome. However, in legal disputes with corporations, the result is unpredictable until the very end.
The legal landscape in cyberspace is evolving slowly, which allows fraudsters to exploit these rather primitive methods of extortion and blackmail. Personally, all these legal processes have taken over a year — during this time, my reputation with potential clients has significantly suffered.
Even after a successful court ruling, it will take time to restore it. But I hope that the court decision will set a precedent, making similar cases of fraud and extortion easier and quicker to resolve in the future.
Source: habr.com
