Phishing Extortion Scams Surge: Action Fraud Issues Warning

Sharp Rise in Extortion Phishing Reports

The public is being urged to stay vigilant following a dramatic spike in phishing emails linked to extortion scams. Action Fraud has revealed that the National Cyber Security Centre’s Suspicious Email Reporting Service (SERS) received over 2,924 reports of these emails in March 2025, compared to just 133 reports in February – a staggering increase that highlights the growing scale of the threat.

The emails relate to a specific type of scam known as Financially Motivated Sexual Extortion (FMSE). These phishing attempts aim to intimidate recipients into paying a ransom by falsely claiming they have been recorded visiting adult websites.

How the Scam Works

According to reports, these phishing emails follow a familiar pattern, even though the subject lines and phrasing may vary. The emails typically claim that malware has been installed on the recipient’s device and that compromising videos or images have been captured. The sender then demands payment – often in cryptocurrency like Bitcoin – to prevent the release of the fabricated footage.

To make the scam more convincing, criminals frequently include genuine personal information in the email, such as a password or home address. Detective Chief Inspector Hayley King, Head of Prevention at the National Fraud Intelligence Bureau (NFIB), explained:

“Criminals will go to great lengths to make these types of extortion scams more convincing, including using a leaked password or home address in the phishing email to make it seem genuine.”

It is believed that this personal information is sourced from historic data breaches, with many recipients unaware that their details have been exposed in the past.

The Role of AI in More Convincing Scams

One of the key factors making phishing attacks harder to spot in 2025 is the increased use of artificial intelligence by cybercriminals. AI is now being used to craft more realistic and personalised phishing emails, making it significantly more difficult for individuals to distinguish scams from legitimate communications.

AI tools can analyse vast amounts of stolen data to automatically generate emails that use correct grammar, natural language, and even imitate the writing style of familiar contacts or organisations. This means that phishing emails no longer contain the obvious spelling mistakes and awkward phrasing that once served as warning signs.

The result is that even experienced internet users may find it difficult to spot a fraudulent message – highlighting the need for extra caution and robust reporting practices.

The Real-World Impact

Analysis by Action Fraud reveals that individuals who receive these emails often experience further cybercrime, including account hacking. One victim, a man in his thirties, received multiple extortion emails in 2024 that included a password he had used for one of his online accounts. Although he correctly identified the emails as a scam and deleted them, he later discovered that he had been locked out of several of his social media and bank accounts – clear evidence that the cybercriminals had gained access to his digital life.

What To Do If You Receive One of These Emails

Action Fraud has provided clear steps to follow if you receive a phishing email of this nature:

  • Do not engage with the sender.
  • Forward the email to report@phishing.gov.uk, the NCSC’s Suspicious Email Reporting Service (SERS).
  • Delete the email after forwarding it.
  • If the email contains a password you still use, change it immediately. Guidance on creating secure passwords and enabling two-factor authentication is available at Stop Think Fraud.
  • To check if your personal data has been exposed in a breach, visit Have I Been Pwned.
  • If you believe you are the victim of extortion, or suspect someone may possess intimate images of you, contact your local police by calling 101.

Paying the ransom is strongly discouraged. Victims who comply with demands often become targets for further scams, as criminals know they are dealing with someone willing to pay.

The Bigger Picture: Phishing on the Rise

Phishing remains the most common form of cybercrime worldwide. In the United States alone, the FBI reported a 33% increase in losses from phishing and other scams between 2023 and 2024, with estimated losses exceeding $16 billion. Globally, it’s believed that over 3.4 billion phishing emails are sent every single day – adding up to more than a trillion each year.

With AI now being weaponised by cybercriminals to generate near-flawless, highly personalised phishing emails, the threat is evolving rapidly. These emails are often indistinguishable from genuine communications, making traditional methods of spotting scams – like looking for spelling errors or poor formatting – less effective.

Reporting Phishing in Outlook

If you suspect a phishing email in Microsoft Outlook, you can report it directly:

  • Right-click the suspicious email in your inbox.
  • Hover over “Report” and select “Report Phishing.”
  • Alternatively, use the Report button on the top toolbar if available.

A confirmation message will appear once the report is submitted, helping Microsoft and cybersecurity authorities improve protections against future threats.

Stay Safe

With phishing scams becoming increasingly sophisticated — and AI making them harder than ever to detect — awareness is your first line of defence. Be cautious of unexpected emails, especially those that contain personal details or demand payments.

For more information on protecting yourself from fraud, visit: Stop Think Fraud.

If you’ve lost money or provided sensitive information due to a phishing scam, contact your bank immediately and report the incident to Action Fraud by calling 0300 123 2040, or Police Scotland on 101 if you’re in Scotland.

By remaining vigilant, questioning unexpected emails, and reporting suspicious messages, we can all play a part in staying one step ahead of cybercriminals.

Need help securing an AI defence system to spot increasingly sophisticated phishing emails? Talk to one of our team today!