x

Contact form with Ransom threat

Just this morning I received a Contact Form entry that stated:

"You've been hacked!

Now we have all the information about you and your accounts:

+ all your logins and passwords from all accounts in payment systems, social. networks, e-mail, messengers and other services (cookies from all your browsers, i.e. access without a login and password to any of your accounts)

+ history of all your correspondence by e-mail, messengers and social. networks

+ all files from your PC (text, photo, video and audio files)

Changing your username and password will not help, we will hack you again.

Pay a ransom of $ 250 and you can sleep peacefully without worrying that all information about you and all your accounts, files and personal correspondence will not become public and will not fall into the hands of intruders.

[It then gave an account to transfer the money to.]

If you do not pay until tomorrow evening, then we will sell all this information on the darknet, there is a huge demand for such information

Pay $ 250 and sleep well!"

Have others seen something similar? Is there any legitimacy to the claim of being hacked? It sounds like a scam. 

8,664 Views
Message 1 of 39
Report
1 Best Answer
Square

Best Answer

Thanks for your posts, everyone. Those submissions are definitely fake, spammy, form submissions that you can safely ignore. I recommend enabling the Google CAPTCHA option on your form like @BadimoMC mentioned as that can help prevent these types of junk from coming through your form.

View Best Answer >

10,421 Views
Message 32 of 39
Report
38 REPLIES 38

I belive its possible to add a "I am not a robot" to a contact form.
https://blog.ivertech.com/blog/how-to-add-recaptcha-to-weebly-contact-form/

This could help with future spam!

3,587 Views
Message 32 of 39
Report
Square

Best Answer

Thanks for your posts, everyone. Those submissions are definitely fake, spammy, form submissions that you can safely ignore. I recommend enabling the Google CAPTCHA option on your form like @BadimoMC mentioned as that can help prevent these types of junk from coming through your form.

10,422 Views
Message 32 of 39
Report

Three issues in one.

Received the "you've been hacked email, via my contact form" so like others in the community are you looking into this and what are you doing about it?

As per one of your suggestions online, I wanted to add Google CAPTCHA option on my contact form, but can't see where to do this? Followed the steps that Weebly says that you need to do but none of the info/options are there in regards to the online form that I have on my site.


Wanted also to use Weebly Chat but told that I would have to wait 15-30 mins, which is unacceptable an as a business you need to remedy this because if a customer has to wait more than 5 mins then you need to hire some new employees, especially at this time when so many people NEED work.

4,198 Views
Message 32 of 39
Report
Square

Thanks for comments, @FHP20

Open your site in the website editor, then go to your Contact page and click on your contact form to edit it. Click on the Form Options button, then look for the Google Captcha option. There should be a toggle for that right underneath the field where you enter email addresses to use with the form.

4,163 Views
Message 32 of 39
Report

I've been getting these spam emails from my contact forms for the past two days. I found that adding Captcha on my website forms was easy and quick. Thanks to Weebly for responding with the directions.

3,977 Views
Message 32 of 39
Report

How do we activate Google CAPTCHA

3,998 Views
Message 32 of 39
Report
Square

To enable Google Captcha, navigate to your form in the website editor and click on it to edit it. Next, click on the Form Options button, then toggle on the Google Captcha option. Finally, save your form and re-publish.

3,993 Views
Message 32 of 39
Report

I've also received multiples of these "hacked" phishing emails.

3,912 Views
Message 32 of 39
Report

I received 4 identical threats today in my contact forms. It involved Btc. What do I do?
2,812 Views
Message 32 of 39
Report

my site easyhearthealth was also hacked 0n 10/13/20 and ransom emails sent to site contacts. can't get anyone at weebly to help or respond! john kosta

3,327 Views
Message 32 of 39
Report

My site was hacked to and a ransom of $250 demanded.
3,327 Views
Message 34 of 39
Report

Same here.  How do we get in touch with support about this? 

3,308 Views
Message 35 of 39
Report

Same here.  I got about 6 emails with the same ransom threat with only the reply to emails different. 

4,052 Views
Message 35 of 39
Report

Thanks for posting this question. I am receiving the same messages BUT today they notified me i have 7 hours left to resond or my info goes to the DARK WEB where the ransom price is $3000. AGH! And thanks to Weebly's response.  

3,358 Views
Message 37 of 39
Report

I got the same thing... Annoying.
3,243 Views
Message 37 of 39
Report

I have received 2 of these in the past 2 days. I assume deleting them is the best solution. I have not bothered to attach a Google CAPTCHA on the form.

3,231 Views
Message 39 of 39
Report
Square

Yes, mark as spam in your email box, and delete/ignore. The emails are definitely frustrating, but will subside over time. Adam posted some instructions for enabling the CAPTCHA option for your form on this thread. Please keep in mind that the CAPTCHA option will not always show on your live site. It is designed to activate if the system detects a possible spam submission. 

3,218 Views
Message 39 of 39
Report

In addition to Ransom Threat.  There's some other things to consider.  I didn't receive the ransom threat, I received more nefarious and active issue this year (2020).  My site was hacked.

In 2016, Weebly was hacked and millions of people's data was collected.  So...it is possible your information was compromised.  All passwords should be changed and you should have been notified, but don't count on it...check Weebly weekly.  So get a new credit card number IF you purchased a pro version and it is posted on Weebly.  In 2018, Weebly was purchased by Square.

Regarding a simple phishing expedition or something more nefarious? 

A.  Ignore it and it will go away...don't open emails you are not familiar with and DEFINITELY don't contact them. (BUT...head in the sand approach could be a cautionary tale to stay vigilant...if you see some alarming activity later, consider further steps)

B.  It is a pfishing exercise with "hooks" and can be activated at a later date.  I received and opened an email claiming to be from Weebly (I was never able to confirm that email was a fraud) with all the correct information stating my account needed to be updated.  That appeared to be the trigger because suddenly I was innundated with 14 charges sent a little bit at at time the first week of June for each $39.95 domain names and believed it would have continued if I hadn't contacted my bank and then Weebly regarding fraudulent activities.  Thus far over $500.00...I haven't added it up yet. And if you go to the domain name created, it actually popped up a warning not to go there on my phone.

Looking closer, I discovered that my weebly had been hacked by an unknown person in January 2021 (take a screenshot) and they inserted their name and a credit card number.  It wasn't until June 2021 that I received the fraudulent charges after opening an email from them.  Then I saw in my email account another email from a mirror account of Weebly but the text clearly indicated fraud...jumbled words, etc. 

What did I do as you should as well?

-Get a new credit card issued, report the fraud to Weebly and your bank (if it occurs and is not just a pfishing exercise without additional "hooks").  Good news?  Weebly was awesome to work with and they now have a team to investigate.

-Change your password on your Weebly account, bank password and probably your email too.

-Check in Account settings to see if someone has been there and remove them (don't forget to screen shot it). 

-Any passwords you may have used for private web settings, remove (or change) and don't use again cause they know what those passwords are. 

-If you assign editors to any of your accounts and/or pages...assess names to make sure they are people you've given permission to edit your account. 

-Stay diligent, do your research to see if something else has happened and check bank account and Weebly regularly even in areas you don't pay attention to like account information.

2,975 Views
Message 40 of 39
Report
This thread has been archived and locked. Please start a new thread if you would like to continue the conversation.