Example: [Collected on the Internet, 2003]
Subject: You use illegal File Sharing...
Ladies and Gentlemen,
Downloading of Movies, MP3s and Software is illegal and punishable by law.
We hereby inform you that your computer was scanned under the IP 220.127.116.11. The contents of your computer were confiscated as an evidence, and you will be indicated. In the next days you will receive the charge in writing. In the Reference code: #34510, are all files, that we found on your computer.
The sender address of this mail was masked, to protect us against mail bombs.
- You get more detailed information by the Federal Bureau of Investigation -FBI-
- Department for "Illegal Internet Downloads", Room 7350
- 935 Pennsylvania Avenue
- Washington, DC 20535, USA
- (202) 324-3000
Origins: The address and phone number given at the foot of the message quoted above are real (they belong to the FBI's Washington, D.C., headquarters), but that's the only thing genuine about this e-mail.
The FBI may have an interest in tracking illegal downloads of copyright-protected material on the Internet, but they don't have a "Department for Illegal Internet Downloads," and they aren't sending out automated messages like the one quoted above to serve notice that "your computer was scanned" and the "contents of your computer were confiscated." If nothing else, the poor grammar and spelling — "an evidence" rather than "evidence"; "indicated" rather than "indicted" — should be an obvious giveaway that the message is a phony, and likely crafted by a non-native speaker of English. (The latter point is probably confirmed by the fact that similar messages stemming from the same source are sent out with subject lines in German.)
The FBI has issued the following denial:
Symantec offers a removal tool for Sober.C on its web site.
Last updated: 29 October 2007
Varghese, Sam. "Invoking the FBI to Spread Malware." The Sydney Morning Herald. 6 January 2004.