Fake Interpol “Investigation” Emails Are Dropping Ransomware on Small Businesses

Cover graphic on a deep navy field reading Fake Interpol Investigation, showing an official-looking email that claims a small business is under investigation and links to a password-protected file that turns out to be ransomware disguised as a video, with a note that the malware is crude but the fear is doing the work

Bottom line up front

An email claiming to come from Interpol’s cybercrime unit tells your business it is under investigation and pushes you to open an attached “evidence” file right away. The password sits in the email; the file that looks like a video is actually ransomware. Real law enforcement does not email a company a locked archive of evidence against itself and ask it to open the file. One rule stops the whole thing: no unsolicited official-looking email gets its attachment opened until someone verifies it through a phone number or website you looked up yourself — not the one in the message.

The email shows up on a Monday, which is when these things always seem to land. The sender says it is Interpol’s cybercrime investigation unit. The subject line is heavy with words like compliance, review, and urgent. Inside, a short, formal paragraph explains that investigators have obtained information and video material related to your organization, and that you should review the evidence as soon as possible. There is a link to a file on Proton Drive, a well-known encrypted storage service, and the password to open it is typed right there in the message.

Nobody wants to read that their company might be tangled up in a criminal investigation. That is the entire point. You click the link, type in the password, and unzip the archive. Inside is what looks like a video file — presumably the footage the email mentioned. You double-click it. There is no video. What you actually launched was a program, and it has already started encrypting the files on your computer.

This is a real campaign that Bitdefender’s antispam researchers documented at the start of July 2026, hitting small businesses across the United States, Europe, Asia, and the Middle East. What makes it worth your attention is not the malware, which turns out to be pretty basic. It is the lure. The attackers do not break in. They talk you into opening the door, using nothing more than a badge you can’t verify and a deadline you invented for yourself.

Six tells in a fake law-enforcement email

You are not hunting for a spelling mistake. This message is clean and formal on purpose. You are looking for the shape of the request — and any single one of these is reason enough to stop and verify before anyone opens anything:

  1. An agency is emailing you directly with an accusation. Interpol coordinates national police forces; it does not send businesses investigation notices, and no legitimate agency opens a case against you by emailing you a file. The channel is wrong before you even read the words.
  2. You are told to open an attachment to see “evidence.” Real investigators do not hand suspects the evidence and ask them to review it. An email that wants you to download and open something to learn what you supposedly did is running a script, not a case.
  3. A password-protected archive with the password in the same email. The password is not there for security. It is there to slip the file past scanners that can’t look inside an encrypted archive, and to make you feel like you are handling something official.
  4. Fear plus a clock. The message manufactures dread — you might be under investigation — and then tells you to act quickly. That pairing is the manipulation, not a sign the sender is real.
  5. A file that says it is a video but behaves like a program. Attackers disguise an executable as a video so you don’t notice the extension before you click. On a small screen or with file extensions hidden, a .exe or .scr can pose as an .mp4 without much effort.
  6. The only way to respond is a channel you’ve never used. Whether it is a link to a cloud drive or, after the fact, a demand to chat over an app called Tox, everything funnels you toward the attacker’s turf and away from anyone who could tell you it’s fake.
29% of businesses with fewer than 25 employees have been hit by ransomware — and two-thirds of small-business leaders say a lack of budget is stopping them from making security upgrades. “Too small to be a target” is exactly the assumption these campaigns are built to exploit.
Source: CrowdStrike, State of SMB Cybersecurity Survey (reported by Dark Reading, July 2026).

Definition

Law-enforcement impersonation phishing: a scam that borrows the authority of the police, a court, or an agency — here, Interpol — to frighten a target into acting fast. The fear short-circuits normal caution, so the victim opens a file, pays a “fine,” or hands over data before pausing to check whether the sender is real.

How the fake Interpol email actually works

The campaign runs a short, repeatable chain, and every step is designed to keep you moving forward instead of stepping back. It opens with the email itself, dressed up as an official notice from a cybercrime unit and written to create just enough anxiety that reviewing the “evidence” feels like the responsible thing to do.

From there you are steered to a password-protected archive hosted on Proton Drive. Using a legitimate, encrypted file service is a deliberate touch. It looks more credible than a random download link, and the encryption means a lot of email filters can’t peer inside to spot the malware. The password, helpfully included in the message, is the key that gets you past the last bit of friction.

Open the archive and you find a file presented as a video documenting the activity under investigation. It is not a video. It is an executable wearing a video’s name, and running it unpacks a ransomware payload buried under several layers of archive. The malware then tries to encrypt files across the drives it can reach and drops a ransom note. In this campaign the note is unusually spare: it warns you not to delete files or scan the machine, and it tells you to make contact through Tox, a peer-to-peer chat tool. It does not name a price.

That missing number is a tactic, not an oversight. As Bitdefender analyst Alina Bizga told Dark Reading, attackers increasingly “make contact first and tailor their ransom demands to the size of the organization they’ve compromised and its perceived ability to pay.” Reach out, and they size you up before they quote you.

Figure 01 · The fake-Interpol ransomware chain
1 THE LURE An “Interpol cybercrime unit” email says your company is under investigation. 2 THE HANDOFF You’re sent to a password-protected file on Proton Drive — password typed in the email. 3 THE DISGUISE Inside sits a program dressed as a video of the “evidence” against you. 4 THE PAYLOAD Open it and ransomware encrypts the files across the drives it can reach. 5 THE SQUEEZE A note with no set price tells you to negotiate over the Tox chat app. THE EXIT AT EVERY STAGE Verify through a channel you looked up yourself — and never open the file.
Campaign details: Bitdefender Antispam Lab, July 2026; Dark Reading, July 2026.

The malware is crude. The fear is doing the work.

Here is the part that should change how you think about defending a small business. When Bitdefender’s researchers pulled the ransomware apart, they found it thin. The code carried hardcoded values, including the very password used to encrypt and decrypt files, and it lacked most of the machinery a serious ransomware crew builds — no dedicated dark-web negotiation portal, no polished victim site, just a Tox handle. As Bitdefender put it, the encryption key is baked into the malware itself, which means recovering the files without paying is technically possible for this sample.

So why does a flimsy piece of malware matter at all? Because the code was never the hard part. The social engineering was. The fake investigation email does the heavy lifting; by the time the ransomware runs, the victim has already been talked into launching it. “Even relatively simple malware can become a serious threat when paired with convincing social engineering,” the researchers wrote. That is the shift worth sitting with: an attacker no longer needs the budget or skills of a major ransomware gang to wreck your week. They need a believable story and one person willing to click.

It is the same lesson we keep running into from a different door. A year of high-profile intrusions has shown that the cheapest way past a company’s defenses is often a human being, not an exploit — the same pattern behind social engineering targeting small and mid-sized businesses and behind token-theft tricks like device-code phishing on Microsoft 365. The tooling changes. The pressure tactic — fear, authority, a deadline — does not.

Why criminals keep aiming at small businesses

Small businesses tend to assume they are beneath a criminal’s notice, and that assumption is precisely what makes them worth targeting. Most run without a dedicated IT or security team. Security duties get shared among people who already have day jobs, budgets are tight, and there is often no written process for checking whether an alarming message is real before someone acts on it. When an official-looking email lands claiming an investigation or a compliance problem, there may be nobody whose job it is to say “wait.”

The numbers make the mismatch concrete. In CrowdStrike’s research, smaller organizations were hit disproportionately more often than large ones, with 29% of businesses under 25 employees reporting a ransomware attack. Sophos, in its annual threat reporting, found that ransomware accounted for roughly 70% of the incidents it investigated at small-business accounts and more than 90% at midsize ones. And the true scale is almost certainly worse than any report shows: Bitdefender has noted that 55% of organizations admit they don’t report breaches even when they know they should, which keeps successful tactics in circulation against the next business in line.

Zoom out to the national picture and ransomware is not a fringe threat. The FBI’s Internet Crime Complaint Center logged $16.6 billion in reported losses across all internet crime in 2024, and it named ransomware the most pervasive threat to critical infrastructure, with related complaints up 9% over the prior year. Regulators also keep noticing that the sectors this campaign went after — healthcare, finance, agriculture, legal services — are the ones where a few locked machines can halt operations, which is exactly why we’ve written before about ransomware hitting dental and medical practices and school districts.

The one rule that stops it

Everything about this attack is built to keep you from doing the single thing that defeats it: verifying the message through a channel the attacker doesn’t control. So make that a standing rule, said out loud to everyone on your team, before a scary email ever arrives.

Say this rule to your whole team

If any email, text, or call claims to come from the police, a court, a regulator, or an agency — we do not open its attachments, click its links, or send anything back until we’ve confirmed it through a phone number or website we looked up ourselves. Not the number in the message. Not the link in the message. Every time, no matter how official it looks or how urgent it sounds.

Real investigators expect to be verified and will not penalize you for calling to confirm. A criminal impersonating one is counting on the opposite — that the badge and the deadline will keep you from checking. Alongside that habit, a handful of unglamorous controls blunt the damage if someone does slip:

What to do in the first hour if you opened the file

If someone downloaded and ran the attachment, move quickly but don’t panic. The first hour shapes how bad this gets.

  1. Disconnect the device from the network. Pull the Wi-Fi and unplug the network cable. Taking the machine offline can stop the malware from reaching shared drives, cloud folders, and other computers, and cut its line back to the attackers.
  2. Don’t delete, move, or “clean” anything yet. Leave the encrypted files and the ransom note where they are. A professional may be able to attempt recovery, and preserved evidence helps if you report it.
  3. Get IT or a security professional involved now. If you have a managed service provider, call them. This is not the moment to troubleshoot alone; the sooner someone experienced isolates affected systems, the less spreads.
  4. Change important passwords from a different, clean device. If credentials may have been exposed, reset business email, cloud storage, and financial logins from a machine you trust, and turn on multi-factor authentication where it isn’t already.
  5. Tell your team and watch for follow-on activity. Warn everyone who might get the same email, and keep an eye out for unexpected logins, password-reset messages, or files that suddenly won’t open over the next several days.
  6. Report it. Flag the email through your provider’s “report phishing” feature, and if ransomware ran, report the incident to the FBI at ic3.gov and review the government’s guidance at StopRansomware.gov. Reporting feeds the warnings that reach the next business before they click.
  7. Work the full sequence. Our business scam incident-response guide covers the rest — internal notifications, insurance, and closing the hole the attacker used.

Do not negotiate or pay on your own

Paying a ransom is never guaranteed to get your files back, and it marks you as a business willing to pay. Even where a strain happens to be technically recoverable, like this one, that is a job for a professional working from a preserved copy — not a live chat with the attacker over Tox. Bring in help before you respond to anything the ransom note asks.

The email wore a badge you couldn’t check and set a deadline you didn’t question. Take away the badge and the deadline, and the attack has nothing left.

Train the pause before a fake badge tests it.

ScamDrill runs realistic simulations for your team — including authority-and-urgency lures like fake law-enforcement and compliance notices — so “let me verify that through a number I looked up” is a trained reflex, not a lucky one. See how it fits a small business.

Explore ScamDrill for organizations →

The line to send your team today

Most businesses meet an attack like this for the first time with the scary email already open and a cursor hovering over the attachment. The whole scheme falls apart on contact with one standing rule — so send this to everyone who touches a company inbox, today: “If a message claims to be the police, a court, or any agency and wants us to open a file, click a link, or reply fast, we don’t. We confirm it first through a number or website we looked up ourselves. Every time, no exceptions, no matter how official it looks.”

It takes ten seconds to send. It holds up against a badge nobody can verify and a deadline the sender invented — which, stripped of everything else, is all this attack ever was.

Frequently asked questions

Does Interpol email businesses to say they are under investigation?

No. Interpol is a coordination body for national police forces and does not contact companies directly to accuse them of crimes, and legitimate law enforcement does not send unsolicited emails with a password-protected file and instructions to open it and review evidence of your own wrongdoing. That format is the tell. A genuine investigation reaches a business through its own country’s police or a lawyer, on paper or in person, not through a link to a cloud drive with the password typed in the same message.

What happens if someone opened the attachment?

In this campaign the file that looks like a video is actually a program that installs ransomware. Once it runs, it tries to encrypt files across the machine’s drives and shows a note saying your files are locked and telling you to make contact through a chat app called Tox. Notably, the note does not name a price. That is deliberate: the attackers wait for you to reach out, size up your business, then set a ransom to match what they think you can pay. If a file was opened, disconnect that device from the network, leave the files where they are, and get a security professional or your IT provider involved right away.

Can we recover the files without paying the ransom?

Maybe, but do not count on it, and do not try to negotiate yourself. Researchers who analyzed this specific malware found it crude, with the encryption password hardcoded inside the program itself, which means recovery without paying is technically possible for this sample. That will not be true of most ransomware, and even here the safe move is to preserve the encrypted device untouched and hand it to a professional who can attempt clean recovery. Your reliable protection is an offline or otherwise isolated backup you can restore from, not the hope that a given strain happens to be reversible.

Why would criminals bother targeting a small business?

Because small businesses are easier to hit and often assume they are too small to notice. Most run without a dedicated IT or security team, without a written process for verifying an alarming message, and on tight budgets that make training and tooling feel optional. Survey data backs this up: in CrowdStrike’s State of SMB Cybersecurity research, 29% of businesses with fewer than 25 employees had been hit by ransomware, and two-thirds of SMB leaders said a lack of budget was stopping them from making security upgrades. An intruder does not need a big company to make a small one’s week very expensive.

How do we tell a real law-enforcement contact from a fake one?

Treat any unsolicited message that invokes the police, a regulator, or an agency as unverified until you confirm it through a channel you found yourself. Do not use the phone number, link, or reply address in the message. Look up the agency’s official contact details independently and ask whether the communication is real. Real investigators expect to be verified and will not punish you for calling to confirm. If a message pressures you to open an attachment quickly to avoid trouble, that urgency is the manipulation, not a sign of legitimacy.

What is the single best defense against this kind of attack?

Make one habit automatic across your team: nobody opens an unsolicited attachment or acts on an alarming official-looking email until it is verified out of band. Pair that with a few boring controls that blunt the damage if someone slips: keep isolated backups you test, turn on multi-factor authentication so stolen passwords do not open doors, show file extensions on Windows so an executable pretending to be a video is easier to catch, and give staff realistic practice so the pause-and-verify reflex exists before the real message arrives. Fear and urgency are the weapon here, so the defense is a team that is allowed to slow down.