{"id":60804,"date":"2026-06-05T21:18:42","date_gmt":"2026-06-05T21:18:42","guid":{"rendered":"https:\/\/www.theregister.com\/a\/5251891"},"modified":"2026-06-05T21:18:42","modified_gmt":"2026-06-05T21:18:42","slug":"if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/","title":{"rendered":"If you don&#8217;t fall for these extortionists&#8217; calls, they&#8217;ll show up with USB sticks"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/image.theregister.com\/5251908.jpg?imageId=5251908&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" class=\"ff-og-image-inserted\"><\/div>\n<p>If they don&#8217;t get you online, they&#8217;ll try in person. A data-theft and extortion gang has targeted \u201cdozens\u201d of banks, law firms, and other professional services companies in the US from January through May, using fake help desk calls and other social-engineering techniques to gain access to corporate IT environments, according to Google\u2019s Mandiant incident response team.&nbsp;<\/p>\n<p>And when those remote-deception methods don\u2019t work, the criminals sometimes show up at victims\u2019 physical offices, posing as IT technicians, and attempt to steal sensitive files using thumb drives.<\/p>\n<p>Google\u2019s threat hunters track the extortion threat group as UNC3753, while other analysts call it Luna Moth, Chatty Spider, and <a href=\"https:\/\/www.theregister.com\/security\/2025\/06\/02\/lumma-infostealer-takedown-may-not-have-succeeded\/987325\">Silent Ransom Group<\/a>. The crew has been around since 2022, originally using fake software renewal emails and other billing lures, typically with PDF attachments containing phone numbers for attacker-controlled call centers, as their means of gaining initial access to corporate networks.<\/p>\n<p>Beginning around March 2025, the crims shifted tactics and started <a href=\"https:\/\/www.theregister.com\/cyber-crime\/2026\/06\/04\/pink-is-the-latest-goon-squad-to-use-fake-helpdesk-calls-to-steal-creds\/5251434\">posing as IT help desk staff<\/a>.<\/p>\n<p>\u201cWhile UNC3753 primarily relies on digital vectors, GTIG assesses that associated threat actors have also attempted direct data theft using physical, in person access,\u201d Google incident responders and researchers Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, and Tyler McLellan <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/targeted-campaign-us-law-firms\" rel=\"nofollow\">said<\/a> in a Friday blog.<\/p>\n<p>The authors also pointed to a May <a href=\"https:\/\/www.theregister.com\/security\/2026\/05\/27\/fbi-crooks-enter-legal-offices-and-steal-data-via-usb-drive\/5247212\">FBI alert<\/a> to corroborate this in-person tactic.&nbsp;<\/p>\n<p>According to the feds, Silent Ransom Group crooks have been walking into law firms\u2019 physical offices as recently as this spring. Once they are on-site, they claim to be IT support staff needing to image a device or create local backups for security reasons. If that line works, they plug a thumb drive into the victim\u2019s computer and steal data the old-fashioned way.<\/p>\n<p>\u201cAlthough limited forensic evidence and the absence of a subsequent extortion attempt prevent formal attribution, GTIG assesses that these physical intrusions are likely associated with UNC3753 based on structural, timeline, and targeting overlaps,\u201d the blog said.<\/p>\n<p>Google won\u2019t say how many dozens of firms have been targeted in these attacks, or how many ended in the data thieves paying a visit to the victims\u2019 locations.&nbsp;<\/p>\n<p>\u201cWhile we can\u2019t share additional details regarding specific investigations, Mandiant CTO Charles Carmakal notes that this tactic has been observed over the years,\u201d a spokesperson told <span class=\"italic m-italic \" data-lab-italic=\"italic\">The Register<\/span>. \u201cMandiant has investigated various matters where adversaries planted insiders, bribed employees, or physically entered buildings to facilitate cyberattacks.\u201d<\/p>\n<p>Another noteworthy thing about UNC3753\u2019s attacks: they are very fast. In many of Mandiant\u2019s investigated incidents, the entire operation from initial contact to data extortion occurred in just one day. \u201cRecently, Mandiant observed data searches, staging, and theft initiated in under an hour,\u201d the threat analysts warned.&nbsp;<\/p>\n<p>These intrusions typically begin with an invoice-themed email &#8211; but these don\u2019t usually contain any malicious links or attachments. The email\u2019s sole purpose is to give the miscreants a plausible reason to follow up via phone, so that the recipient is more likely to believe the call is legitimate.<\/p>\n<p>Most of the crew\u2019s entry mechanisms involve <a href=\"https:\/\/www.theregister.com\/special-features\/2026\/03\/23\/voice-phishing-skyrockets-as-smooth-crims-talk-their-way-in\/5223759\">voice-phishing<\/a>, using a <a href=\"https:\/\/www.theregister.com\/security\/2026\/04\/09\/several-dozen-orgs-targeted-by-a-new-extortion-crew\/5222215\">method<\/a> that has <a href=\"https:\/\/www.theregister.com\/security\/2026\/02\/26\/scattered-lapsus-hunters-seeks-women-to-defraud-helpdesks\/4326750\">worked so well for other groups<\/a> like <a href=\"https:\/\/www.theregister.com\/security\/2026\/03\/09\/shinyhunters-claims-yet-another-salesforce-customers-breach\/5220118\">ShinyHunters<\/a> and <a href=\"https:\/\/www.theregister.com\/security\/2025\/05\/21\/scattered-spider-snared-financial-orgs-before-retail\/1190219\">Scattered Spider<\/a> over the past few years.&nbsp;<\/p>\n<p>UNC3753 calls organizations\u2019 employees directly and purports to be a help desk worker or member of the security team. The criminals say they need the target\u2019s help addressing a security issue or aiding with a corporate data migration project, and convince the individual to join a screen-sharing session via Zoom, Microsoft Terminal Services, Microsoft Teams, or Quick Assist.&nbsp;<\/p>\n<p>In one such intrusion, using Teams to gain access to the victim\u2019s computer, the attacker jumped on five separate calls with the same target over a three-day period, we\u2019re told.<\/p>\n<div data-element-guid=\"fbb25e5a-333b-43fe-bfcf-2c44bbca0224\" class=\"quotebox column size-small desktop-floatLeft mobile-floatLeft small-12 large-4 small-abs-12 large-abs-4\">\n<div class=\"content\">\n<h3 class=\"quote\"> Mandiant has investigated various matters where adversaries planted insiders, bribed employees, or physically entered buildings to facilitate cyberattacks <\/h3>\n<\/p><\/div>\n<\/div>\n<p>And in more than one incident that Mandiant responded to, UNC3753 established Zoom sessions directly on targets&#8217; personal laptops, using these machines to access corporate virtual desktop infrastructure (VDI) using native client platforms, such as Windows 365 or Citrix clients.&nbsp;<\/p>\n<p>Once they\u2019re in the corporate systems, the intruders map local directories and network drives, and target specific legal and document storage repositories. The crooks also use very-specific keyword searches to find sensitive folders containing tax logs (Forms W-2, W-9, and 1099), audit files, corporate client agreements, and Social Security numbers, before staging this data for exfiltration.<\/p>\n<p>UNC3753 uses several methods to sneak the data out of the corporate IT environment without setting off any security alarm bells, including using portable versions of free Windows file manager WinSCP or another open source filesystem like Rclone.&nbsp;<\/p>\n<p>The crew has also been known to log into a file-sharing account from the victim\u2019s browser and upload the stolen files that way &#8211; or even instruct the victims to send the files to an attacker-controlled email address.<\/p>\n<p>After stealing the data, they send the extortion email, usually within 30 minutes of exiting the victim\u2019s environment, and set a three-day deadline to respond and begin the negotiation process. \u201cWe hope to find a financial solution that will be acceptable for both parties,\u201d reads one such extortion email. <\/p>\n<p>It continues:<\/p>\n<p class=\"quote\">In case of ignorance or no agreement, We will notify your employees, partners and customers, after which We will publish your data. You will receive claims from individuals, and legal entities for information leakage and breach of contracts, your current deals will be terminated. Journalists and others will dig into your documents, finding inconsistencies or violations in them. Your organization will lose its reputation, shares will fall in price, and your organization will be forced to close.<\/p>\n<h3>Stay safe, friends<\/h3>\n<p>In the Friday report, Google\u2019s threat hunters list IP addresses and other indicators of compromise, including these phishing domains that UNC3753 uses in its social-engineering attacks, all designed to look like the target organization\u2019s help desk: &lt;organization&gt;-itdesk[.]com, &lt;organization&gt;-it[.]com, and &lt;organization&gt;-helpdesk[.]com.<\/p>\n<p>The security shop also suggests a range of things companies can do to avoid falling victim to this group and other voice-phishing scams or physical office intrusions. <\/p>\n<div data-element-guid=\"afe083ca-6701-48e9-9bd8-f8827dd7fb42\" class=\"lab4 column articleList layout_vertical imageLayout_left small-12 large-12 small-abs-12 large-abs-12 abs_grid_12 grid-vas-start mobile-grid-vas-start\">\n<div class=\"content border_width_0 border_width_mobile_0 border-radius-48 border-radius-mobile_48\">\n<h2 class=\"article-list-title t19 font-RobotoCondensed\">MORE CONTEXT<\/h2>\n<\/p><\/div>\n<\/div>\n<p>Some of the physical controls include requiring visitors to display official credentials and photo identification, and mandating front-desk staff log all visitor IDs before granting access. Also, check pre-scheduled work orders to ensure the \u201ctechnician\u201d at the front desk is who they say they are, and make sure any visiting technical service workers are always accompanied by a corporate, in-office supervisor.<\/p>\n<p>Because the bulk of these intrusions occur without any physical entry into the office, however, companies should also implement remote access conditional access policies to ensure only corporate-owned devices can authenticate to any VDIs or VPNs. Plus, block the installation and execution of unauthorized remote monitoring and support utilities. \u00ae<\/p>\n<p> <img decoding=\"async\" src=\"https:\/\/image.theregister.com\/?imageId=5251908&#038;width=800\">READ MORE <a href=\"https:\/\/www.theregister.com\/cyber-crime\/2026\/06\/05\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/5251891\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> When &#8216;Chatty Spider&#8217; morphs into tech services cosplay spider READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":60805,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[1047],"class_list":["post-60804","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register","tag-cyber-crime"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>If you don&#039;t fall for these extortionists&#039; calls, they&#039;ll show up with USB sticks 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"If you don&#039;t fall for these extortionists&#039; calls, they&#039;ll show up with USB sticks 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-05T21:18:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/image.theregister.com\/5251908.jpg?imageId=5251908&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"If you don&#8217;t fall for these extortionists&#8217; calls, they&#8217;ll show up with USB sticks\",\"datePublished\":\"2026-06-05T21:18:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\\\/\"},\"wordCount\":1164,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks.jpg\",\"keywords\":[\"Cyber Crime\"],\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\\\/\",\"name\":\"If you don't fall for these extortionists' calls, they'll show up with USB sticks 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks.jpg\",\"datePublished\":\"2026-06-05T21:18:42+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks.jpg\",\"width\":100,\"height\":66},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyber Crime\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/cyber-crime\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"If you don&#8217;t fall for these extortionists&#8217; calls, they&#8217;ll show up with USB sticks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"If you don't fall for these extortionists' calls, they'll show up with USB sticks 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/","og_locale":"en_US","og_type":"article","og_title":"If you don't fall for these extortionists' calls, they'll show up with USB sticks 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-06-05T21:18:42+00:00","og_image":[{"url":"https:\/\/image.theregister.com\/5251908.jpg?imageId=5251908&amp;x=0&amp;y=0&amp;cropw=100&amp;croph=100&amp;panox=0&amp;panoy=0&amp;panow=100&amp;panoh=100&amp;width=1200&amp;height=683","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"If you don&#8217;t fall for these extortionists&#8217; calls, they&#8217;ll show up with USB sticks","datePublished":"2026-06-05T21:18:42+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/"},"wordCount":1164,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/06\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks.jpg","keywords":["Cyber Crime"],"articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/","url":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/","name":"If you don't fall for these extortionists' calls, they'll show up with USB sticks 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/06\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks.jpg","datePublished":"2026-06-05T21:18:42+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/06\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/06\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks.jpg","width":100,"height":66},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cyber Crime","item":"https:\/\/www.threatshub.org\/blog\/tag\/cyber-crime\/"},{"@type":"ListItem","position":3,"name":"If you don&#8217;t fall for these extortionists&#8217; calls, they&#8217;ll show up with USB sticks"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60804","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=60804"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60804\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/60805"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=60804"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=60804"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=60804"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}