you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 13 min ago 255 onions tracked
home / news / security
29 July 2025 security 4 min read

Fake Admins, Fake Police: How Impersonation and Extortion Scams Prey on Dark Web Users

A message arrives claiming to be from market staff, a police agency, or both at once. It carries official logos, the names of real investigators and a single demand: pay now in cryptocurrency or face arrest, exposure, or worse. On the Tor network, impersonation has quietly become one of the most reliable moneymakers in the entire criminal ecosystem.

An old con wearing a new badge

The playbook is centuries old. A stranger claims authority the victim cannot easily check, invents urgent consequences for non-compliance, and insists on immediate payment through channels that cannot be reversed. Cryptocurrency removes the last friction, because a transfer to the wrong wallet is gone forever. What has changed is the production quality. Scammers now forge multi-language legal notices, spoof caller ID, and name-drop actual senior officials to make their letters feel authentic. As Europol warned in a public awareness guide, fraudulent messages have even invoked the names of real executives at the agency, including its then operations director Jean-Philippe Lecouffe (Europol).

Extortion becomes a business model

The most striking documented case came from inside a market itself. In March 2024, the administrator of Incognito Market, operating under the handle Pharoah, told vendors he had retained years of order records, private messages and crypto transaction IDs, and demanded payments in exchange for not handing the data to law enforcement. Researchers described it as a first in darknet market history.
"Extortion is the new exit scam," wrote the researcher behind the dark.fail index at the time. "Now its admin Pharoah is demanding that each seller pay a ransom or he will turn their data over to the police."
Trade press documented how the operator even published lists of who had and had not paid the blackmail fee (Cybersecurity News). The lesson generalizes far beyond that single market. Anyone holding user data can weaponize fear of prosecution, and victims of such schemes face a cruel dilemma: paying confirms the leverage works, while ignoring it gambles on the blackmailer bluffing.

The fake seizure banner industry

Not all impersonation targets individuals. Some of it impersonates law enforcement itself, replacing a site's homepage with a convincing takedown notice. In March 2024, the ransomware group ALPHV posted a bogus seizure banner as cover for what analysts concluded was an exit scam; researcher Fabian Wosar called the forgery blatantly obvious from the page source alone (The Hacker News). Genuine banners do exist, which makes the trick work. When Europol-led Operation Deep Sentinel dismantled Archetyp Market in June 2025, the real homepage displayed an official seizure notice bearing participating agencies' logos (Bitdefender). We break down how to tell the two apart in our guide to fake seizure banners.

When agencies become props

Europol has repeatedly stressed what it will never do. It does not issue fines, does not open investigations by phone, and never asks citizens for banking details, personal information, or app downloads. Its blunt public message, "Europol will not call you," exists precisely because so many fraudsters claim otherwise (The Cyber Express). The same pattern holds for national police forces, tax authorities, and court systems worldwide. Real agencies do not demand instant crypto payments, threaten arrest within hours, or ask you to keep the call secret. Any contact combining those three features is a scam by definition, regardless of how official it looks.

How to verify any official contact

Verification beats vigilance. Before acting on any urgent message, treat these checks as non-negotiable:
  • Never trust contact details supplied inside the suspicious message itself.
  • Find the organization's independently published channel and ask there directly.
  • Demand PGP-signed proof of identity from anyone claiming staff status.
  • Treat every payment deadline as a red flag, since real institutions use formal processes.
For market users specifically, the decisive habit is cryptographic. Genuine operators sign announcements and mirror lists with keys whose fingerprints they publish separately, and you should confirm any signature with our PGP verify tool before trusting a word. Appearance can be faked pixel-perfectly; a signature against a fingerprint you sourced yourself cannot. Impersonation thrives on panic, and panic is optional. Slow down, verify out-of-band, and remember that no legitimate authority has ever needed your coins within twenty-four hours.

more notes

all news ›