Fake Admins, Fake Police: How Impersonation and Extortion Scams Prey on Dark Web Users
A message arrives claiming to be from market staff, a police agency, or both at once. It carries official logos, the names of real investigators and a single demand: pay now in cryptocurrency or face arrest, exposure, or worse. On the Tor network, impersonation has quietly become one of the most reliable moneymakers in the entire criminal ecosystem.
An old con wearing a new badge
The playbook is centuries old. A stranger claims authority the victim cannot easily check, invents urgent consequences for non-compliance, and insists on immediate payment through channels that cannot be reversed. Cryptocurrency removes the last friction, because a transfer to the wrong wallet is gone forever. What has changed is the production quality. Scammers now forge multi-language legal notices, spoof caller ID, and name-drop actual senior officials to make their letters feel authentic. As Europol warned in a public awareness guide, fraudulent messages have even invoked the names of real executives at the agency, including its then operations director Jean-Philippe Lecouffe (Europol).Extortion becomes a business model
The most striking documented case came from inside a market itself. In March 2024, the administrator of Incognito Market, operating under the handle Pharoah, told vendors he had retained years of order records, private messages and crypto transaction IDs, and demanded payments in exchange for not handing the data to law enforcement. Researchers described it as a first in darknet market history."Extortion is the new exit scam," wrote the researcher behind the dark.fail index at the time. "Now its admin Pharoah is demanding that each seller pay a ransom or he will turn their data over to the police."Trade press documented how the operator even published lists of who had and had not paid the blackmail fee (Cybersecurity News). The lesson generalizes far beyond that single market. Anyone holding user data can weaponize fear of prosecution, and victims of such schemes face a cruel dilemma: paying confirms the leverage works, while ignoring it gambles on the blackmailer bluffing.
The fake seizure banner industry
Not all impersonation targets individuals. Some of it impersonates law enforcement itself, replacing a site's homepage with a convincing takedown notice. In March 2024, the ransomware group ALPHV posted a bogus seizure banner as cover for what analysts concluded was an exit scam; researcher Fabian Wosar called the forgery blatantly obvious from the page source alone (The Hacker News). Genuine banners do exist, which makes the trick work. When Europol-led Operation Deep Sentinel dismantled Archetyp Market in June 2025, the real homepage displayed an official seizure notice bearing participating agencies' logos (Bitdefender). We break down how to tell the two apart in our guide to fake seizure banners.When agencies become props
Europol has repeatedly stressed what it will never do. It does not issue fines, does not open investigations by phone, and never asks citizens for banking details, personal information, or app downloads. Its blunt public message, "Europol will not call you," exists precisely because so many fraudsters claim otherwise (The Cyber Express). The same pattern holds for national police forces, tax authorities, and court systems worldwide. Real agencies do not demand instant crypto payments, threaten arrest within hours, or ask you to keep the call secret. Any contact combining those three features is a scam by definition, regardless of how official it looks.How to verify any official contact
Verification beats vigilance. Before acting on any urgent message, treat these checks as non-negotiable:- Never trust contact details supplied inside the suspicious message itself.
- Find the organization's independently published channel and ask there directly.
- Demand PGP-signed proof of identity from anyone claiming staff status.
- Treat every payment deadline as a red flag, since real institutions use formal processes.