Fake Europol Telegram Channel Tricks Media with Bogus $50,000 Qilin Ransomware Bounty


# Fake Europol Telegram Channel Tricks Cybersecurity Community with Bogus Ransomware Bounty

A fraudulent Telegram channel impersonating Europol successfully deceived cybersecurity researchers and journalists by offering a fake $50,000 reward for information on Qilin ransomware administrators.

## The Deception Unfolds

On August 16th, a fake Telegram channel named @europolcti appeared, claiming to offer substantial rewards for information leading to the capture of two Qilin ransomware operators known as “Haise” and “XORacle.” The impostor channel mimicked official law enforcement language, stating that these administrators “coordinate affiliates and oversee extortion activities” for the notorious ransomware group.

Europol quickly debunked the claims when contacted by BleepingComputer, confirming that “the announcement didn’t come from us” and expressing surprise at how widely the story spread.

## Behind the Hoax

After being exposed, the fake channel revealed its true purpose: trolling the cybersecurity community. The perpetrator, signing as “Rey” (a hacker previously linked to breaches at Telefonica and Orange Group), boasted about how “easy” it was to fool researchers and journalists who “just copy stuff.”

This incident appears connected to ongoing harassment campaigns against the Qilin ransomware operation, which has been one of the most active groups since rebranding from “Agenda” in 2022.

## A Pattern of Manipulation

This isn’t an isolated incident. The cybersecurity industry has faced similar deception attempts:

– **2021**: A RAMP administrator called for attacks on the USA, later claiming it was fake after media coverage, though security experts believe it was damage control for a failed operation.

– **2023**: BleepingComputer received fabricated tips about arrests related to crypto-theft, designed specifically to manipulate media coverage.

## Key Takeaways

This incident highlights critical vulnerabilities in cybersecurity reporting and the need for enhanced verification processes. As threat actors become more sophisticated in their disinformation campaigns, the industry must develop stronger safeguards against manipulation while maintaining the speed necessary for effective threat intelligence sharing.

The ease with which this hoax spread serves as a wake-up call for cybersecurity professionals to implement more rigorous fact-checking procedures before amplifying unverified claims.

Share This Article