Fake Interpol Arrest Notices Are Delivering Ransomware to Small Businesses
Criminals are impersonating the international police agency to frighten small business owners into downloading malware. The tactic is simple. It's working.

Key points
- Criminals are sending fake Interpol emails to small businesses in the US, Europe, Asia and the Middle East to trick staff into downloading ransomware.
- Targeted sectors include pharmaceuticals, food and agriculture, technology and legal services.
- Bitdefender confirmed the ransomware payload has a hardcoded encryption password written directly into the code.
- CrowdStrike survey data shows 29% of businesses with fewer than 25 employees were hit by ransomware attacks.
- Sophos reported ransomware accounted for 70% of cyber incidents it investigated at small businesses.
A fake email arrives, carrying the Interpol logo and formal language, telling the recipient their business is under criminal investigation. Investigators, it claims, have video evidence.
That's the opening move in a ransomware campaign, an attack where criminals lock a company's files using encryption and demand payment for the key, first reported this week by Bitdefender, a cybersecurity company. The campaign has hit businesses across multiple sectors on four continents.
The email is phishing, a fake message crafted to trick the reader into doing something harmful. It instructs the recipient to download a password-protected archive file from Proton Drive, a legitimate file-storage service, presented as evidence they must review.
Opening it releases ransomware disguised as a video file. The malware encrypts files on the victim's computer and instructs them to contact the attackers through Tox, a peer-to-peer messaging app that routes messages directly between users without a central server, to arrange payment.
There's no fixed ransom amount. Victims learn the price only once they make contact. Bitdefender analyst Alina Bizga told Dark Reading this lets attackers tailor demands to what each victim appears able to pay.
Why are small businesses the target here?
Small businesses are under-defended. Many have no dedicated IT staff, no formal incident-response plan, and limited security budgets. CrowdStrike survey data found two-thirds of small business leaders said budget constraints stopped them from making any security upgrades at all.
Bizga is blunt about the underlying misconception: small business owners routinely assume they're too small to attract criminals. Campaigns like this one correct that assumption, usually at considerable cost.
The Interpol disguise exploits a real anxiety. Compliance demands are increasingly common across many industries, so an official-looking investigation notice can feel plausible. It's engineered to produce panic, not scrutiny. Our earlier report on Australian small business cyber exposure from 3 July found the same pattern: legal and regulatory pressure makes official-looking threats land harder on smaller operators.
Bitdefender's technical analysis found the malware is far from sophisticated. The encryption password is hardcoded, literally written into the program itself, and the code lacks features common in larger criminal operations. Simple construction, real damage. As Bizga wrote in Bitdefender's report: "Even relatively simple malware can become a serious threat when paired with convincing social engineering."
Should you worry?
If you run a small business or manage staff at one, yes. An unexpected email claiming to be from any police force or government agency, asking you to download a file, should stop you cold. Verify through the organisation's official public website. Real investigators don't serve evidence via cloud-storage links.
Bitdefender also notes that 55% of organisations admit to not reporting security breaches even when they know they should, which means the true scale of attacks like this is almost certainly larger than any figure suggests. The hardcoded password is actually the one structural weakness here: a decryption tool built from recovered samples could, in principle, help victims recover files without paying.



