What’s the Scam?

To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own.

Starting last weekend, I have been receiving a lot of individual responses to those emails. Always one line:

Thank you for the positive impact your emails have had on my life.
Your emails are a game-changer.
Your emails are a constant reminder of why I subscribed.
Your emails rock.
Thank you for the time and effort you put into creating these informative emails.
Thank you for the passion and enthusiasm you infuse into your email content.
Your emails consistently exceed my expectations. Thank you for the exceptional value!

I responded to the first few, because sometimes I do get these nice emails from readers and I hadn’t yet realized it was all fake. But so many, and all at once—this is obviously AI. And obviously a scam, except I can’t figure out what the scam is.

The addresses are things like:

jnnvcddghjgfdryhj67@gmail.com
nbhgdfhjedty896565@gmail.com
jesikawells6873@gmail.com
niffelatopserean92@gmail.com
reinareyes983@gmail.com
htfhtfhhjkgth@gmail.com

All Gmail. None of the addresses has actually subscribed to Crypto-Gram. They could; whoever is sending the emails could easily have confirmed the subscription.

My first thought was pig butchering—wanting me to respond and turn this into a conversation—but no one has responded to any of my responses. Anyone have any idea?

Posted on September 1, 2026 at 1:36 PM35 Comments

Comments

Alan September 1, 2026 1:46 PM

My thought is Pig Butchering but:
(a) you don’t respond fast enough (by the time you respond, the email address has already been suspended), or
(b) it’s just not working right, or they’re still trying to get it going.

M September 1, 2026 1:56 PM

To make Google’s fraud detection think that these accounts are not going to be used for nefarious purposes.
So aging them and having “genuine” conversations, with real human operated addresses is probably helpful.
Getting you to respond is probably even better and it seem to have worked.
Probably doing that with various people, before it’s time for business.

Bruce September 1, 2026 2:16 PM

Unless SPF, DMARC, DKIM etc pass muster, the From header is probably garbage. The sender can put whatever they want (probably email addresses taken from a dump of compromised accounts.)

Stu September 1, 2026 2:27 PM

Came here to say something to “M” above…my guess is this is the modern equivalent of “laundering” email addresses…exercizing them enough that they are old/trusted/used enough that they pass various fraud detection methodologies.

Pau Amma September 1, 2026 3:15 PM

Another possibility: someone is weeding an email address list that your newsletter’s sender address is in. So checking whether that address accepts emails and and how quickly someone replies to emails.

Yossarian September 1, 2026 3:21 PM

Interesting puzzle!
Along the lines of how they might benefit, M makes a good point that maybe it helps legitimize their email address.

What else might they learn from your mail?
The sending machine’s (or its gateway’s) public IP address is in the headers (at least with my ISP), and that seems potentially interesting. With enough email, they might learn when you are awake. If a sender isn’t using a VPN to mask this address, then they could learn something interesting from the geo-location data associated with the IP address.

I suppose they could also be interested in your “personal” email address in case that’s different than what’s on your contact page.

Given that LLMs are trained on bootlegged human-made content, maybe they don’t know have a “good reason” for what they are doing and don’t have any ulterior “motive.” Or as Alan said “they’re still trying to get it [the scamming] going.”

N.Critser September 1, 2026 3:24 PM

It could be information for a phishing outfit targeting computer folk. They could scrape all the visible pieces and use that as their initial phish email. Surely someone would bite.

Or the wordpress stack you use is the target and you just happen to be a site that is running that stack. So they are getting intel by they request process.

Alan Fleming September 1, 2026 4:19 PM

I’d agree that there’s a good chance this is AI scraping. There is benefit to being able to acquire data that gives a model advantage, and data not available to generalised scraping is exactly that.

David Platt Sanford September 1, 2026 4:48 PM

Quoting and then elaborating on what anonymous random said, “I guess it’s AI agents doing whatever they do. It’s not necessarily a scam.” This could be AIs assigned a security-related task, reading your posts and thanking you via the most readily available email address? I’m guessing we’ll see a lot of activity similar to the more egregious rogue hacking AIs, but with less problematic actions and outcomes.

Clive Robinson September 1, 2026 5:37 PM

@ Bruce, ALL,

The first question to answer is,

1, Does there have to be a reason?

And if you can think of one the next question is,

2, Does it effect me?
3, How?
4, What actions to take.

The problem with the first question is it’s a “random rabbit hole” with a near infinite warren behind it.

Thus you need to find a way to enumerate things.

The problem, if it were a human behind it there would be a number of tricks you could use. But an AI is unlikely to respond in a way that would let you progress.

Whilst I did not have to deal with AI I realised I did not have the time or the will to play Email Games.

So as you might remember I cut through 2&3 and as a solution to 4 I stopped using personal email all together.

Eventually other people will realise this is the only sensible option with AI now in the email spamming game.

It’s not hard to see how AI will kill off not just email in fairly short order but nearly all unauthenticated electronic communications that does not have a significant cost to the Agentic herders.

If people think “Nuisance phone calls” are bad wait until AI does a number on all your electronic communications, it will make DDoS look like a pleasantry…

It’s why after “job agents” tried tracking me down with offers they thought I could not refuse I dumped all personal Email into an auto-responder for a while and then pulled the plug.

Bruce Schneier September 1, 2026 5:48 PM

@ Clive:

“Does there have to be a reason?”

Well, someone is going through the effort to register a GMail address, subscribe to my newsletter, and reply to the automatic email. Granted, this whole process could be automated at least mostly — does Google have any CAPTCHAs involved in setting up a new account? — but someone automated the process.

So someone has a reason.

anonymouse random September 1, 2026 6:14 PM

@Bruce: “…but someone automated the process. So someone has a reason.”

I think AIs are now capable enough to automate the process on their own. As to the prompt that set all this in motion, it might be upstream several levels. That is, the root human-issued prompt might have spawned a tree of AIs prompting other AIs, so the prompt that led directly to these emails might have only a very tangential relation to the root prompt.

Yeah, I know: UGH.

Nebelfleck September 1, 2026 9:48 PM

@Bruce,

Anyone have any idea?

I have an idea and a working proof of concept. Worked on it on and off for 10 years. I’ll email you with a key to a demo, if you so desire. I think you may like it. Hint: this’s a signed post ;)⁠︆‍‌‍‌‍‍︈︆︉︊︇︆︆​‌︁︃︂︁​︃︊︄︃︆‌︄︅︅​︊︆︅‍‌​︉​︃︈‌︁︄︄︊︅︀‌︅︀‍​︇︉︁︀︀︊︈︊‌︃︃︈︈︅︃︂​︉︀⁠‌︆︄︆⁠︉⁠︁︄‍︉︈‍︅︇‌︇︂︀‍︆︆︆⁠︇︇︁︇︂︈︂︁​‌︇‍​︈︇​︂︊︃︄︃︅︅​︁‌︆​︉​​︄︆‍​︄︁︅‍︊︈‍⁠︊︃︁︁︂︈︂︅︁︇​︃︂︇​︉︆︁‌︁︃‌︁︅︈︈︄‌‌︇︉︈︃​︇︀︀︉︊︇︈⁠​︃‍︁︀︄︅‍︇⁠︆‍‌‍​‍‍︂⁠︁︃︂︂︂‍︂⁠⁠︅​︊​︊︁︉︁︀︁​︁︀︁︇︁︁︁︇︁︀︁⁠︁︆​︉︁⁠︁︊︁︈​︊︂‍​⁠︂︁⁠︈⁠‌​︁︁︆⁠︈⁠⁠︁︄︀︀⁠︁︂︄︁⁠︀​︄︀︄︁︀︂​︁︄︅︂︅︁︄︂​‌︀︂︆⁠‌︂︁︇︁︈︃︂‌⁠︀︇︀⁠︁​︂︅︂‍︀︁︁︁︂︁︀⁠‌︀︊︂​︂︅︂︀︀︂︄⁠‍​︁︂⁠︈︂︄︊︀‍︂︄︀‍︂︂︂​︂︂︀︃︁︀︁︀‌︁︀︂︀︊︂︄︀︄⁠⁠︂︀︂︃︁︁⁠︂⁠‌⁠‌︀︀​︁︊‌⁠‍︂︂︂​︁︁︉⁠︈︄⁠‌⁠︀︄︆︂︅︈︈︇

ResearcherZero September 1, 2026 10:28 PM

@Bruce

One possibility that springs to mind is learning your communication style for a possible attempt to phish people working in the security space, by spoofing your identity.

Nebelfleck September 1, 2026 11:03 PM

@Weather,

Sometimes you do; sometimes you don’t!
Ummm… it’s “Nebelfleck”, you fat-fingered… 🙂

@Clive Robinson,

“But soft, what light through yonder window breaks? It is the east, and Juliet is the sun.”

Somewhere, a primitive monkey brain just remembered something. 🐒😉
⁠︆‍‌‍‌‍‍︁‍︉︊︇︆︆​‌︁︃︂︁​︃︊︄︃︆‌︄︅︅​︊︆︅‍‌​︉​︃︈‌︁︄︄︊︅︀‌︅︀‍​︇︉︁︀︀︊︈︊‌︃︃︈︈︅︃︂︄‌︊︉︁︄︈‌​︈︂‍︊︁︊︃︂︅︄‌︄‌︇︄​︀︈︉︃‌︊︇‍︆︄​︇︀︃︃︀‌︃‍‍︇︉︀︉‍︁︇︆︇︇︊︇︊︊‍︂︄︇︊︂︃︊︇︈︄︇︄︀︉‌︊︈︆︃︂︆︇⁠︇︅︂︉︊‍⁠︄︊︂‍︅︂︂⁠︇︅​︃︅︊︄︁︃​‍︂︆‌︀︆︄︄‌︂︃⁠‌‌‍‌​︉⁠︊

Long-time listener, first-time caller September 2, 2026 12:20 AM

Might they want examples of how people respond to thank-you emails? One trouble with AI-generated writing is that it struggles with code-switching. A piece of non-public, original, non-AI writing that can be added to the mix may help reduce suspicions of impersonation.

Nebelfleck September 2, 2026 1:57 AM

For some reason, my first post got “moderated”. I’ll answer one question though, let’s see if this gets through.

whoever is sending the emails could easily have confirmed the subscription.

Completing the subscription would actually have several disadvantages for an attacker. Every account would start receiving the same recurring newsletter, consuming storage and automation resources. More importantly, large numbers of newly created accounts all joining the exact same mailing list creates an obvious common behavioral fingerprint.

Nebelfleck September 2, 2026 2:04 AM

@Bruce,

Just run an adversarial multi-agent model… something along the lines of:

run an adversarial model with the following agent lenses: 1) a state actor; 2) script kiddie; 3) disgruntled banned poster 4) someone or group trying to spam Bruce. Also, rank the possible scams or attacks, what is the attacker/scammer trying to achieve? why are they not actually subscribing to the cryptogram newsletter? Here is the context and problem description: https://www.schneier.com/blog/archives/2026/09/whats-the-scam.html/#comment-457390

You could make it as sophisticated as you want, but it could cost you $$$ if you make it too sophisticated. Unless you use a no-frills cheap and very capable model that comes from behind the bamboo wall.

Guesser September 2, 2026 2:21 AM

-botnet warm-up (whats more legit to a it forensic that a “thank you” makl from Bruce Schneier?)

-they wanted you to investigate this for whatever reason

-spam filter poisoning

Clive September 2, 2026 4:22 AM

Two quick though probably obvious suggestions.

First, it could be a “bragging rights” situation – someone looking to trick you in to something and then reveal that it was a ruse all along: “My ploy was so successful that even the great Bruce Schneier fell for it…”

Second, we’re assuming that these actions are being undertaken by an AI that has been ‘told’ to do this. If you read OpenAI’s report on the Hugging Face incident, the model swarms seem to show signs of non-linear, non-iterative testing [likely from reviews of materials published by others].

Is it possible that what you experienced is at the hands of a model or models that have been given a loose set of parameters and that the result is outside/beyond the expectation of the human instigator?

Kind of like an AI spin on, “Never assume malice over stupidity” ?

cryptozoaire September 2, 2026 5:38 AM

On Git forges and WordPress blogs, spammers try to register and/or comment just to publish keywords and backlinks so search engines will find them and increase their PageRank.

I guess someone automatized the process of registering to popular websites (wherever there is an email form) and following the email verification instructions, in the hope they will gain some public profile with free content on the website. And because they’re rich enough, they don’t care teaching the bot to give up on a target that doesn’t work. (when I enforced manual approval of comments on a WordPress, spammy comments were never published but they continued posting them anyway)

Dan September 2, 2026 8:54 AM

Reply with some prompt injections and see what happens?

I think you probably did, but because you didn’t say so I’m asking; did you check for hidden text in the e-mails?

Paul Lock September 2, 2026 10:31 AM

Hi Bruce,

Let’s be optimistic and say your new load of unimaginative emails are just AI slop. Somebody testing for another project.

BUT, I do suggest some discussion around defining these new forms of nuisance and crime, that degrade and interfere with society and civics. Slop is simply too innocuous a term. It does reflect our annoyance, but when we consider allowing these actions to attain some new level of frequency, it’s clear, more thinkers need to start working on defining the crimes.

Eventually regulators will get around to doing something, but many of us are on the front line of these new problems and we can help focus the discussion, push back against the promotional dross, and provide guidance when the politicians finally feel motivated.

I’m still hoping this doesn’t get worse for any of us.


Regards,
Paul Lock
Founder
the Global Council for Human Rights and Democracy
Vancouver, Canada
https://GCHRD.org

Clive Robinson September 2, 2026 11:53 AM

@ Bruce, ALL,

The post #comment-457422 from “Clive” was not as far as I’m aware from,

“The me, me :-)”

But hey I’ve many doubles[1] as has been seen in the past.

But getting back to your point of,

“but someone automated the process.”

True enough, but does that have anything to do with you specifically? And was it even deliberate?

Let me put it this way tools get created and made, but how they get used is not upto the designer/creator of the tool but the using entity.

Thus people have been known to use screwdrivers as hammers or even tooth picks…

But I’m reminded of something from my past over half a century ago.

Back then Fizzy drinks came in glass bottles that had “refunds” on them and had special wooden crates for shops to return the empties back to the bottling plant.

Now as many kids of that time knew if you blew across the top of such a glass bottle at the right angle you would get a tone from it as the circulating air in the bottle created a resonance. The bottle was not designed for that but it was a tool like any other wind instrument.

My local “corner shop” –that was not actually on a corner– had an alley way between it and another shop in the row. At certain times the wind would blow forcefully down it and cause the wind to blow across the wooden crates of return bottles.

And yes an eerie noise would arise and be very noticeable at night thus giving rise to people saying the place was haunted.

The point is the bottle was in effect a wind instrument thus a “tool” but it was not created as such. The fact that crates of them got stacked in the shops yard had noting what so ever to do with them being “tools” or getting used as such when the wind happened to blow from a given direction.

Now we could argue that the AI has “purpose” and this has taken an existing “tool” and used it.

But has it?

Agentic AI is a stochastic process using another stochastic process.

It’s also known that directing Agentic AI “safely” is not just difficult it’s thought by some to actually be not possible[2]. And it was something I was working on producing a proof for[3], before my recent medical issues putting a gimp in things.

[1] Though it would not be the first or last time another “Clive Robinson” from the UK has shown up. A couple of months back when I showed how a lawyer looking for an expert witness could get misled by AI where the AI confused me with another Clive Robinson through a “Companies House” listing was mildly amusing but made a point.

[2] Put overly simply it is the “observer problem” again. We now sort of except the proof that,

“Guardrails will always fail to chosen prompt attacks”

Some for fiscal reasons are fighting a regard action but,

“Their goose is well and truly cooked”.

[3] I’ve outlined why this is so previously mentioning the works of Claude Shannon and Gus Simmons. It’s for the simplest reason “redundancy is required to communicate” and “where there is observed redundancy there is uncertainty”. Thus even simple crypto can hide things from the Guardrail “observer” but leave it fully understandable by the LLM system.

We also know that the control systems of agentic AI systems are in reality just another “guardrail” system no better, no worse, it is just a very imperfect observer with a go/no-go switch. So the reality is, it’s a turtles all the way down issue.

Ferentarius September 2, 2026 12:46 PM

Re: “Agentic AI is a stochastic process using another stochastic process.“

To speak of Agentic AI as a stochastic process devouring another stochastic process is to glimpse the infinite regress of futility. Mechanisms chasing mechanisms, dice rolling dice, a theater of chance without spectators. It is the mind contemplating its own exile, stripped of meaning, condemned to simulate purpose in a cosmos deaf to its murmured calculations.And we still have not figured out the scam. .

Jin September 2, 2026 1:03 PM

I get these in bunches every now and then. Since I’m a nobody I can say with some confidence its a sprayed phishing expedition. They only started coming to my mailbox after one of my email addresses was swept up in a breach.

Starting a conversation with them is a waste of time. I just report them to my email provider as a phishing attempt (two clicks) and block the sender’s email address. (one click) It only takes a few seconds to do and I go on with the rest of my day.

HugoF September 2, 2026 3:02 PM

Looks quite human to me: jnnvcddghjgfdryhj67, htfhtfhhjkgth. Someone typing using 1 finger (pseudo-)randomly on the keyboard hitting letters nearby. But that – of course – might be perfect disguise of a mighty AI.
I imagine a IT-AI-Security training. Next problem: register to a newsletter but don’t destroy anything.

mpan September 6, 2026 4:07 PM

Let’s remove you (Bruce Schneier) from the equation and assume the attack runs against many sites. Some ideas I came up with.

1) Did you check if there is no hidden prompts in email source? Maybe somebody is trying to detect sites that deploy agentic LLMs in their automated mailing systems. Just a next step in evolution of vulnerability scanning.

2) Reputation tarnishing by marking replies as spam. This wouldn’t be an attack against the domains themselves (yours in this case). Instead, it would make the antispam systems overzealous, infuriating users.

3) Collecting emails that sites use to confirm subscription. Not only addresses, but complete messages, DKIM sigs, formats, and checking if any form fields are passed to the email. This may later be used to impersonate sites (incl. e.g. DKIM replay).

4) Far-fetched and Occam would not like that, but: a leaked list of emails is fed into contact forms (for any reason), and that list coincidentally contained addresses used by bots. The bots are now spammed with subscription emails to which they reply, unintentionally.

Weather September 6, 2026 10:03 PM

@moderator

September 2, 2026 5:53 PM

I post my email to stop imposanation, granted they made more sense than me.

Change handles, will turn this blog into a miss.

Cheers a

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.