Skip to main content

Extortion via AI playbook

This playbook has technical guidance for responding to a business email compromise incident. It is not a standalone resource: use it alongside your incident management plan to make sure it works for your school.

Extortion or ransom message

You must follow your safeguarding procedures.

Anyone in your school setting may receive an extortion message (also known as a ransom). This message may be to your school, associated social media profiles or email or directly to the school community (for example staff, students, parents or governors).

The message may say that images, videos, or audio have been digitally altered or AI-generated to be inappropriate. They may threaten to release the media for personal gain.

Remember: the content may still be used even if the demands are met.