Law & AI

Fake warning letters and fake invoices: how scammers exploit public company data — and how to check in minutes

This week it happened to weooo.de itself: an email over an alleged copyright infringement, sent by a company that does not exist. The case stands for a growing family of scams that automatically mine public company data — and AI is making them more convincing. Here is the checklist that exposes almost every one of these emails within minutes.

Abstract letter icon with a warning signal — symbolising a fake warning letter built from public company data

In short: It happened to us this week: an email accusing weooo.de of copyright infringement — sent by a company that does not exist. The case belongs to a growing family of scams that automatically mine publicly available business data from imprint pages, company registers and WHOIS records to build convincing-looking threat letters or invoices. What’s new: according to a recent study by TU Berlin, Inria and Ruhr University Bochum, AI personalisation triples the click rate of such emails — at 45 seconds of effort and 3 cents per address. The good news: a few minutes of checking exposes almost every one of these emails for what it is.

What happened — and what makes this case typical?

On Thursday morning, a message arrived through the contact form on weooo.de: an alleged company called “Sicopyright” accused us of copyright infringement and demanded we get in touch, or face “legal action.” No work is named, no address, no lawyer, no dated deadline — just a vague threat and a reply address.

The technical check took less than ten minutes and was unambiguous: the sender domain had been registered with a Chinese registrar just 62 days earlier, runs no website of its own, and had been technically activated exactly two days before the email was sent. “Sicopyright” exists nowhere online — no company register entry, no law firm, not a single result. The pattern matches exactly the “copyright infringement backlink scam” documented since 2023 by, among others, Kaspersky and the Austrian consumer watchdog Watchlist Internet: mass mailing through contact forms, a vague threat, the goal being either a forced backlink or — once you reply — a payment demand.

Why are these scams getting more professional right now?

Because data gathering and drafting are increasingly handled by AI — and that measurably works. A study presented in August 2026 at the USENIX Security Symposium by TU Berlin, Inria and Ruhr University Bochum tested this on 7,741 real employees at TU Braunschweig: the researchers automatically built personal profiles using only publicly findable information — professional background, interests, affiliations — and had a language model draft tailored messages from it. Result: automatically personalised emails reached a click rate of 10.0%, generic AI emails only 3.9%. Effort per email dropped to about 45 seconds and 3 US cents — a human-personalised spear-phishing message scored higher at 24.2% clicks, but cost seven minutes of manual work per address. That is exactly the gap AI closes: near-manual click rates at a fraction of the effort, scalable at will.

Bar chart: phishing email click rates by creation method — generic 3.9%, automated AI-personalised 10.0%, manually personalised 24.2%; effort 45 seconds vs. 7 minutes per email.

One notable side finding from the study: more data is not automatically more dangerous. People with especially extensive public profiles clicked less often than people with a moderate amount of data — the language models started to abstract rather than use concrete details once there was too much information to work with. That is no real comfort, though: a company imprint page or a WHOIS record already provides more than enough public data points to build a credible-looking approach — exactly what the Sicopyright case shows, where the domain visible on weooo.de alone was enough to make us a target.

What variants of this scam are currently circulating?

The copyright scam is just one variant of the same underlying pattern: automatically mining publicly available business data and turning it into a letter that looks like a genuine claim. German chambers of commerce (IHKs) are currently warning about at least two further variants built on the same principle:

  • Fake company-register invoices: After every entry or change in the German commercial register — publicly viewable — dubious providers such as “Gewerbe- und Handelsregister Deutschland” (GHRD) send invoices for several hundred euros, styled to look like an official fee notice, sometimes even carrying the federal eagle. The German Association for the Protection against Economic Crime (DSW) has already filed criminal complaints over this.
  • Fake domain and hosting invoices: Providers with names like ”.DE Deutsche Domain” or “Web Domain Deutschland” send invoices for a domain “renewal” designed to look like a message from the real registrar. DENIC — the actual registry for .de domains — explicitly warns: domain invoices should only ever come from the provider you actually have a contract with.

All three variants work because the underlying data — imprint, company register, WHOIS — is public in Germany for good reason. That very transparency is what makes it a perfect springboard for mass, automated outreach.

Is every email threatening a lawsuit or an invoice automatically suspicious?

No — and that is exactly why a short, calm check beats panic. Genuine copyright warnings, genuine register fees and genuine domain invoices do exist. The difference comes down to a handful of clearly checkable features. Under German law (§ 97a(2) UrhG), a valid copyright warning letter must, among other things, name the rights holder, precisely describe the infringement, and itemise the claim — a warning letter that fails to do so is legally invalid, regardless of whether a rights holder is actually behind it. Genuine register and domain invoices, in turn, come exclusively from the party you actually have a contract with — never unsolicited from a previously unknown provider. Anyone who asks these two questions first — “Is the claim specific enough?” and “Do I even have a contract with this sender?” — can sort most cases within seconds.

How do you check a suspicious email in a few minutes?

Using a fixed sequence that applies regardless of the exact scam variant:

  1. Stay calm. The time pressure in the email is part of the scam — a genuine claim does not expire within hours.
  2. Don’t reply, don’t pay, don’t sign anything before the check is complete. Every reply confirms to the sender that the address is active — often technically traceable via individually tagged reply addresses.
  3. Check the sender domain via WHOIS/RDAP (e.g. via lookup.icann.org or rdap.org). A domain that is only weeks old is a strong warning sign.
  4. Open the domain in a browser. Is there even a website behind the alleged company?
  5. For alleged law firms: look up the name in Germany’s official nationwide lawyer directory (BRAK) — name, office location and contact details must match.
  6. For invoices: only pay if you actually have a contract with this exact provider. An unsolicited invoice is never a reason to pay.
  7. Check for specificity: work, rights holder, claim amount, dated deadline — if several of these are missing, it is not a legally valid letter.
  8. Report the suspicious email and block the sender: for example via the consumer association’s phishing radar, the relevant chamber of commerce, or the police’s online reporting portal.

Checklist: eight steps to verify a suspicious warning letter or invoice email.

Can you just use ChatGPT or Claude to check it?

Yes, as an additional first read — with one important caveat. An AI chatbot can reliably scan a pasted email for typical red flags: time pressure, impersonal greeting, lack of specificity, unusual links, the language patterns typical of machine-drafted text. That does not replace a WHOIS check or a look at the lawyer directory, but it is a fast second opinion before you react. Important: only paste the plain email text, never your own confidential business data, customer data or contract details — checking a suspicious message should not itself become a data protection problem.

What should you do once the suspicion is confirmed?

Ignore it, document it, harden your defences — in that order. Archive the email (in case something substantial ever does follow), block the sender on your own mail server, and consider the matter closed. If genuine doubt remains — for instance if a postal warning letter arrives from a law firm that is actually findable in the BRAK directory — the review belongs in a lawyer’s hands, before any response. Anyone running their own contact form should also harden it technically: an invisible honeypot field, a rate limit per IP address, and a time threshold against forms submitted faster than a human could type already catch most automated submissions before they ever reach an inbox.

Conclusion

The Sicopyright case is a textbook example of this growing family of scams: a young, anonymous domain, a vague threat with no substance behind it, a claim built on a publicly available business address. AI making these emails more convincing and cheaper to send in the future does not change the solid checkpoints against them — WHOIS age, lawyer directory, specificity of the claim, contractual basis for invoices. Running through this checklist once usually takes less time than reading the email did in the first place.

Not sure whether a message in your inbox is genuine, or want to harden your own contact form against mass scam mail? Talk to us — we’ll take a look at your case.

Sources
  • Czybik, Kouam, Heubl, Nold, Rieck (BIFOLD/TU Berlin, Inria, Ruhr University Bochum), “A Large-Scale Study of Personalized Phishing using Large Language Models,” USENIX Security Symposium 2026 — click rates 3.9% (generic) / 10.0% (AI-personalised) / 24.2% (manually personalised), cost approx. $0.03/email, field study with 7,741 employees at TU Braunschweig.
  • Kaspersky, “Copyright Infringement Backlink Scam” — description of the scam campaign running since 2023.
  • Watchlist Internet (Austria), “When the alleged copyright violation turns out to be a scam attempt.”
  • eRecht24, “Fake warning letter: how to recognise the scam”; Händlerbund, “Recognising fake warning letters.”
  • § 97a(2) German Copyright Act (UrhG) — statutory minimum requirements for a valid warning letter.
  • IHK Osnabrück / IHK Düsseldorf, warnings on fake invoices for commercial register entries (incl. “Gewerbe- und Handelsregister Deutschland”).
  • DENIC eG, warning against fake third-party domain invoices.
  • Verbraucherzentrale, Phishing Radar and “How to read the email header.”
  • Internal technical analysis by weooo GmbH of the “Sicopyright” incident from 27 August 2026 (RDAP, DNS and header review).
FAQ

Frequently asked questions

How do I recognise a fake copyright warning letter?

By missing mandatory information: under German law (§ 97a(2) UrhG), a valid warning letter must name the specific work, the rights holder, and an itemised claim. If these are missing, it is legally invalid regardless of who sent it. Further warning signs include a very young sender domain, no reachable website behind the alleged company, and a demand to simply 'get in touch' instead of a clear, specific claim.

How do I check whether a sender domain is trustworthy?

A free WHOIS or RDAP service such as lookup.icann.org or rdap.org shows the domain's registration date. Domains that are only a few weeks old, run no website of their own, or sit with a mass registrar abroad are a strong warning sign.

Why does AI make these scam emails more dangerous?

A study presented at the 2026 USENIX Security Symposium by TU Berlin, Inria and Ruhr University Bochum found that AI-personalised phishing emails reach a 10.0% click rate versus 3.9% for generic emails — at just 45 seconds of effort and about 3 US cents per address. That makes large-scale, individually convincing attacks cheaply scalable for the first time.

Can I paste a suspicious email into ChatGPT or Claude to check it?

Yes, as an additional first read that makes sense — an AI chatbot reliably spots typical red flags such as time pressure or an impersonal greeting. Only paste the plain email text, never your own confidential business or customer data. This does not replace a WHOIS check or a look at the lawyer directory.

What should I do if I already replied to a fake warning letter?

Do not reply again, do not pay, and do not add any backlink. A reply already sent marks your address as an 'active target,' but it creates no legal obligation. If uncertainty or follow-up contact persists, a brief legal opinion helps.

Transparency: This article was researched and drafted with AI support, then reviewed on the substance and approved before publication. Editorial responsibility rests with weooo GmbH.