Where to begin
A Shenzhen-based tech company employee, overwhelmed by personal debt, orchestrated a fake "hacker extortion" scheme by stealing confidential research materials and demanding ransom payments in Bitcoin and Tether. Following a prosecution by the Pingshan District People's Procuratorate in Shenzhen, the court sentenced the defendant, Jia, to three years and three months in prison for attempted extortion in April, along with a fine of 10,000 yuan. The verdict is now final.
The case prompted the procuratorate to drive corporate improvements in security protocols, achieving the goal of "resolving one case, governing an entire sector." During a key case review meeting in June, the prosecutor in charge emphasized that handling internet extortion cases involving enterprises requires a precise grasp of the boundary between crime and non-crime, scientifically assessing the value of virtual currencies, comprehensively securing evidence related to subjective coercion and objective harm, and leveraging the procuratorate's role in guiding pre-trial investigations and proving crimes. This approach aims to continuously safeguard core data security and intellectual property for tech companies.
On September 13, 2025, the prosecutor conducted a thorough review of all evidence in the case. Driven by desperation due to mounting debt from online loans, Jia, an employee of the company, was caught in a web of financial pressure. In mid-August 2025, the company received an anonymous extortion email from overseas, claiming, "I have stolen your company's confidential documents. Pay 0.88 Bitcoin, or I will leak everything!" The email included samples of core technical data, alarming company executives who knew that exposing such proprietary information would destroy years of research investment and undermine market competitiveness. Despite the relentless pressure, the company refused to give in and reported the incident to the police.
On September 8, 2025, police arrested Jia and seized 43 folders of classified research materials from his phone. Investigations revealed that Jia, a regular employee, was burdened by over 400,000 yuan in online loan debt and unable to repay it, leading him to steal core technical data for extortion. Between July and August 2025, Jia exploited company management loopholes to download large amounts of research data from the company's servers, illegally disassembled office computer hard drives, and copied all data onto his personal phone. After acquiring the materials, he posed as a foreign hacker, sending multiple threatening emails to the company. On August 13, 2025, he sent an email via an overseas account, claiming to be a hacker who had stolen confidential files, attaching samples as proof, and demanding 0.88 Bitcoin as a "confidentiality fee." On August 27, he escalated pressure through the company's official website customer service channel, falsely claiming to have stolen 50GB of core data with a cloud link as evidence, and reduced the demand to 0.8 Bitcoin. By September 5, he changed the ransom to 90,000 Tether, proposing a partial payment of half to exchange a data directory, intensifying the pressure step by step.
Why just the lack of payment?
On September 12, 2025, police requested the Pingshan Procuratorate to intervene. A key legal question arose: did Jia's actions constitute extortion? Extortion requires the victim to hand over property out of fear. In this case, the company did not pay anything but instead reported the crime. If the company believed Jia was bluffing and not afraid of a data leak, his repeated emails demanding virtual currency might only be considered intimidation, not extortion. The crux was whether the company was "unafraid" or "so afraid it dared not act rashly."
The prosecutor discovered that the initial investigation did not clarify the company's psychological state and its link to attempted crime. The Pingshan Procuratorate quickly launched a collaborative mechanism, assembling a team to analyze the case and provide precise supplementary investigation recommendations: comprehensively verifying Jia's job duties, the value of the stolen data, and the company's response after the incident. Further investigation confirmed that the company had developed a genuine fear. The company knew Jia likely had extensive confidential data, and refusing could lead to a full leak, so they engaged in negotiations as a tactical move to identify phishing attacks, stabilize the suspect, and gather evidence. "Jia selectively released some data to prove the theft and concealed all files to create unknown risks, deliberately inducing panic. His subjective intent and objective actions for extortion are fully established," the prosecutor explained.
On November 17, 2025, police transferred the case to the Pingshan Procuratorate for review and prosecution. The procuratorate determined that Jia, with the intent to illegally occupy property, committed extortion involving an extremely large amount. Due to the company's report to police—a factor beyond his control—he failed to obtain the money, constituting attempted extortion. Another challenge was whether the value of Bitcoin and Tether, which are not legal tender, could be used as criteria for the crime's amount and how to accurately assess it. "Virtual currency directly reflects the crime's social harm," the prosecutor said. Jia's goal was to repay debts, and he had calculated the value of the virtual currencies beforehand, with his debt amount serving as a reference. To precise sentencing, the procuratorate guided police to commission a professional valuation, using the lowest exchange rate on the day of the crime, and determined the virtual currency's equivalent value to be over 630,000 yuan. This was corroborated by Jia's loan records, linking the ransom to his debt repayment needs, forming a complete evidence chain. The court ultimately delivered the verdict as described.
Protecting corporate innovation
During the case, the Pingshan Procuratorate also investigated the root causes, finding significant management weaknesses in the company. Although the company had signed confidentiality agreements with employees, it lacked technical safeguards, allowing employees to freely download and copy core data, rendering data protection ineffective. The procuratorate proactively engaged with the company, identifying shortcomings in data security, confidentiality management, and emergency response, and proposed targeted improvements. They helped the company overhaul internal controls, establish a ransomware emergency response process, and provide ongoing legal advice and risk assessment services. After systematic reforms, the company upgraded its data security across all processes, significantly enhancing protection. "The procuratorate not only helped us plug management holes but also boosted all employees' awareness of confidentiality and legal compliance, giving us a 'peace of mind' to focus on R&D and business growth," said a company representative.
"This case strongly cracks down on crimes like stealing core data through internal management loopholes and posing as foreign hackers for internet extortion, creating a powerful deterrent against similar violations of tech companies' intellectual property and data security," the prosecutor said. They will continue to work on multiple fronts, upholding high-quality judicial handling to safeguard the safety of innovation, building a solid legal shield for the development of new productive forces in the region.
Source: Procuratorate Daily, Pingshan Procuratorate