How to Recognize a Sextortion Email

How to recognize a sextortion email

An email lands claiming a hacker filmed you through your webcam and will send the footage to everyone you know unless you pay in cryptocurrency — and to prove it is real, it quotes one of your old passwords. It is terrifying by design, and almost always an empty bluff. Our GetMyPassword team explains how to recognize a sextortion email and what to do.

Spot a sextortion email
How to recognize a sextortion email.

How the scam works

A sextortion email claims the sender has compromising video or browsing history and threatens to share it with your contacts unless you pay a ransom, usually in cryptocurrency, within a short deadline. To make the threat land, the message often includes a real password of yours or your phone number. That detail feels like proof of a hack — but it almost always comes from an old data breach, bought or downloaded in bulk, not from spying on you.

Why the “proof” is hollow

The whole scam runs on fear plus one recognizable fact. Billions of leaked email-and-password pairs circulate from past breaches, so a scammer can blast the same template to millions of people and sprinkle in each one’s leaked password automatically. There is no video, no webcam footage, and no targeted hack. If the password they quote is one you actually used, it is a sign that password appeared in a breach — not that someone is watching you.

What to do if you get one

  • Do not pay — paying confirms a live target and invites more demands.
  • Do not reply or engage with the deadline or threats.
  • Change the quoted password everywhere you used it, starting with important accounts.
  • Turn on two-factor authentication so a leaked password alone cannot open anything.
  • Report and delete the email; mark it as spam or phishing.

The password in a sextortion email is not proof you were watched — it is proof you reused a password that once leaked. Change it, add a second factor, and the threat collapses.

How to take away their leverage

These emails only sting when an old password is still in use somewhere. Give every account its own unique password from our password generator, so a single leaked credential is worthless everywhere else, and store them in a password manager. Add two-factor authentication on anything that matters. Once no breached password still works and a second factor guards the door, a sextortion email is just noise you can delete.

Frequently asked questions

The email knows my password — was I really hacked?

Almost certainly not. The password was harvested from an old data breach and added automatically to a mass email. It means that password leaked, not that anyone filmed you or accessed your device. Change it and enable two-factor authentication.

Should I pay a sextortion demand?

No. There is no footage, and paying only marks you as a responsive target for more demands. Do not pay or reply — change the exposed password, turn on two-factor authentication, and report the email.

How do I stop these emails from having any power?

Use a unique password for every account so a leaked one is useless elsewhere, store them in a password manager, and enable two-factor authentication. Then a breached password the scammer quotes cannot actually open anything.

Help your friends stay safe. Share this article!