Skip to content
Extortion

"We recorded you": extortion emails, and how to tell bluff from breach

An email claims they hacked your webcam, shows you a real password, and demands cryptocurrency. Almost always it is a mass-mailed bluff — here is how to check, and what to do either way.

"We recorded you": extortion emails, and how to tell bluff from breach — Response Red advisory illustration

The essentials

  • These emails are sent in the millions. The password they show is nearly always from an old, public data breach — not from your device.
  • The convincing detail — your real password on screen — is the entire trick. It proves a website leaked years ago, nothing more.
  • Never pay and never reply; either marks your address as live and paying.
  • If the quoted password is still in use anywhere, change it there today and enable MFA.
  • Treat it as potentially real only if it shows something genuinely current: a recent password, actual file names, or real screenshots.

The formula is fixed: "we installed malware, we recorded you through your webcam, we have your contacts — pay in Bitcoin or everyone sees it." And then the hook: a password you actually used, right there in the subject line.

That hook comes from breach dumps traded for pennies. The sender has never seen your screen. But the email still tells you something useful: which of your old passwords is circulating.

Do this now

  1. Do not reply, do not pay. Any response — even an angry one — flags your address as monitored and moves you up the target list.
  2. Check where that password still lives. If the quoted password is in use anywhere today, change it there first, then everywhere else it was reused. This is the one real action the email demands.
  3. Turn on MFA where it matters. Email, banking, and any account that shared that password get app-based two-factor authentication or passkeys now.
  4. Triage for the rare real case. A current password, names of real files, genuine screenshots, or details no breach dump contains — any of those, and you treat it as a device compromise, not a hoax: disconnect and get the machine checked.
  5. Report and archive. Report the email as phishing/extortion to your provider or IT, keep a copy with headers, and note the payment address.

What not to do

  • Do not pay — payment is the only outcome the sender is fishing for, and it invites follow-up demands.
  • Do not open any attachment offered as "proof".
  • Do not keep using the quoted password anywhere, even on "unimportant" sites.
  • Do not forward the email to friends to ask if it's real — report it instead.
  • Do not spiral over the claims; the script is identical for millions of recipients.

Preserve the evidence

Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:

  • The email with full headers, saved as a file.
  • The cryptocurrency address in the demand.
  • A note of where the quoted password was used, and when you changed it.

Keep a clear head

Seeing a real password of yours in a stranger's threat is designed to short-circuit your judgment — that jolt is the product. Take the ten minutes; the fear does not survive the checklist.

If the claims touch on something private and the panic feels overwhelming, talk to someone before you act. The one truly damaging move available to you is paying.

Questions victims ask

They knew my real password. How is that not a hack?

Billions of credentials from old website breaches circulate publicly. The sender bought a list and mail-merged it. It proves a site you used leaked — which is worth fixing — not that your device was touched.

Could it ever be real?

Rarely, and it announces itself with specifics a dump cannot supply: a password you set last month, real file names, actual screenshots. Absent those, it is the mass script.

Should I cover my webcam?

A cover costs nothing and ends this particular fear permanently — go ahead. Just know that in this scam, no one was watching in the first place.

When the first hour is over, we take it from there.

Scoping, containment, forensics, and recovery — expert-led and evidence-safe, with AI removing the waiting. Engage a responder or talk to us about readiness.