SCAMSSocial engineering, decoded First steps
← All stories
After a scamThreat response

An extortion email contains your old password. That is not proof of a webcam recording

Separate the real data the sender may possess from the much larger story they want you to believe, then address the actual exposure without paying or engaging.

Ink illustration of a closed laptop, an old key and an ominous envelope in daylight
Original editorial illustration. Not a photograph or evidence of an individual incident.

An email threatens to release an intimate recording unless you pay. Most of its claims sound generic until you reach a password you recognize. That one accurate detail changes the emotional weight of everything around it: perhaps the sender really did access the camera, read your files and collect your contacts.

A password in a message is evidence that the sender has that password, not proof of every other claim in the message. It may come from an earlier data breach rather than surveillance of your device. The right response is to separate the known exposure from the threatening story.

This article concerns unsolicited, generic extortion emails that cite old passwords and make broad claims of secret recording. It should not be used to dismiss a targeted threat involving actual images, an abusive partner, stalking or verified account compromise. Those situations deserve appropriate specialist support and law-enforcement advice.

Start by stepping outside the countdown

Do not reply, pay, open attachments or visit a payment page to investigate the claim. Put the message aside long enough to read it as a set of assertions rather than an instruction. If you feel overwhelmed, ask a trusted person to sit with you while you decide the next practical step.

The sender wants the deadline to become the most important fact. It is not independent evidence. A threat that says a timer began when you opened the email does not prove that the sender can observe your device or that any material exists.

You do not need to obtain reassurance from the person making the threat. Questions such as “Show me proof” keep the conversation active and can invite further manipulation. Use independent account checks and appropriate support instead.

Known fact

A disclosed password may need replacing wherever it is still used.

Unproven claim

The message’s recording and surveillance story.

Safer response

Do not engage; secure actual exposure and report through official routes.

What the NCSC says about this pattern

The UK’s National Cyber Security Centre response guidance explains that passwords included in this type of threatening email are likely to come from previous data breaches. It advises not engaging and changing a disclosed password if it is still in use, including anywhere else it was reused.

Its longer explanation of sextortion emails describes the use of plausible technical language and fear to pressure recipients. The guidance is about this mass-phishing pattern. It does not establish that every threat involving intimate material is a bluff.

That boundary is important. You can recognize a common scam without making an absolute claim about a device or relationship you have not investigated.

Separate evidence from interpretation

Write down the elements that are independently true. Perhaps the email address is yours, the password was once used, and the sender included a public address. Now separate those facts from the claims of camera access, recordings, contact lists and scheduled distribution.

Item in the message What it may establish What it does not establish alone
An old password The value has been exposed or obtained Current camera access
Your email address The sender knows where to contact you Control of the mailbox
Public personal details Information about you is available Access to all devices
Technical-sounding descriptions The sender can describe a scenario That the scenario happened
A payment deadline The sender is applying pressure A real release mechanism
Actual private material or account changes A more specific incident may exist That paying guarantees safety

The purpose is not to prove a negative about every possible compromise. It is to avoid letting one genuine detail validate a much larger unsupported narrative.

Do not paste the password into random “breach checker” websites. If you use a reputable breach-notification service, reach it independently and understand what it checks. A result about a past breach is not a complete security assessment of your current accounts.

If the password is old and no longer used

Confirm that it is not still protecting another account. People often remember changing the main email password but forget an old shopping, forum or work-related account that reused the same value.

If the value is genuinely retired everywhere, the message does not make it current again. You can still report the threat and review important account activity through official tools. Avoid creating a crisis by changing unrelated settings without a plan.

Do not infer that the sender knows every password you have ever used. Focus on the actual credential in the message and any independent signs of account access. General fear is not a reliable inventory.

A password manager can help you identify and replace reused passwords without building predictable variations. Use the manager and account providers through their normal interfaces, not links supplied in the threat.

If the password is still active

Change it through the genuine service, using a trusted device and a unique replacement. Change it anywhere else it was reused. Review recovery addresses, phone numbers and active sessions where the provider offers those controls.

Enable appropriate multifactor protection. If there are unfamiliar sign-ins or account changes, follow the provider’s recovery guidance and tell support what you observed. Do not assume that a password change alone reverses every unauthorized action.

Prioritize accounts that control other accounts, such as email, while keeping a written checklist. This is more manageable than trying to secure every service at once from memory. If the device itself shows independent evidence of compromise, seek trusted technical assistance before relying on it for sensitive recovery work.

These are responses to actual credential exposure. They do not require you to accept the email’s surveillance claims.

If the message appears to come from your own address

The displayed sender is not conclusive proof that someone sent mail from your account. Email presentation can be misleading, and the visible address is not the whole authentication record.

Check your account through its official interface for actual security alerts, unfamiliar sessions, sent items or changed settings. Absence of a visible sent message is not a complete forensic conclusion, but it helps separate what you can observe from what the threat asserts.

If you need help interpreting the message, use your email provider’s support or a trusted professional. Do not forward the full email with passwords and personal details to a public forum. A redacted description is safer for general discussion.

The question is whether there is independent evidence of account misuse, not whether the sender chose a frightening display name.

When this guide is not enough

If the person has actual intimate material, is known to you, threatens physical harm, stalks you or controls your accounts, do not dismiss the situation as a generic email scam. Preserve relevant evidence and seek appropriate local police, victim-support or specialist assistance.

If you are under 18 or helping a young person, involve a trusted adult or specialist child-safety service promptly. Do not request, download or circulate explicit material as proof. The priority is safety and support, not investigating the content yourself.

If you feel in immediate danger or at risk of harming yourself, contact local emergency or crisis support and someone you trust. The shame the threat tries to create is part of the pressure; you deserve help without having to explain or justify private behavior.

This page cannot assess an individual threat remotely. It can help identify the limits of the evidence and the need for a more appropriate response.

If you already paid

Do not send another payment to secure deletion, extend the deadline or obtain a promise. Payment cannot independently verify what the person possesses or ensure what they will do next.

Contact the payment provider promptly through its official route and ask what reporting or intervention is available. Preserve transaction references, the threat and relevant communication. Recovery may be difficult and is not guaranteed, but an accurate record is useful.

Report through the appropriate local law-enforcement route. The NCSC pages link to current UK reporting and support information; outside the UK, use the corresponding services in your jurisdiction. An email report is not a substitute for immediate help where there is a personal safety threat.

Be alert to people who later claim they can erase the material or retrieve the money for a fee. Our recovery-scam guide explains why the desire for a clean ending can create a second exposure.

Help without turning the message into a spectacle

If someone shows you the email, do not ask unnecessary questions about their private life. You can help check whether the password is still used and find official support without investigating the threat’s embarrassing subject.

Avoid forwarding the message widely. It may contain a real password, personal information or a live payment address. Preserve what is needed privately and redact sensitive details before any general discussion.

A calm response might be: “That password needs attention if it is still active. It does not prove the rest of the story. Let’s check the accounts through their real sites.” This acknowledges the genuine issue without amplifying the sender’s claims.

The useful outcome

For a generic old-password extortion email, the meaningful tasks are limited and concrete: stop engagement, address any active credential exposure, check independent account evidence, report appropriately and obtain support if the threat is more specific.

You do not need a promise of absolute certainty before refusing to pay. The sender has supplied a frightening story; your response should be based on verifiable facts.

Sources: NCSC immediate response guidance and NCSC’s explanation of sextortion phishing. For another threat designed to rush account decisions, see fake copyright appeals.

Found a factual error or a source that has changed?

Send a correction →
Scam notes · email

Get new scam guides

Occasional, practical updates on emerging scam patterns and what to do next. No hype; unsubscribe at any time.