What is sextortion?
Sextortion is extortion that uses intimate content as blackmail currency, whether real or merely claimed. In the version that lands in corporate inboxes every day, the sender claims to have recorded the victim through their webcam and displays a genuine password as proof of access. The password is usually authentic, taken from an old breach. The recording does not exist. It is a volume scam, blasted to thousands of addresses on a purchased list, not an attack aimed at you. But what it reveals about your company is true.
How the sextortion email is assembled
There is no break-in, no webcam switched on and nobody watching your company. What exists is a cheap assembly line that trades precision for scale and bets that, in every thousand recipients, someone will believe it enough to pay in silence.
Raw material bought ready-made
The criminal starts from a list of email addresses with matching passwords, compiled from breaches at old websites and sold on. When victims of the scam check, the password on display is usually old: close to ten years in the cases Krebs documented, from a service they barely remember using.
Credibility borrowed from a real piece of data
The password appears in the very first line, because it is what makes the message feel true. Recent campaigns add full name, phone number, street address and even a map image of the street where the person lives, all drawn from the same leaked databases. None of that proves access to the computer; it only proves the data is in circulation.
Delivery through a legitimate account already compromised
This is where the corporate filter fails. The messages that reach the inbox come from senders and network addresses with good reputation, because the criminals use corporate or personal email accounts they broke into earlier. The filter sees a trusted sender, not a suspicious origin.
A short deadline and a figure pulled from nowhere
The message gives a short deadline, twenty-four hours in the documented example, and demands payment in cryptocurrency, almost always bitcoin, these days through a QR code pasted into the body of the email. The amount is not calculated against anyone's income: in the campaigns analyzed in 2018 it was drawn at random, a digit from one to seven followed by three zeros; in recent campaigns it became a fixed figure, the same for everyone, in the region of two thousand dollars. Either way, it bears no relation to the person receiving it. What the urgency is designed to produce is a decision made alone, without consulting anyone.
Sources: Cisco Talos, analysis of 233,236 messages from two campaigns (2018); Krebs on Security (2018); Barracuda, Threat Spotlight (2024); Sophos, payment tracking (2020).
How to recognize it
- The message shows a password of yours, but an old one, no longer used anywhere that matters
- Nothing beyond the password is specific: no file name, no date, no time, no verifiable detail
- The deadline is short and counted in hours, twenty-four in the documented examples
- Payment is demanded in cryptocurrency, by bitcoin wallet address or QR code
- The text explicitly forbids you from telling anyone or seeking help
- The sender sometimes claims to have sent the message from your own account, which is usually just a forged sender field, that is, spoofing
- The same message, with small variations, reaches several colleagues in the same week
The forms sextortion takes
- Mass email extortion The bluff described above, with no material behind it at all. It is the form that reaches corporate inboxes in volume, and what this entry sets out in detail. Unlike phishing, there is no link or attachment to click; unlike BEC, nobody impersonates an executive asking for a transfer. The only lever is embarrassment.
- Extortion with real material Preceded by social engineering, days or weeks of approach, until the criminal obtains images of the victim and starts threatening to publish them. Here the content is real, and the response changes in kind: preserve everything as evidence, delete nothing, and involve law enforcement.
- Financial sextortion of teenagers An organized, transnational form, run at scale by criminal groups, aimed at minors with money as the objective. The FBI referred more than 5,700 cases involving minors to NCMEC, the US National Center for Missing & Exploited Children, in 2025, and the center logs around 137 reports a day.
- Extortion using AI-generated imagery Since 2023 the FBI has recorded the use of deepfake images fabricated from content the victim posted on their own social media. The victim never produced any material at all, and still has something to deny.
The incident the company never hears about
In direct financial terms, this email almost never costs the company money: whoever pays, pays out of their own pocket, and most people do not pay. The real damage is elsewhere, and it is silent. That message is proof that a credential tied to someone at your company is circulating in leaked databases, available to anyone who cares to try it. It is first-rate security information, delivered free to the inbox. And it is precisely the information that never reaches the security team, because the subject is embarrassing and the message orders silence. The FBI itself observes that shame, fear and confusion tend to stop victims from asking for help or reporting the abuse. The result is a company that learns about the leaked password months later, when somebody uses it to actually get in.
What to do when this message arrives
Order matters. The first three decisions belong to the employee and take minutes; the next three belong to the company and they last.
- Do not pay and do not replyReplying confirms the address is live and moves the person onto a better list, which will be resold. Paying settles nothing, because there is nothing to settle. Keep the message, do not delete it.
- Change the displayed password everywhere it still existsThis is the only genuinely urgent technical action. If that password, or any variation of it, still opens something today, the problem is not the email: it is the access it grants.
- Forward the message to whoever handles securityThis is the step embarrassment usually swallows, and the one act that turns personal awkwardness into information the company can use. Forward the whole email, headers included, and say which password appeared. Nothing else needs explaining: the team needs the data, not the story.
- Require a second factor wherever access actually mattersWhere access actually matters, requiring a second factor strips the password of the power to open anything by itself. That credential keeps circulating, but it stops being a key and becomes just an old piece of data: that is what reduces an old breach to an incident with no practical consequence.
- Monitor company credentials appearing in breachesThe point is to discover exposure through monitoring rather than through a blackmail message. Companies that track leaked databases change the password before anyone tries to use it.
- Say in advance, in writing, that reporting carries no personal costA one-line policy, communicated before it happens, is what separates the company that gets the warning from the one left in the dark. Anyone who receives the message needs to know, without having to ask, that alerting the security team exposes nobody and causes no embarrassment.
In one sentence
The password is real; the recording does not exist. Anyone who grasps that difference stops paying and starts doing the one useful thing, which is speaking up. A company that treats this email as an embarrassment loses the warning. A company that treats it as a credential alert gets ahead of whoever bought that list.
How Zamak handles this
For Zamak Technologies, that message is an indicator of an exposed credential, not a content moderation matter. It gets read as a signal: which password surfaced, where it still works, and how many addresses at the same domain were hit in the same wave. From there the work is to shrink the surface the scam runs on: tracking company credentials that show up in leaked databases, requiring a second factor wherever access actually matters, and tightening domain authentication, which blocks the variant where the scammer pretends to write from the victim's own address. The free domain check shows in seconds how that authentication stands. The trail behind the password is always the same pair, the data breach that exposed it and the dark web where it went on sale. This is part of Managed Email Security and Managed Cybersecurity in the Zamak method, and it starts the day the company agrees where this email gets forwarded.