Skip to Content
Threats and Attacks · Social engineering and fraud

What is sextortion?

Sextortion is extortion that uses intimate content as blackmail currency, whether real or merely claimed. In the version that lands in corporate inboxes every day, the sender claims to have recorded the victim through their webcam and displays a genuine password as proof of access. The password is usually authentic, taken from an old breach. The recording does not exist. It is a volume scam, blasted to thousands of addresses on a purchased list, not an attack aimed at you. But what it reveals about your company is true.

Zamak TechnologiesUpdated on August 7, 2026

How the sextortion email is assembled

There is no break-in, no webcam switched on and nobody watching your company. What exists is a cheap assembly line that trades precision for scale and bets that, in every thousand recipients, someone will believe it enough to pay in silence.

1

Raw material bought ready-made

The criminal starts from a list of email addresses with matching passwords, compiled from breaches at old websites and sold on. When victims of the scam check, the password on display is usually old: close to ten years in the cases Krebs documented, from a service they barely remember using.

2

Credibility borrowed from a real piece of data

The password appears in the very first line, because it is what makes the message feel true. Recent campaigns add full name, phone number, street address and even a map image of the street where the person lives, all drawn from the same leaked databases. None of that proves access to the computer; it only proves the data is in circulation.

3

Delivery through a legitimate account already compromised

This is where the corporate filter fails. The messages that reach the inbox come from senders and network addresses with good reputation, because the criminals use corporate or personal email accounts they broke into earlier. The filter sees a trusted sender, not a suspicious origin.

4

A short deadline and a figure pulled from nowhere

The message gives a short deadline, twenty-four hours in the documented example, and demands payment in cryptocurrency, almost always bitcoin, these days through a QR code pasted into the body of the email. The amount is not calculated against anyone's income: in the campaigns analyzed in 2018 it was drawn at random, a digit from one to seven followed by three zeros; in recent campaigns it became a fixed figure, the same for everyone, in the region of two thousand dollars. Either way, it bears no relation to the person receiving it. What the urgency is designed to produce is a decision made alone, without consulting anyone.

Sources: Cisco Talos, analysis of 233,236 messages from two campaigns (2018); Krebs on Security (2018); Barracuda, Threat Spotlight (2024); Sophos, payment tracking (2020).

How to recognize it

  • The message shows a password of yours, but an old one, no longer used anywhere that matters
  • Nothing beyond the password is specific: no file name, no date, no time, no verifiable detail
  • The deadline is short and counted in hours, twenty-four in the documented examples
  • Payment is demanded in cryptocurrency, by bitcoin wallet address or QR code
  • The text explicitly forbids you from telling anyone or seeking help
  • The sender sometimes claims to have sent the message from your own account, which is usually just a forged sender field, that is, spoofing
  • The same message, with small variations, reaches several colleagues in the same week

The forms sextortion takes

  • Mass email extortion The bluff described above, with no material behind it at all. It is the form that reaches corporate inboxes in volume, and what this entry sets out in detail. Unlike phishing, there is no link or attachment to click; unlike BEC, nobody impersonates an executive asking for a transfer. The only lever is embarrassment.
  • Extortion with real material Preceded by social engineering, days or weeks of approach, until the criminal obtains images of the victim and starts threatening to publish them. Here the content is real, and the response changes in kind: preserve everything as evidence, delete nothing, and involve law enforcement.
  • Financial sextortion of teenagers An organized, transnational form, run at scale by criminal groups, aimed at minors with money as the objective. The FBI referred more than 5,700 cases involving minors to NCMEC, the US National Center for Missing & Exploited Children, in 2025, and the center logs around 137 reports a day.
  • Extortion using AI-generated imagery Since 2023 the FBI has recorded the use of deepfake images fabricated from content the victim posted on their own social media. The victim never produced any material at all, and still has something to deny.

The incident the company never hears about

3%
of all targeted phishing attacks detected each year, roughly, are extortion emails, and they reach the inbox because they are sent from legitimate accounts already compromised, carrying good reputation (Barracuda, 2024)
33,916
sextortion complaints to the FBI in 2025 came from the 20-to-39 age bands combined, more than half of the 64,283 with an age recorded: most victims are of working age (IC3 2025)
0.5%
is how much each volley of messages converted into payment in a campaign tracked over five months across 2019 and 2020: only 328 of nearly 50,000 wallets ever received anything (Sophos, 2020)

In direct financial terms, this email almost never costs the company money: whoever pays, pays out of their own pocket, and most people do not pay. The real damage is elsewhere, and it is silent. That message is proof that a credential tied to someone at your company is circulating in leaked databases, available to anyone who cares to try it. It is first-rate security information, delivered free to the inbox. And it is precisely the information that never reaches the security team, because the subject is embarrassing and the message orders silence. The FBI itself observes that shame, fear and confusion tend to stop victims from asking for help or reporting the abuse. The result is a company that learns about the leaked password months later, when somebody uses it to actually get in.

What to do when this message arrives

Order matters. The first three decisions belong to the employee and take minutes; the next three belong to the company and they last.

  1. Do not pay and do not replyReplying confirms the address is live and moves the person onto a better list, which will be resold. Paying settles nothing, because there is nothing to settle. Keep the message, do not delete it.
  2. Change the displayed password everywhere it still existsThis is the only genuinely urgent technical action. If that password, or any variation of it, still opens something today, the problem is not the email: it is the access it grants.
  3. Forward the message to whoever handles securityThis is the step embarrassment usually swallows, and the one act that turns personal awkwardness into information the company can use. Forward the whole email, headers included, and say which password appeared. Nothing else needs explaining: the team needs the data, not the story.
  4. Require a second factor wherever access actually mattersWhere access actually matters, requiring a second factor strips the password of the power to open anything by itself. That credential keeps circulating, but it stops being a key and becomes just an old piece of data: that is what reduces an old breach to an incident with no practical consequence.
  5. Monitor company credentials appearing in breachesThe point is to discover exposure through monitoring rather than through a blackmail message. Companies that track leaked databases change the password before anyone tries to use it.
  6. Say in advance, in writing, that reporting carries no personal costA one-line policy, communicated before it happens, is what separates the company that gets the warning from the one left in the dark. Anyone who receives the message needs to know, without having to ask, that alerting the security team exposes nobody and causes no embarrassment.

In one sentence

The password is real; the recording does not exist. Anyone who grasps that difference stops paying and starts doing the one useful thing, which is speaking up. A company that treats this email as an embarrassment loses the warning. A company that treats it as a credential alert gets ahead of whoever bought that list.

How Zamak handles this

For Zamak Technologies, that message is an indicator of an exposed credential, not a content moderation matter. It gets read as a signal: which password surfaced, where it still works, and how many addresses at the same domain were hit in the same wave. From there the work is to shrink the surface the scam runs on: tracking company credentials that show up in leaked databases, requiring a second factor wherever access actually matters, and tightening domain authentication, which blocks the variant where the scammer pretends to write from the victim's own address. The free domain check shows in seconds how that authentication stands. The trail behind the password is always the same pair, the data breach that exposed it and the dark web where it went on sale. This is part of Managed Email Security and Managed Cybersecurity in the Zamak method, and it starts the day the company agrees where this email gets forwarded.

Frequently asked questions about sextortion

Do they really have a video of me?
In the mass variant, almost certainly not. The tell is in what is missing: if material existed, the message would cite a verifiable detail, such as a date, a file name or a fragment. What these messages present is always the same thing, an old password from a breach, because it is the only true piece of data the sender holds. The threat to send it to your contacts is part of the standard script, fired identically at thousands of addresses; there is nothing to send. The variant with real material does exist, and it is different: there was prior contact, a conversation that ran for days, and the person knows it happened.
How did they get my password?
From a breach at a website you signed up to years ago, not from your computer and not from your company. These lists are sold ready-made, address and password side by side. That is why the password on display is usually old and tied to a service you have all but forgotten. The useful question is not how they reached it, but where it still works today.
Should I pay to make this go away?
No. There is no material to destroy, and in a five-month tracking study of one campaign only 328 out of roughly 50,000 wallets ever received a payment, which shows the model lives on send volume rather than individual success. Paying does not close the matter either: it flags an address that responds to pressure, and that address gets targeted again. And if you have already paid, there is nothing to recover on the other side, but there are two things to do today: change the displayed password everywhere it still exists, and tell the security team.
Is this the company's problem or the person's?
The message is addressed to the person, but the data it exposes belongs to the company. A credential tied to an employee is in circulation, and nobody knows where it still opens a door. Add to that the fact that these lists are organized by email address: if the breach reached the company domain, it is the whole domain on the list, not one person.
Is it worth putting it on record?
It is, for two separate reasons. The first is internal: the security team needs to know which password surfaced, in order to check where it is still valid. The second is external: these measurements exist because people report. The FBI logged more than 75,000 sextortion submissions in 2025. And the series Europol tracks in its IOCTA 2026 report shows the curve on the gravest side of it: reports of financial extortion involving minors received by NCMEC in the first half of the year went from 13,842 in 2024 to 23,593 in 2025, a rise of about 70%.
And when the victim is a teenager?
That is not a volume scam but organized transnational crime with a chosen target. Official guidance is not to pay, not to delete the conversations, to preserve everything and to involve law enforcement immediately. The FBI itself points to Take It Down, the free service from NCMEC, the US National Center for Missing & Exploited Children, which helps get the material removed from the internet. And there is one sentence the family needs to hear without hedging: the fault never lies with the person who was coerced.

Related terms