The Sextortion Email That Names Your Password: Why It’s a Scam and What to Do
The key is the password. Scammers buy millions of stolen passwords from old data breaches at websites and apps. They mash together email addresses and passwords in bulk, then send extortion emails that include one of those exposed passwords to make you think they have been inside your computer. That password is not proof of a hack. It is proof that you used it somewhere that got breached. The webcam video threat is a fiction. They did not record you. They do not have a file. They have no idea what you look like. Passwords from breaches are often years old, but they are still useful to criminals for exactly this kind of lie.
This scam works because it plays on shame and secrecy. People in middle age often worry they will be judged for their private online activity. They might not tell anyone. They might pay to make the problem disappear. That is exactly the trap. If you pay, you confirm your address is valid, your fear is real, and your wallet is open. You will get another demand, often higher. Paying never ends it.
If you receive a message like this, do not pay, reply, argue, or click any links or attachments. The attachment might actually contain malware. Delete the message. No matter how panicked you feel, do not send money or reveal more personal information. If you want to keep a copy for reporting, save it to a folder or take a screenshot, but do not interact with the sender.
Do not assume your device is infected. Run a security scan if you want peace of mind, but the urgent task is password hygiene. The password they showed you may still be in use. Change it immediately. Change the password on your primary email account first, because scammers can use it to reset passwords for everything else. Then change passwords on banking, retirement, and healthcare accounts. Use a unique, long passphrase for every site. Use a reputable password manager. Turn on two-factor authentication wherever it is offered, especially for email and financial accounts.
Understand that these threats are not targeted. The same email goes to tens of thousands of people at once. Scammers do not know your habits, your family, or your friends. Their goal is volume. For every ten thousand emails, a few frightened people will pay. They are not watching you through a camera. That would be expensive and pointless.
There are variations. A “hitman” email claims a contract has been taken out on your life. A message from “law enforcement” says you missed jury duty or owe back taxes. A text includes a photo of your house pulled from Google Maps, implying the sender is nearby. All use the same playbook: create urgency, invoke fear, demand untraceable payment. None of it is real.
If the message contains a password, check whether it is old. If it is, the breach database explanation is nearly certain. If it is a current password, change it right away, but still do not pay. The sender cannot prove they have a video, and no legitimate extortionist expects you to comply without proof. The scam relies on you filling in the blank with the worst possible scenario.
The best defense is calm. Delete the message, update your credentials, and move on. You were not hacked because you did something wrong. You were targeted because your email address appeared in a breached list someone bought for pennies. Report the email to the FBI’s Internet Crime Complaint Center and the Federal Trade Commission. The scammers want your money, not your secrets. They have no secrets. They just have a stolen password and a scary story.


