An email claims it recorded your webcam and shows an old password. Do not pay
Mass blackmail uses shame and panic, while an old password supplies credibility. Learn how to distinguish a broad bluff from a real account compromise and respond safely.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 21 September 2026
- READING TIME
- 13 min read
- TOPIC
- Human Security
The message opens with a sentence designed to stop you breathing: “I have access to your device.” The sender claims to have installed spyware, controlled the camera and recorded an intimate video. They threaten to send it to relatives, colleagues and every contact unless cryptocurrency arrives within 24 or 48 hours.
The email includes a password you genuinely used. That makes the rest of the story feel credible. Knowing an old password usually does not demonstrate access to a camera, however. Credentials can come from an earlier data breach and be matched to an email address. The fraudster sends a similar threat at scale, relying on fear and shame to make some recipients pay.
Do not reply or pay. First identify what the message actually contains, secure the accounts and preserve evidence. At the same time, do not assume every threat is automatically a bluff: a message containing genuine private media or evidence of active account access needs an expanded response.
What a password in the message actually proves
It shows that the sender knows a string once associated with your address. It does not show where they obtained it, whether it still works or whether anybody accessed a device.
Leaked databases are copied and combined for years. An old password from a shop, forum or entertainment site may appear in blackmail long after it was changed. The message often omits a real device name, file, recording date or sample because the sender has none.
If the displayed password remains active anywhere, treat that as a separate incident. Change it on that service and every place where it was reused. Start with email because control of a mailbox can support password resets for other accounts.
Common features of a mass bluff
- a generic claim about “advanced software” without a verifiable detail;
- no device name, operating system, file or precise recording date;
- an old or retired password near the top;
- a claim that the email was sent “from your own account”;
- a 24- or 48-hour countdown designed to prevent consultation;
- a cryptocurrency demand sent to one wallet address;
- instructions not to contact police, relatives or specialists;
- a threat to reach “all your contacts” without showing the list.
The sender field may appear to contain your own address. The visible “From” line alone does not prove the email left your mailbox. Review sent items, sign-in history, forwarding rules and active sessions in the provider’s official account panel.
When the situation may be more than a bulk message
Treat it as a possible account compromise or targeted blackmail if the sender:
- supplies a fragment of a genuine private image or video;
- knows a current password or shows an active session;
- quotes recent private correspondence;
- changed account-recovery details;
- publishes material or contacts people you know;
- threatens physical harm and knows your current location;
- obtained media during a relationship, video call or earlier contact.
Do not negotiate alone. Preserve messages and metadata, do not send more images, do not follow instructions, and contact law enforcement. If a minor is involved, seek immediate help from a trusted adult and the appropriate authorities; do not copy or circulate the media as “evidence.”
Adults can also use our separate plan for an intimate image or deepfake shared without consent. The existence of genuine media does not mean payment will prevent distribution.
What to do in the first hour
1. Do not reply or send money
A reply confirms that the address is active and the threat reached a person. Payment gives you no control over an alleged copy. It can instead mark the victim as likely to pay again.
2. Preserve evidence
Capture the sender, subject, date, wallet address and full text. Keep the original email with its headers if you know how to export it. Do not open attachments or follow links.
3. Secure the mailbox
Open email through your own bookmark or app. Create a unique password, end unfamiliar sessions, enable multifactor authentication and review recovery details. Inspect forwarding rules, filters and addresses receiving copies.
4. Eliminate password reuse
If the password in the threat is still used elsewhere, change every occurrence. Do not create a small variation by adding a number. A password manager makes a separate credential for every account practical.
5. Assess the device using evidence
Update the operating system and applications, run a trusted security scan, and review unfamiliar software and extensions. Never install a “video removal tool” linked by the sender. The threat alone does not prove infection, but a basic check is sensible.
Does covering the camera solve it?
A physical camera cover can improve privacy, but it does not address a leaked password or protect a microphone, mailbox and cloud files. Treat it as an additional habit, not evidence that the email was true or false.
Unique passwords, MFA, updates and careful review of application permissions matter more. If the camera indicator behaves unexpectedly or the device has other symptoms, ask a trusted professional for help. Do not call a number in the blackmail message or an unverified advert for “hacker assistance.”
Shame is part of the mechanism
The content is meant to keep the recipient silent. Even somebody who never visited the sites described may fear that others will not believe them. The criminal does not need to know anything about the victim’s behaviour; a stigmatized subject is enough to make asking for help difficult.
Tell one trusted person. Another person can more easily recognize the generic claims, old password and bulk nature of the email. At work, report it to security, especially if it arrived in a corporate mailbox or the password was ever used for work. A responsible reporting process should not demand explanations of private browsing habits.
Do not shame someone who receives this threat. A calm response increases the chance that they disclose follow-up messages, suspicious sign-ins or genuine media.
If you already paid
Do not send another amount when the sender promises “final deletion.” Preserve the wallet address, transaction identifier, amount and time. Contact the exchange or service used to purchase the cryptocurrency and report the matter to law enforcement. Cryptocurrency transfers can be hard to reverse, but the records remain valuable evidence.
Be cautious of a later offer to recover the funds or hack the extortionist for an upfront charge. Details about somebody who paid can lead to another fraud. Report the email through your national phishing or cybercrime service.
What the sources confirm, and what Breachroad recommends
The UK National Cyber Security Centre describes this scheme as phishing: the sender commonly does not know whether the recipient owns a webcam or visited the named sites, while technical language and a password make the bulk bluff feel credible. The US Federal Trade Commission confirms that a password can originate in an earlier breach and advises recipients not to pay Bitcoin blackmail demands.
The distinction between a mass bluff and targeted compromise, the first-hour plan and trusted-person check are Breachroad recommendations. They do not replace law-enforcement help for a genuine threat. Our guide to strong password myths and practical protection covers the credential problem, while teams can practise safe reporting through our employee cybersecurity training.
