It shows one of your actual passwords, claims to have recorded you through your webcam, and demands Bitcoin or it goes to everyone you know. It is terrifying by design — and it is a bluff sent to millions of inboxes at once. There is no video. Here’s where that password really came from, and exactly what to do.
Published 2 August 2026 · ~7 min read · By the Phixo team
Few emails land harder than this one. It opens by quoting a password you recognise — maybe one you still use — then claims the sender installed malware on your device, filmed you through your webcam while you visited an adult site, and copied your contacts. Pay a few hundred to a few thousand dollars in Bitcoin within 48 hours, it says, or the video goes to your family, friends and colleagues.
Take a breath. This is called sextortion, and despite the personalised password, it is a mass-produced bluff. The same message, word for word, is sitting in millions of other inboxes right now with a different password pasted in. The sender has no video, no malware on your device, and often not even your real name. Understanding why makes the fear collapse — so let’s take it apart.
Do not pay, and do not reply. The password almost certainly came from an old data breach at some website you once had an account on — not from hacking your computer. The webcam “recording” does not exist. Check which breaches your email appears in at haveibeenpwned.com, change that password anywhere you still use it, turn on two-factor authentication, and delete the email (or report it). Paying only marks you as someone who pays, and invites more demands.
The whole scam hinges on one moment of shock: they know my password, so they must have hacked me. They didn’t. When a website you once signed up for suffers a data breach, the leaked lists of email addresses and passwords get traded, sold and dumped publicly — sometimes years later. There are billions of these records in circulation. Scammers buy a batch, and a script pastes each person’s own leaked password into the threatening template.
Proof you can check in 60 seconds: go to haveibeenpwned.com, a free, well-known service run by a security researcher, and enter your email address. It lists the known breaches your address appeared in. If the password in the email is an old one you used on a breached site, that’s the whole story — no hacker, no webcam, just a leaked list.
If the password shown is one you still use anywhere, that’s the one genuinely useful thing this email tells you: change it now, everywhere it appears, and never reuse it again. The scam is fake; the password exposure is the real (and fixable) problem.
The “I recorded you through your webcam” claim is engineered to trigger shame, because shame makes people act fast and tell no one. But look at what the email never does: it never actually shows you a frame of the supposed video, never names the site, and never proves anything beyond a password anyone can buy. Real extortion with real material leads with the material. These emails lead with a threat and a countdown because that is all they have.
Variants add technical-sounding detail — “I used a zero-day,” “I’m watching you type this,” “don’t bother resetting, I’ll know” — and some spoof your own email address in the “From” field to look like they sent it from your account. That, too, is a trick: spoofing a sender address takes no access to the account at all. It is the same surface-level fakery we break down in the warning signs of a phishing email.
A single password — often one you haven’t used in years — and nothing else verifiable. No video still, no screen recording, no detail only a real intruder could know.
Bitcoin (or another coin) to a wallet address, within 24 to 48 hours. Crypto is chosen because it’s hard to reverse and hard to trace — and the deadline exists to stop you thinking or checking.
Isolation is the tool. The email actively discourages you from doing the two things that dissolve it instantly: talking to someone, and looking it up. A genuine threat doesn’t care whether you Google it.
No real name, no company, no specifics about you. “I know Summer2019! is your password” is as personal as it gets — because that string is literally all the sender bought.
Because these are blasted from throwaway or spoofed senders, they routinely fail the behind-the-scenes checks (SPF, DKIM, DMARC) that confirm a message really came from where it claims. You can see this yourself with our free email header analyzer — and it’s one of the signals Phixo weighs automatically.
First, breathe: you were never actually in danger, because there was never a recording. But do report it. Cryptocurrency payments are usually irreversible, yet reporting quickly to ic3.gov (or your local equivalent) is still worth it — occasionally it helps, and it always feeds the data that shuts these operations down. Expect follow-up demands (“send more or I release it”) and ignore every one; paying once is exactly what marks a target for more. Then do the account cleanup above — unique passwords and two-factor everywhere. If you entered your password into any linked page as part of this, our guide on what to do if you gave your password to a phishing site covers the full recovery.
Almost always from an old third-party data breach, not your device. Leaked email-and-password lists are traded for years; a scammer buys one and pastes your own password into the template so it feels like proof. Check your breaches free at haveibeenpwned.com — and change any password you still reuse.
No. These are sent by the million as a template — no video, no malware, often not even your correct name. The claim exists to trigger panic and shame so you pay before you check.
Don’t pay, don’t reply. Change the exposed password anywhere you still use it, turn on two-factor authentication, then delete or report the email — in the US to the FBI at ic3.gov, or via “Report phishing” in your mail app.
You’re not in danger — there was no recording — but report it to ic3.gov or your local equivalent, ignore any follow-up demands, and secure your accounts with unique passwords and two-factor authentication.
Phixo is a browser extension that checks the email open in your Gmail or Outlook against several signals — sender and domain reputation, link mismatches, lookalike domains, and email authentication (SPF, DKIM, DMARC) — plus an AI read of the language that flags extortion and pressure tactics like these in seconds. Free plan includes 10 scans a day, no credit card. A one-time Google or Microsoft sign-in keeps your scan count tied to your account.
Install Phixo free →Your email body is never stored. Analysis happens in real time and is discarded immediately.