At some point, a large share of internet users receive an email claiming the sender has compromising material, has hacked their computer, or has recorded them through their own webcam, and demanding a cryptocurrency payment to prevent it from being shared with contacts, family, or the public. This is one of the most common forms of cryptocurrency related fraud, and it works because it is designed to trigger panic before a victim thinks clearly. This guide explains how these scams actually function, why bitcoin is almost always the demanded payment, and what to genuinely do if you receive one.
The Basic Structure of a Crypto Extortion Email
Despite countless variations, the vast majority of these messages follow a nearly identical template, which is itself a useful clue about how they are produced and distributed at scale.
- A claim that the sender has installed malware on your device, often citing a password you actually once used as proof, typically obtained from an old, unrelated data breach
- A claim they recorded you through your webcam while you visited an adult website, or that they have accessed private photos, messages, or files
- A threat to send this material to your entire contact list, post it publicly, or notify your employer or family, unless payment is made within a short deadline, often 24 to 48 hours
- A demand for payment specifically in bitcoin, sent to a wallet address included directly in the email
- Language designed to discourage reporting, such as a claim that they are monitoring your response or that involving the police will trigger immediate release of the material
In the overwhelming majority of documented cases, this is a complete bluff. There is no actual malware, no webcam recording, and no compromising material. The email is sent in bulk to enormous mailing lists, and the old password included as proof was pulled from a previously leaked, unrelated data breach that has nothing to do with your current device.
A Worked Example, Annotated Line by Line
A typical message opens with a line like, I know your password is [an old, real password], I have full access to your device. This line relies entirely on the recipient's shock at seeing a real password, and it is almost always sourced from a breach at some unrelated website years earlier, not from any actual current access. It continues with something like, I installed a trojan through an adult website you visited, and I have recorded video through your webcam. This claim is generic by design so that it applies broadly to as many recipients as possible, and it is presented with confident, specific sounding technical language, malware, trojan, remote access tool, to sound more credible than it actually is.
The message then typically states a deadline, send the equivalent of a few hundred dollars in bitcoin to the following address within 48 hours or I will send this video to everyone in your contact list. The specificity of the dollar amount and the short deadline are both deliberate pressure tactics. It usually closes with a warning against contacting the police, since I am monitoring your inbox, a claim with no technical basis given that the sender has no actual access to the recipient's device or accounts. Reading the email with each of these tactics identified individually makes the bluff far easier to recognize than reading it in a moment of panic.
Common Misconception: Paying Once Will End It
A significant number of people who pay a bulk extortion demand do so believing it resolves the situation permanently. In practice, paying confirms two things to the sender: that the target's email address is active and monitored, and that the target is willing to pay under pressure. Both of those facts make a repeat target more valuable, not less, and it is common for the same or a different extortion campaign to follow up against someone who has already paid once, sometimes within weeks, often with a higher demand the second time. There is no verification step, no confirmation, and no actual account of who has or has not paid beyond what the sender's own bitcoin wallet shows, and even that offers no real way for the sender to distinguish a payment as final versus a payment as an invitation to try again.
Why Bitcoin Specifically
Bitcoin is overwhelmingly the currency of choice in these campaigns, for practical reasons rather than any special connection to the threat itself. It can be sent globally without a bank intermediary, it does not require the sender's identity to be verified the way a wire transfer does, and a wallet address can be generated instantly and used across an enormous volume of identical emails sent to different targets. Research analyzing sextortion campaigns has found bitcoin used in effectively all documented cases, precisely because these properties make it the path of least resistance for a scammer operating at scale rather than targeting any one individual.
How Common and How Costly This Actually Is
Extortion consistently ranks among the most commonly reported categories of internet crime in FBI data, with tens of thousands of reports annually in the United States alone, and reported financial losses running into the tens of millions of dollars each year. Individual payments tend to be relatively modest by cryptocurrency fraud standards, often in a range of a few hundred to a couple thousand dollars, which is itself a deliberate choice, since a smaller demand is more likely to be paid quickly by a panicked recipient without pausing to verify the threat.
A More Serious Variant: Targeted Sextortion
A distinct and considerably more serious category involves cases where the threat is not a bluff, most often targeting minors or young adults who were previously manipulated into sharing real images or video through a fabricated online relationship, sometimes built through a fake dating profile or social media contact over an extended period. This variant, sometimes called financial sextortion, has been linked to organized criminal groups operating internationally and has resulted in documented tragic outcomes. If real material genuinely exists because of a prior online relationship, this should be treated as a serious criminal matter and reported immediately to law enforcement and, for cases involving minors, to the National Center for Missing and Exploited Children, rather than handled as a routine spam email.
How to tell a bluff from a genuine case
The distinction usually comes down to a simple question: did any actual prior relationship, conversation, or exchange of images occur with the person making the threat, even if that relationship turned out to be built on a fake identity. A bulk extortion email arrives out of nowhere, with no prior contact, and references nothing specific to the recipient beyond a recycled password. A targeted case follows weeks or months of actual conversation, often on a dating app, social media platform, or messaging app, during which images or video were genuinely shared, and the person making demands can produce that real material because they actually have it. If there was never any prior relationship or exchange, treat the threat as almost certainly a bluff. If there was, treat it as a genuine and serious matter requiring law enforcement involvement rather than a decision to make alone.
What to Actually Do if You Receive One
- Do not pay. Payment does not make the threat go away, and it confirms to the sender that your email address belongs to someone willing to pay, which frequently leads to repeat demands
- Do not reply to the email or engage with the sender in any way, since this also confirms the address is active and monitored
- Change the password referenced in the email if you still use it anywhere, and check whether that password appears in a known data breach using a reputable breach lookup service
- Enable two factor authentication on your important accounts, particularly email, since email compromise is a common vector for a wide range of unrelated fraud
- Report the email to the FBI Internet Crime Complaint Center at ic3.gov, including the full message and the bitcoin address if one was provided, which helps agencies track and occasionally disrupt these campaigns
If you do have a genuine reason to believe your device is actually compromised, separate from the claims in the email itself, such as unexplained account activity or software you did not install, treat that as its own security incident and have the device professionally reviewed rather than assuming the extortion email's claims are accurate just because something else seems wrong.
If You Already Paid
If you paid an extortion demand, first confirm whether any further demands follow, since paying once frequently leads to a second, larger demand rather than resolution. Report the payment through IC3, and preserve the original email and the transaction details, including the wallet address and transaction hash. While recovering funds sent to an extortionist is difficult, since these operations are specifically built to avoid identification, the transaction can sometimes be traced as part of a broader investigation, similar to the process described in our guide on how to trace stolen Bitcoin, even when a specific individual recovery outcome cannot be promised.
It is also worth being alert to a predictable follow up: being contacted afterward by someone offering to help recover the money you already paid, which is frequently itself a recovery scam, covered in our guide on cryptocurrency recovery scams.
- The full original email, including headers if possible, since header data can sometimes reveal the sending infrastructure even when the visible sender address is spoofed
- The bitcoin address the demand was sent to, and the transaction hash if a payment was made
- Any screenshots or attachments the sender included as supposed proof
- A note of the exact date and time the email arrived and, if a payment was made, the exact date and time of that transaction
Frequently asked questions
Almost always from an old, unrelated data breach at some other website or service, where your email and password combination was exposed and later circulated or sold in bulk on criminal marketplaces. It does not mean your current device or accounts are actually compromised, but it does mean you should stop reusing that password anywhere.
This is unsettling but still usually part of the same bluff, since personal details like an address or phone number are often included in the same breached data sets or are purchased separately from data broker leaks, and do not by themselves indicate the sender has actual compromising material or ongoing access to your device.
These campaigns are typically run by organized groups operating from overseas, using bitcoin specifically because it complicates tracking, which makes individual arrests uncommon for routine bulk campaigns. Reporting still matters, since aggregated reports support broader law enforcement action against the larger criminal infrastructure behind these campaigns.
A bulk extortion email is a bluff sent to a huge number of recipients with no actual access to any device. Ransomware is a real malware infection that actually encrypts a victim's files or systems, and the extortion demand follows a genuine, verifiable technical compromise, which our guide on ransomware payments covers in detail.
The transaction itself can generally be traced on chain the same way any other cryptocurrency payment can, following the wallet address through subsequent hops. Whether that trail leads anywhere actionable depends on where the funds eventually moved, since bulk extortion operators typically launder small payments quickly, but reporting the transaction hash and wallet address still contributes to broader investigative efforts.
Sources and further reading
- Sextortion Scams · Chainabuse
- Scam Alert: Beware of sextortion emails · Better Business Bureau
- Cryptocurrency Crime Information · Internet Crime Complaint Center, Federal Bureau of Investigation