Back
Aug 03, 2026
8
CrackEmail

Your Account Was Hacked and They Are Demanding Money

Most extortion emails are a bluff built on a leaked password database, and that is checkable. How to tell, what to do, and when the threat is real.

Your Account Was Hacked and They Are Demanding Money | CrackEmail

An email says someone has been inside your device for months, recorded you through the webcam, copied your contacts and chats, and will send all of it to your friends unless you pay in cryptocurrency within 48 hours. Then you see your password printed in the message, and it is real, or it was once.

[[answer]]Almost all of these messages are mass-sent bluffs built on old leaked password databases. The sender has no access to your device and no recordings. Check whether the password appears in a known breach, change it everywhere, turn on two-factor authentication or a passkey, save the message as evidence, and do not pay.[[/answer]]

That recognition is the whole trick: a message sent to hundreds of thousands of addresses suddenly feels personal. Nothing in it needs an answer in the next ten minutes.

Why most of these messages are bluffing

Extortion mail of this kind is a volume business. Someone buys a dump of addresses and passwords from an old breach and sends one template to every address on it, with the password inserted automatically. There is no surveillance and no folder of screenshots — only a spreadsheet and a mail server.

The tells are consistent. The message never mentions anything specific: no site you actually use, no real conversation, no name. It describes what it supposedly has instead of showing it, demands cryptocurrency because that payment cannot be reversed, and sets a short deadline, because a frightened person who thinks for a day stops being frightened. If it appears to come from your own address, that proves nothing either: a sender field is as forgeable as the return address on an envelope. Knowing [[post:how-personal-data-is-collected-online|where these databases of emails and passwords come from]] takes much of the menace out of it.

How to check whether the password actually leaked

You do not have to guess. Free breach-notification databases index credentials from public dumps and let you search by email address; Have I Been Pwned is the best known and runs as a public-interest project. If your address appears next to a site you recognise, and the year matches when you used that password, the mystery is solved.

The check is strong in one direction only, and that limit matters. A hit tells you the password has been in circulation for years, which points at a bluff. Finding nothing tells you only that no indexed dump contains your address — plenty of stolen data is never published, never parsed, or sits in private trade. The largest single source of stolen logins today is not a hacked website at all but infostealer malware: software that empties the saved-password store of an infected computer and ships it out in bulk. Have I Been Pwned indexes part of this material separately as stealer logs, and single batches added tens of millions of unique addresses through 2025 and 2026. So read an empty result as «unproven», never as «my password never leaked» and never as evidence that the threat must be real.

Google and Apple both put a checker inside their own password managers, which is usually the faster route. Google's Password Checkup compares saved passwords against known leaks. On iPhone and iPad the equivalent lives in the separate Passwords app, in its Security section; the detection itself is switched on in Settings → Apps → Passwords → Detect Compromised Passwords. Both show which logins reuse the same password, usually the more urgent question. One rule: search by email address, and never type a current password into a site you cannot verify. Some legitimate tools are built so the password never leaves your device — Have I Been Pwned's password search sends only a short prefix of a hash and compares the rest locally — but that is a property to confirm before typing, not to assume.

What to do in the first hour

[[steps]] Do not reply and do not pay :: Any response tells the sender the address is live and belongs to someone who reacts, which moves you onto a shorter, more aggressive list. Check the password against breach records :: Work out which account it belonged to, then search your email address in a breach index. A match settles it in favour of a bluff; finding nothing settles much less, because not every dump is indexed. Change that password everywhere it was used :: Not just the original site. Reuse turns one old breach into ten live accounts. Turn on two-factor authentication, or a passkey where it is offered :: An app code, a hardware key or a passkey is the difference between a stolen password being an inconvenience and a break-in, and a passkey leaves no shared secret for the next breach to leak. Review active sessions and connected apps :: Every major service lists signed-in devices and apps with access. Sign out anything unfamiliar. Save the evidence and tell someone :: Keep the message with its headers, and say it out loud to one person you trust — shame and isolation are what make this work. [[/steps]]

When the threat is real

A minority of cases involve genuine access, and then one password change is not enough. The signals below are read together, not one at a time: no single row proves anything by itself.

[[compare]] Signal | Mass-sent bluff | Real compromise | How to check it Password quoted | Old, or used only on a minor site | Current, and never reused | Search your address in a breach index: a hit points to a bluff, no hit proves nothing either way Proof offered | None, or a vague description | A file or message you recognise | Ask whether that proof could come from a public profile Account activity | Login history looks normal | Unknown devices, new app passwords | Open the security or devices page of the account Where it arrived | Old address, generic template | Inside a chat you use, or from your own account | Check the Sent folder and the message headers [[/compare]]

Account activity is the row that carries the most weight, because it is the only one the sender cannot stage. If a contact received messages you never wrote, your recovery email changed without you, or you were logged out of a service you never left, treat it as an active break-in and follow the steps for when [[post:someone-signed-into-my-account|someone actually signed into your account]]. Real device compromise is rarer still and leaves signs — fast battery drain, unexplained data use, unfamiliar admin apps — which is [[post:what-is-spyware-programs|how spyware really behaves on a phone]].

Why paying rarely ends it

People who pay are recorded as people who pay. The pattern reported over and over is that payment is followed within days by a second demand with a larger figure, because the first one proved the target could be pressured. Nothing obliges anyone to delete anything, and in a bluff there is nothing to delete. Even in the rare case where material genuinely exists, payment buys a promise from someone anonymous by design, who has no way of demonstrating that a copy was destroyed.

Where to report it

Reporting rarely gets one message investigated, but it feeds the data that shuts down wallets and campaigns. In the United States the FTC takes reports at reportfraud.ftc.gov and the FBI runs the Internet Crime Complaint Center, which takes complaints about online extortion. In the United Kingdom that role now belongs to the Report Fraud service run by City of London Police — online at reportfraud.police.uk or by phone on 0300 123 2040 — which replaced Action Fraud over the winter of 2025–2026 and covers England, Wales and Northern Ireland; in Scotland, report to Police Scotland on 101. Mark it as phishing in your mail client too, and if it came through a messenger, use the in-app report tool — Apple documents how to block, filter and report messages on iPhone. If the person targeted is under 18, go straight to law enforcement or a child-protection takedown service.

Making the next one harmless

The reason a password leaked years ago can still frighten you today is reuse. Once every account has its own password and second factor, an old breach becomes trivia rather than a lever, and the password managers built into iOS, Android and browsers are enough for most people. Where a service offers a passkey, take it: the credential stays on the device or in the password manager and nothing reusable is stored on the server, so a future breach of that site has nothing to sell. Apple, Google and Microsoft accounts all support passkeys, and the built-in managers sync them across devices.

Keep recovery contacts current and cover a laptop webcam if it makes you calmer. If the checks above pointed to a bluff — an old password, no specific proof, clean login history — then nobody looked at you individually in the first place, and the next message like this will arrive as text on a screen, nothing more. If they pointed the other way, the section on real compromise is the one to work through first.

[[faq]] The email showed my real password — does that mean they hacked me? :: Not by itself. Passwords leak in bulk from breached websites and from malware that empties saved-password stores, then get resold in lists, so quoting one proves only that it was in circulation. I searched my email in a breach index and found nothing — is the threat real then? :: No. Indexes only cover dumps that were published and processed, so an empty result means «unconfirmed», not «never leaked». Judge the threat by login history and devices, not by the absence of a record. The message came from my own address, so are they inside my account? :: Sender addresses can be forged, and this is standard in these campaigns. Check your Sent folder and login history: if the message is not there and no unfamiliar devices are listed, nothing was sent from your mailbox. Should I pay if I really do have something embarrassing? :: No. Payment marks you as someone who pays, and a second demand commonly follows. If genuine material exists, report it rather than negotiating — an anonymous sender cannot show that a copy was deleted. What if I already replied to them? :: Stop responding, change the passwords on the accounts named or implied, enable two-factor authentication or passkeys, and expect further attempts. A reply gives nobody access to anything. [[/faq]]

Did this answer your question?