Skip to content
VaultPass

Breaches

You get an email claiming they filmed you and want bitcoin

The VaultPass desk4 min read
Old postal envelope on a wooden surface

An email arrives in a flat tone: they installed software, recorded you through your own webcam, and will publish the video unless you pay in bitcoin within 48 hours. To make you believe it, they include a password that is genuinely yours. There is no video, there is no software, and that password has a far duller explanation.

The email always has the same shape. The subject line carries your address, or the password itself. The text says, in English that is sometimes flawless and sometimes robotic, that months ago they installed software on your machine, switched on your webcam while you visited certain sites, and now hold both the recording and your contact list. They want somewhere between £400 and £2,000 in bitcoin, with a short deadline: 24 or 48 hours.

As proof, they include a password you recognise.

That detail is what turns a lot of stomachs. And it is precisely the intended effect.

The truth, in two sentences

There is no recording. There is no software on your computer.

This is an automated campaign. The same text goes out to millions of addresses, with the name and password swapped in by a program. Whoever sent it does not know who you are, has not been inside your machine, and holds no material of any kind. They only need a tiny fraction of recipients to pay.

So where did my password come from?

From a data breach, almost certainly.

When any service — a shop, a forum, an app you signed up to eight years ago and have forgotten — suffers a breach, the list of emails and passwords ends up circulating. It is sold, shared, and eventually published for free. From there, anyone can take that list and build an extortion campaign on top of it.

It is the same raw material that feeds credential stuffing, except that here, instead of trying the password, they show it to you to frighten you.

You can check for yourself with the leaked password checker. If the password from the email turns up there, you have the whole explanation. How those lookups work without exposing your keys is covered in how to check if your data has been leaked.

The tells

Even once you know, the pattern is worth recognising:

  • A short deadline and a countdown. Hurry prevents thinking. It is the number one tool of every scam.
  • Payment in cryptocurrency. Irreversible and hard to trace. No real-world blackmailer asks for a bank transfer.
  • No concrete proof. They never attach a screenshot, a fragment, anything. If they had something they would show it: it is the only thing that would give the threat force.
  • A generic threat. No specific site, date or device is named. It has to fit everyone.
  • Sent from your own address. Sometimes it looks like you emailed yourself. That is sender spoofing, an old and trivial trick that proves no access whatsoever.

It is the same family of signals set out in how to spot a phishing email: urgency, nothing you can verify, and a payment channel with no way back.

What to do, in order

1. Do not pay. There is nothing to publish. And paying marks you as an address that responds, which brings more attempts.

2. Do not reply. Not to argue, not to ask. Any reply confirms the address is live.

3. Change that password. This is the only part that genuinely matters. If that password is still in use anywhere, change it everywhere. The full guide is in what to do if your password is leaked.

4. Turn on two-step verification, on your email at the very least. Even with the password, nobody gets in without the second factor. The rundown of methods is in two-factor authentication explained.

5. Mark as spam and delete.

6. Report it if you want to. In the UK, suspicious emails can be forwarded to the National Cyber Security Centre’s reporting address, and Action Fraud takes reports. There is rarely anything to chase, but the aggregate data is useful.

When it is worth worrying

There is a different, much rarer variant where the blackmail is not automated: someone you actually had contact with — a conversation, an exchange of images — threatens to spread them. There, material does exist, and so does a crime.

In that case the advice inverts: do not pay, do not delete the conversations (they are the evidence), keep dated screenshots, and go to the police. It is a prosecutable offence and there are specialist units.

The difference between the two cases is simple: the mass scammer cannot name anything specific. The real blackmailer can.

The short version

  • The webcam-and-bitcoin email is an automated campaign. The video does not exist.
  • The password inside came from an old data breach, not from your computer.
  • Neither pay nor reply: both confirm the address is live.
  • The only urgent task is changing that password wherever it is still in use, and enabling two-factor.
  • If the threat names something specific and real, it stops being this scam and becomes a police matter.

Frequently asked

The questions that keep coming up

Is the email claiming to have webcam footage of me real?

Almost always false. It is an automated scam sent to millions of addresses with identical text. There is no recording, no access to your computer and no video.

Why does it contain a real password of mine?

Because it came from a data breach at some service you signed up to. Those lists circulate and are traded. The scammer includes it for credibility, not because they got into your machine.

Should I pay?

No. There is nothing to publish. Paying only confirms your address is live and that you respond, which usually brings more attempts.

So what should I do?

Do not reply, do not pay, mark it as spam, and — this part matters — change that password everywhere you still use it and switch on two-step verification.

Keep reading