Key takeaways

  • These "I know your password" sextortion emails are a mass-mailed bluff. There is almost never any malware on your computer and no webcam footage.
  • The password they show is real but old, taken from a data breach of some website you once used, not proof your computer was hacked.
  • Never pay and never reply. Forward the email to report@phishing.gov.uk, then delete it.
  • Report fraud in the UK at Report Fraud (reportfraud.police.uk, 0300 123 2040), which replaced Action Fraud in December 2025. In Scotland, call Police Scotland on 101.
  • If your account genuinely has been hacked, the real warning signs are sign-ins you do not recognise, password reset emails you did not request, and forwarding rules you did not set up.
  • Protect yourself: turn on 2-step verification, use a unique password or a password manager, and check haveibeenpwned.com to see what has leaked.

If an email has just landed in your inbox showing one of your real passwords and threatening to send embarrassing webcam footage to your friends and family unless you pay in Bitcoin, take a breath. It is frightening by design, but it is almost certainly a bluff. These messages are sent out by the million in the hope that a tiny fraction of people will panic and pay.

This guide explains, in plain English, what these scams actually are, why seeing your own password does not mean you have been hacked, exactly what to do next, and how to report it properly in the UK in 2026. We will also cover the wider world of phishing, the genuine signs that an email account really has been broken into, what to do if that happens to you, and the few simple steps that make you a much harder target in future.

The short answer

You have not been filmed, your computer almost certainly has not been hacked, and you should not pay a penny. The criminals are guessing. As the UK's National Cyber Security Centre puts it in its own sextortion guidance, the people behind these emails "do not know if you have a webcam, or know if you've visited adult websites," and the password "in all likelihood has been obtained from historic breaches of personal data."

So the plan is simple: do not pay, do not reply, forward the email to report@phishing.gov.uk, then delete it. If the password shown is one you still use anywhere, change it and turn on 2-step verification. That is the whole response, and the rest of this guide explains why, then goes further into staying safe from the wider family of email scams.

What an "I know your password" email actually is

This type of scam is known as sextortion. The criminal sends a threatening email claiming they have planted malware on your device, watched you through your webcam while you visited an adult website, and recorded everything. To "prove" it, they include a password you recognise. They then demand payment, usually in cryptocurrency, within a short deadline, and threaten to send the footage to your contacts if you do not pay.

It is convincing for one reason only: the password is genuine. That single detail makes the rest of the threat feel real. But it is a trick of presentation. The email is one of millions sent automatically, with your address and old password slotted in from a list. The National Crime Agency and police treat these as financially motivated extortion, and the overwhelming majority are empty threats with no footage and no malware behind them. The NCA notes that organised criminal groups, often based overseas, run these campaigns at scale, which is exactly why the wording so rarely contains anything personal about you beyond that one recycled password.

Why showing your password does not mean you were hacked

When a website you once signed up to suffers a data breach, the email addresses and passwords from that site can end up traded or dumped online. Criminals buy these old lists and use them to make sextortion emails look legitimate. So the password is real, but it came from a third-party breach, not from your computer or your webcam.

To give a sense of scale, Have I Been Pwned, a free and well-respected breach-checking service, has indexed more than 17 billion compromised accounts drawn from over a thousand known website breaches. Your old password turning up on one of those lists is unremarkable, and it is not a sign that anyone has touched your own devices. That is the key thing to understand, and it is why the threat falls apart once you know how it works:

What the email claimsThe reality
"We hacked your computer and webcam"They have not. It is a mass-mailed bluff sent to millions of addresses.
"We filmed you through your camera"There is no footage. They are guessing you might have a webcam.
"Your password proves we were inside"The password came from an old breach of a website, not your PC.
"Pay in Bitcoin within 48 hours"Paying marks you as a real target and funds the criminals. Never pay.
"We will email all your contacts"An empty threat designed to panic you into paying quickly.

If the password they quote is old, or one you have already changed, it is harmless. If it is one you still use, that is the only real risk here, and it is easily fixed by changing it, which we cover below.

What to do if you receive one

Work through these steps and you have dealt with it properly:

A person reporting and deleting a scam email on a laptop
Once you have reported it to report@phishing.gov.uk, simply delete the email. There is no need to engage with it any further.
  1. Do not panic and do not pay. The threat is almost certainly empty.
  2. Do not reply, and do not click any links or open any attachments in the email.
  3. If the password shown is one you still use anywhere, change it straight away and make the new one unique to that account.
  4. Turn on 2-step verification on your email and other important accounts, so a stolen password alone is not enough to get in.
  5. Forward the email to report@phishing.gov.uk, the NCSC Suspicious Email Reporting Service, then delete it.
  6. Check haveibeenpwned.com to see which breach exposed your details, and update any other accounts that share that password.
  7. If you have already paid, report it (see below), tell your bank, and know that free emotional support is available from Victim Support on 0808 168 9111.

How to spot a phishing or fake email

Sextortion is just one flavour of phishing, the catch-all term for emails and texts that try to trick you into handing over money, passwords or personal details. Most are far less dramatic than a blackmail threat. They pose as your bank, a delivery company, HMRC, Netflix, Microsoft or Royal Mail, and they rely on you acting before you think. Once you know the tells, they become much easier to spot.

No single sign proves an email is fake, but the more of these you notice, the more suspicious you should be:

  • Urgency and threats. Real organisations rarely demand that you act within hours or lose access. Pressure is the scammer's favourite tool because it stops you checking.
  • It asks you to log in or "confirm" details. Your bank and HMRC will never email or text you a link to log in or verify your details. If in doubt, go to the website yourself by typing the address, rather than tapping the link.
  • The sender address does not match. The display name might say "PayPal", but the actual address is a jumble of letters at a domain that has nothing to do with the company. On a phone, tap the sender name to reveal the full address.
  • Links that go somewhere else. On a computer, hover over a link (or press and hold on a phone) to preview where it really points before you tap it.
  • Generic greetings. "Dear customer" or "Dear user" instead of your name is a common sign of a mass-mailed scam.
  • Spelling, grammar and odd formatting. Many scams still contain mistakes, although AI-written phishing is getting harder to fault on language alone, so do not rely on this one by itself.
  • Unexpected attachments. Invoices, "voicemails" or "delivery notes" you were not expecting can carry malware. Do not open them.

Here is a quick side-by-side to keep in mind:

A genuine email tends toA phishing email tends to
Address you by your nameUse "Dear customer" or no name at all
Come from the company's real domainCome from a lookalike or random address
Give you time and use a calm toneDemand urgent action or threaten consequences
Send you to a site you already knowPush you to click a link or open an attachment
Never ask for your password or full card detailsAsk you to "confirm", "verify" or "re-enter" them

The same instincts apply across the board. Our guide to fake online stores and how to spot them covers these warning signs in a shopping context, and if you work from home it is worth reading our tips on working more securely from your home office.

When scams get personal: spear-phishing and business email compromise

The sextortion email at the top of this guide is a blunt instrument, fired at millions of inboxes at once. Some scams are far more targeted, and those are the ones to watch for if you run a business or handle money at work.

Spear-phishing is phishing aimed at a specific person. Instead of a generic message, the criminal does their homework first, using what the NCSC calls your digital footprint, the information about you and your company that is freely available on your website, LinkedIn and social media. They might mention a real colleague, a recent project or a supplier you actually use, which makes the message far more convincing. When the target is a senior figure such as a director or finance lead, it is sometimes called whaling.

Business email compromise (BEC) takes this a step further. A criminal either spoofs or breaks into a genuine business email account, then sends a believable request to pay an invoice, change bank details or transfer funds urgently. Because the email comes from a real, trusted address (often the boss or a known supplier), staff act on it. The NCSC's cyber security guidance for small businesses makes the key point clearly: verify any request to move money or change payment details using contact details you have found yourself, never the ones in the email, which may be false.

If you look after computers for a Manchester firm, this is exactly the sort of thing worth getting ahead of. We help local businesses with business computer support and can help you set up 2-step verification, sensible email rules and safe payment checks before anything goes wrong.

Signs your email account really has been hacked

A sextortion email is almost always a bluff, but email accounts do genuinely get compromised, usually through a reused password or a phishing link rather than anything dramatic. Your email is the master key to your digital life, because most other accounts can be reset from it, so it is worth knowing the real warning signs:

  • Sign-ins or devices you do not recognise in your account's recent activity, especially from places you have never been.
  • Password reset emails for accounts you did not try to reset, which can mean someone is using your email to break into your other accounts.
  • Emails in your Sent folder that you never wrote, or messages missing from your inbox.
  • Friends or colleagues telling you they have had odd messages from you.
  • Email forwarding rules or filters you did not create, quietly copying your mail to an outside address.
  • Being suddenly logged out, or finding that your password no longer works.
  • Two-step verification prompts arriving when you are not trying to log in.

Any one of these on its own might be innocent. Several together mean you should act quickly, and the next section walks you through exactly how.

What to do if your email account has actually been hacked

If you think a criminal really is in your account, rather than just bluffing in a sextortion email, work calmly through these steps in order. Start with your email, because it controls everything else.

  • Regain access first. If you can still log in, change your password immediately. If you are locked out, use your provider's account recovery process to get back in before doing anything else.
  • Set a strong, unique password. Make it different from every other account. Three random words is a good, memorable approach, and a password manager makes it effortless.
  • Turn on 2-step verification. This stops the attacker getting back in even if they still know a password.
  • Sign out everywhere. Most email services have a "sign out of all sessions" or "sign out everywhere" option that kicks out any device the attacker is using. On some services this can take up to 24 hours to take full effect.
  • Check for sneaky forwarding rules and filters. This is the step people miss. Attackers often set up a hidden rule that quietly forwards a copy of your incoming mail to themselves, so they keep reading your email even after you change the password. Delete any rule, filter or forwarding address you did not create.
  • Review your Sent and Deleted folders. See what was sent in your name and whether anything was read and deleted, so you know what the attacker may have seen.
  • Check your recovery details. Make sure the recovery email address and phone number on the account are still yours, and remove anything you do not recognise.
  • Revoke access for apps you do not recognise. Remove any connected apps or devices you did not authorise.
  • Change passwords on linked accounts. Anything that shares the old password, or that can be reset from this email (banking, shopping, social media), should be updated, starting with the most important.
  • Warn your contacts. Let people know your account was compromised so they ignore any dodgy messages sent in your name.

If any of that feels daunting, or you are not certain the attacker is really gone, that is exactly the kind of job we can take off your hands, and there is more on that at the end of this guide.

How to report it in the UK (2026)

There is one important change to be aware of. Action Fraud no longer exists. On 4 December 2025 it was replaced by Report Fraud, run by the City of London Police, as the UK's national fraud and cybercrime reporting service for England, Wales and Northern Ireland. The phone number is unchanged.

  • Report online: reportfraud.police.uk
  • By phone: 0300 123 2040
  • In Scotland: Report Fraud does not cover Scotland. Report to Police Scotland directly on 101.
  • Suspicious emails: forward them to report@phishing.gov.uk. By May 2026 this NCSC service had removed around 443,000 scam web addresses, all flagged by reports from ordinary people.
  • Scam texts: forward them to 7726 (free, and it spells "SPAM" on a keypad).

Reporting takes a couple of minutes and genuinely helps. Every report feeds the national picture that gets scam websites taken offline, which protects the next person who would have received the same message.

How to protect your accounts

A sextortion email is really just a reminder that one of your old passwords is floating around. A few simple habits make you a much harder target and neutralise these threats almost entirely.

Setting up two-step verification on a smartphone next to a laptop
Two-step verification is the single most effective step. Even if a criminal has your password, they still cannot get into your account.
  • Turn on 2-step verification (2SV). The NCSC calls this one of the most effective ways to protect your accounts. Even if someone has your password, they cannot get in without the second step. Do it on your email first, since that is the account that can reset all the others.
  • Use a strong, unique password for your email. The NCSC recommends combining three random words to make a password that is long and memorable but hard to crack, rather than fiddly character swaps like changing "o" to "0". Length matters more than a clutter of symbols.
  • Let a password manager do the work. A password manager creates and remembers a unique password for every account so you do not have to. It will also warn you if a saved password turns up in a breach, and will only fill in passwords on the genuine website, which quietly protects you from phishing pages. Passkeys, where offered, are an even simpler and more secure way to sign in.
  • Keep antivirus simple. For most home users, Microsoft Defender, which is built into Windows, free and on by default, is enough. It scores top marks in independent AV-TEST results. Just keep it switched on and do not run two antivirus products at once.
  • Install Windows updates promptly. Security updates close the holes criminals rely on, so turn on automatic updates.

Microsoft Defender: independent AV-TEST score

Built into Windows, free and on by default. Top marks across the board in AV-TEST's 2026 home-user testing (out of 6).

Protection
6 / 6
Performance
6 / 6
Usability
6 / 6

Source: AV-TEST home-user evaluations, 2026. Scores are point-in-time, so check AV-TEST for the latest.

One more thing worth flagging: free support for Windows 10 ended on 14 October 2025. If you are still on Windows 10, you are no longer getting regular free security updates, which matters a great deal for staying safe online. It is worth seeing whether your PC can move to Windows 11, or looking at Microsoft's paid Extended Security Updates as a stopgap.

Passwords, passkeys and the future of logging in

Every scam in this guide ultimately depends on one weak link: passwords. They get reused, leaked in breaches and typed into fake login pages. The good news is that the way we sign in is changing, and the changes work in your favour.

The NCSC now recommends passkeys over passwords wherever they are offered. A passkey replaces your password with a secure key stored on your phone, tablet or computer, unlocked with your fingerprint, face or device PIN. The clever part is that it is tied to the genuine website, so it cannot be phished. Even if you are tricked into visiting a convincing fake login page, the passkey simply will not work there, because the cryptographic match fails. Google, eBay, PayPal, Microsoft and many others already support them, and you will increasingly see "set up a passkey" offered when you sign in.

Until passkeys are everywhere, the same three habits do most of the heavy lifting:

  • A unique password for every account, so one breach cannot unlock the rest.
  • A password manager to create and remember them all for you.
  • 2-step verification on anything important, email above all.

Get those three in place and a leaked password from some forgotten website becomes a shrug, not a crisis. It is also worth keeping a recent backup of anything you would hate to lose, because good security and good backups go hand in hand. See why backing up your data is critical if you have been meaning to sort that out.

Common mistakes that make a scam worse

Most of the harm from these emails comes not from the threat itself but from how people react. Here are the slip-ups we see most often, and what to do instead:

  • Replying to "see if it is real". Any reply, even an angry one, confirms your address is live and active, which marks you as worth targeting again. Do not engage.
  • Paying "just to be safe". Paying does not make the threat go away. It signals that you will pay, and the demands usually continue. There is almost never any footage to release.
  • Clicking the link to "unsubscribe" or "see what they have". Links and attachments in scam emails can lead to real malware or credential-harvesting pages. Never click them.
  • Assuming the worst about your computer. Seeing your own password is alarming, but it points to an old website breach, not a hacked PC. Check haveibeenpwned.com rather than panicking.
  • Doing nothing at all. The opposite mistake. If that password is still in use somewhere, change it and turn on 2-step verification today.
  • Ignoring the report step. Forwarding to report@phishing.gov.uk takes a minute and genuinely helps shut these operations down.

Worried your account really has been hacked?

Most of the time, a sextortion email is all bluff and the steps above are all you need. But if you are genuinely worried, if a password you still use has leaked, if you have spotted logins you do not recognise, or if you simply want peace of mind, it is worth having things checked over properly.

We help people across Manchester with exactly this. Whether it is a full virus and malware check, securing a compromised email account, a wider computer security health check, or moving you safely onto Windows 11, we will give you honest advice with no scare tactics. We offer free local collection and return right across Manchester, so you do not even need to leave the house. If you have had one of these emails and it has unsettled you, get a free, no-obligation quote or call us on 0161 820 1992 and we will put your mind at rest.