An Email Says They Have My Password and a Video

An Email Says They Have My Password and a Video
There is no video, and there never was one. The password, though, is probably genuine, and that single detail is doing all of the work.
These messages arrive by the million and they follow a set pattern. The sender claims to have installed something on your computer, watched you through the webcam, recorded something compromising, and copied your contacts. Payment in cryptocurrency within a short deadline, or it goes to everybody you know. And there, usually in the first line, sits a password you recognise.
That password is the reason intelligent, careful people sit at their desk feeling cold, reading it a second time.
The short answer
The password is real, the video is not, and the only thing worth doing is changing that password wherever it still lives.
Where the password actually came from
It did not come from your computer. It came from a website you signed up to, possibly a decade ago, which was breached at some point afterwards.
When a company is breached, the usernames and passwords in its database circulate freely. Those lists are traded in bulk, and they contain email addresses paired with passwords. Somebody takes a list, writes one message, and sends it to every address on it, inserting each recipient's own breached password automatically.
Nobody read anything about you, and nobody chose you specifically. A script matched your address to the password sitting next to it, in a file with several million other people in it, and pressed send.
Which is why the password is so often an old one. People notice that and assume the sender has outdated information. In fact it is the strongest clue about what actually happened: the password is old because the breach was old, and that breach is the entire extent of what anybody has. (referenced in the supplementary exposure benchmarking report).
Why the rest of it is a bluff
Look at what the claim actually requires somebody to have done. Software installed on your particular machine and never detected, access to your webcam at a moment when something worth recording happened to be happening, and your contact list copied off. All of that done to millions of people simultaneously, at no cost, by somebody who then asks for a few hundred pounds.
The economics simply do not work, and they were never meant to. Sending the message to a million addresses costs essentially nothing, so if a few hundred people pay then writing it was worthwhile. Nobody needed to compromise a single machine anywhere.
Honestly, there are tells everywhere once you know to look for them. The message never names anything specific: not a site, not a date, not what you were supposedly doing. It cannot, because whoever sent it has no idea. Genuine blackmail is specific, because specificity is the proof. A message that keeps everything vague is telling you it has nothing.
The deadline is doing a job as well. Forty-eight hours, no time to think it over, and above all do not tell anybody. That is not how somebody holding real evidence behaves, because real evidence does not expire on Thursday. It is how somebody behaves when they need a decision out of you before you have spoken to a single other person about it.
That instruction not to tell anyone is the most revealing line in the whole message. Every version of this fraud contains it, in some form, because the moment you describe the email out loud to somebody else, they will say what you already half suspect.
The one that appears to come from your own address
A common variation makes the message look as though it was sent from your own email account, which is presented as proof of access.
That is not proof of anything at all. The sender line on an email can be written by whoever sends it, much as you can write any return address you like on the back of an envelope. The Royal Mail does not check it and neither, by default, does email. Seeing your own address there means somebody typed it, not that they were ever inside your mailbox.
If you want to be certain your account is genuinely fine, our guide on checking a mailbox for signs of compromise walks through the three things actually worth looking at, particularly mail rules and forwarding.
Ask yourself what they have not said
Read the message again, if you still have it, and notice what is missing.
It never names the website, and it never says when any of this supposedly happened. It never describes what you were meant to have been doing, or which device, or how long the recording runs to. Would somebody holding genuine evidence really leave all of that out?
Real blackmail is specific, because the specificity is the proof. This is vague in every particular, and the vagueness is not carelessness. It is the only way one message can be sent to a million different people.
What to do
Delete the message and get on with your day. Do not reply, do not pay, and do not spend the evening working out whether you have anything to worry about, because you do not.
Then take the one genuinely useful thing out of it. A password of yours is circulating in a breach. That is worth acting on, and it is the only real information the email contains.
Change that password anywhere you still use it, and be honest with yourself about where that is. If it was a variation you have carried across several accounts over the years, change all of them. Turn on a second sign-in step wherever it is offered, which makes a stolen password insufficient on its own, and our guide on why that step is worth the hassle covers what to switch on first.
Our breach checker will tell you which breaches your address appears in, which is usually a longer list than people expect and is worth seeing once.
Do not be alarmed by the length of that list either. Appearing in a breach of a forum or a retailer from years ago is extremely common and says nothing about your own carelessness. What matters is only whether any password from those breaches is still in use anywhere today.
If somebody you employ receives one
They will be embarrassed, and that embarrassment is the actual risk here rather than anything technical.
Somebody who receives one of these at work may well say nothing, because the claim is humiliating and they are not sure whether it is true. Meanwhile the useful fact, that a company password may be circulating in a breach, goes unreported.
So say it in advance, before anybody receives one. These emails circulate constantly, they are a bluff, and nobody will be in trouble for mentioning it. The National Cyber Security Centre (NCSC) makes the same point about incident reporting generally: people tell you early when telling you is safe, and they say nothing at all when it is not. That single sentence, said once in a team meeting, is what converts an unpleasant private evening into a two-minute password change.
The version aimed at businesses
There is a variant that skips the personal humiliation and goes straight for the money, and it is worth recognising because it looks more credible.
Instead of a video it claims to hold company data: customer records, contracts, payroll. Sometimes it names your business, which is easy enough to do from your own website. Occasionally it references a real breach that genuinely happened somewhere in your supply chain, which makes it land harder.
The test for it is exactly the same. Does the message contain a single specific thing that could only be known by somebody who actually had the data? A file name, a customer name, a figure, a sample. Anybody genuinely holding data will show you a piece of it, because that is the entire basis of the threat. A message that describes what it has in general terms has nothing.
If it does contain something real, that changes matters completely, and it stops being an email to delete. Treat it as an incident: preserve the message, do not reply, and work through our guide on when you have to tell people, because a genuine data theft carries reporting duties on a 72 hour clock.
Worth passing on
This is one to tell people about before it lands rather than afterwards, and particularly anybody who would find the accusation itself distressing.
Older relatives are worth a specific mention. The message is written to be humiliating, it arrives without warning, and somebody who is not confident about what a webcam can and cannot do has no way to assess it. Telling them in advance that these go around constantly, that the password comes from an old website leak, and that nobody has any recording, removes most of the fear before it ever arrives.
The whole thing collapses into a single sentence worth remembering: the password is real and came from an old breach, and every other word in the message was written for a million people at once.
Nobody watched you through anything, and nobody chose you out of a crowd. A file containing your email address was sold on to somebody who owns a mailing script, and that really is the entire story.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Doesn't the Firewall Block All This?
A firewall controls which doors are open. Almost every modern attack arrives through a door you deliberately left open, which is why it passes straight through.
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
Does Incognito Mode Make Me Anonymous?
It hides your history from the next person using the device. Your employer, your provider and the sites themselves see exactly as much as before.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is It Safe to Plug In a USB Stick?
A drive you did not buy is a device somebody else configured. Here is what can actually go wrong, and what to do with one you have found.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
We've Got Nothing Worth Stealing
They are not after your trade secrets. They are after your payroll run, your mailbox and the machines themselves, which every business has.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.