Personal Reputation

Got a “You’ve Been Hacked” Email? How to Tell It’s a Scam

That email saying a hacker recorded you and wants Bitcoin is almost always a scam. Here's how to recognize it, what to do about the real password it quotes, and when to actually worry.

By Editorial Team 7 min read
A laptop on a dark desk showing an email inbox on the screen

A “you’ve been hacked” email that claims someone installed malware, recorded you through your webcam and will send the video to your contacts unless you pay in Bitcoin is almost always a scam. The sender usually has no video and no access to your device. Don’t pay and don’t reply. If the email quotes a real password, change that password everywhere you’ve used it and turn on two-factor authentication, because it most likely came from an old data breach.

These emails are designed to cause panic, and they work because they sometimes include a detail that feels impossible to know. Below is how the scam works, how to check whether anything was actually compromised, and what to do next.

What the email usually says

The wording varies, but most versions follow a script. The email saying you’ve been hacked typically claims that:

  • The sender hacked your device or email account months ago and has been watching you.
  • They installed malware or a “trojan” through a website you visited, often an adult site.
  • They recorded you through your webcam, alongside your screen.
  • They have your contact list and will send the video to friends, family and colleagues.
  • You have 24 or 48 hours to pay a set amount in Bitcoin or another cryptocurrency to a wallet address.
  • The email has a tracking pixel, so they’ll know when you open it, and contacting police will trigger the release.

Some versions include your password, your phone number, your home address, or even a photo of your street taken from online maps. Others appear to be sent from your own email address.

How to tell it’s a scam

Several signs give it away, and most of these emails show several of them at once.

What they claim What’s usually going on
They know your password The password came from an old data breach at another website, published or sold online. It’s often one you stopped using years ago.
The email was sent from your own address The sender address was spoofed. Faking the “from” line of an email is easy and doesn’t require access to your account.
They recorded you on your webcam No proof is included. If they had a video, a clip or still would be the obvious thing to send.
They know your address or phone number That information is often listed on people-search sites or exposed in breaches.
They’ll release it if you contact anyone This is to stop you asking for advice, because anyone you ask would tell you it’s a scam.
A tight deadline Panic makes people pay before thinking. Real attackers rarely announce themselves this way.

The same message, word for word, is often sent to huge numbers of people at once. Searching online for a distinctive sentence from the email frequently turns up many others who received it.

I’ve been hacked, what do I do? The steps to take now

If you’ve read one of these emails and your first thought was “I’ve been hacked,” take a breath. Here’s what to do.

  1. Don’t pay. Paying doesn’t make anything go away and marks you as someone who pays. Cryptocurrency payments are very hard to reverse.
  2. Don’t reply or click anything. Replying confirms your address is active. Links or attachments could be phishing or malware.
  3. Change the password they quoted. If it’s a password you still use anywhere, change it on every account where you used it. Use a unique password for each account from now on, ideally in a password manager.
  4. Turn on two-factor authentication, starting with your email, banking and social media accounts.
  5. Check whether your email appears in known breaches. Free breach-checking services such as Have I Been Pwned let you see which breaches your email address appeared in, which usually explains where the password came from. Many password managers also flag breached passwords.
  6. Mark the email as spam or phishing in your email provider, then delete it. You can report it to the FBI’s Internet Crime Complaint Center at ic3.gov, especially if you’ve paid.
  7. Cover your webcam if it gives you peace of mind. It’s a sensible habit anyway, and it costs nothing.

When a “you’ve been hacked” message might be real

The mass email is almost always a bluff, but actual account compromise does happen. Worry more, and act quickly, if you see any of these:

  • You can’t log in to an account, or your password or recovery details changed without you.
  • You get security alerts from your email provider or a platform about logins you didn’t make.
  • Friends receive messages from your account that you didn’t send.
  • Your sent folder contains emails you didn’t write, or there are forwarding rules you didn’t create.
  • The person has sent a genuine private image or video and is threatening to share it.

If an account has been taken over, follow the provider’s official recovery steps. Our guides on a hacked Gmail account and a hacked Facebook account cover the main ones. If someone actually has intimate images of you and is threatening you, that’s a different situation: see our guide to sextortion help for how to report it and stop images spreading.

Not sure where to start?

Get a free audit of your search results and review profiles, with a prioritized fix list.

Get a free audit

Worked example: the email with a real password

This is an illustrative scenario, not a real case.

A marketing manager opens an email with the subject line showing a password she recognizes. The message says a hacker has been watching her through her laptop camera and wants a cryptocurrency payment within 48 hours, or a video goes to everyone in her contacts.

Her stomach drops, but she notices a few things. There’s no video or screenshot attached. The email appears to come from her own address, but her sent folder doesn’t show it. The password is one she used on a shopping site years ago. She checks a breach-notification service and finds her email in a breach from that site.

She doesn’t reply. She changes that old password on the two accounts where she’d reused it, turns on two-factor authentication for her email and bank, and marks the message as phishing. She receives two more similar emails over the next month, with different wallet addresses and the same wording, and deletes them. Nothing is ever released, because there was never anything to release.

Common mistakes to avoid

  • Paying “just in case.” It doesn’t buy safety and may lead to more demands, sometimes from the same group under a different name.
  • Replying to argue or ask for proof. It confirms your address and invites more messages.
  • Ignoring the password entirely. The threat is fake, but a real, reused password is a genuine risk to your other accounts.
  • Clicking links in follow-up “security” emails. Scammers sometimes send fake account warnings afterward.
  • Paying someone who offers to “trace” the hacker. Recovery and tracing offers are a common follow-up scam.

Reducing how much scammers can find about you

The versions that include your address, phone number or a photo of your house feel the most frightening. That information usually comes from breached data and public people-search listings, not from your device. Opting out of the main people-search sites reduces what’s easy to find. Our guide to removing yourself from people-search sites explains how, and our list of ways to prevent identity theft covers the wider protections worth having if your details are circulating.

If personal details are showing up in Google results for your name, our personal reputation management service can help identify what qualifies for removal and what can be pushed down.

Frequently asked questions

Is the Bitcoin email saying I was hacked real?

In almost all cases, no. It’s a mass scam sent to many people at once. The sender usually has no video and no access to your device. Any password it includes most likely came from an old data breach at another website.

How did the scammer get my password?

Usually from a data breach at a website where you used that password. Breached email and password lists circulate online. Change that password anywhere you still use it and switch to unique passwords for every account.

Why does the email look like it came from my own address?

The sender spoofed the “from” field, which is easy to fake. It doesn’t mean they have access to your account. Check your sent folder: if the message isn’t there, you didn’t send it.

Should I report the email?

Mark it as spam or phishing in your email provider, which helps filter future messages. You can also report it to the FBI’s Internet Crime Complaint Center at ic3.gov, and you should if you’ve paid anything.

What if I already paid?

Report it to ic3.gov with the wallet address and transaction details, and contact the exchange or payment service you used. Recovery is difficult, so be wary of anyone who contacts you offering to get your money back for a fee.

Editorial Team

The 123 Reputation Management editorial team writes practical guides on reviews, search results and online reputation.

Start with step 1

See what people see when they search for you.

Get a free, no-obligation reputation audit covering search results, review profiles and social mentions, with clear next steps.