We know a lot of information about us likely available on the Dark Web. If you’re online at all, it’s difficult to avoid. However, a growing email scam is making the rounds that tries to convince people their entire digital life has been compromised. The message often begins with a bold claim that the sender already has access to your passwords, photos, financial information, and files; essentially anything that is on your computer or smart device.
Keeping it real
To make it more realistic, the scammer may include an old password in the message to make the threat feel real. After all, many passwords are stolen all the time. They then demand quick payment, usually in cryptocurrency, to prevent your information from being posted online or sold on the dark web.
In reality, these scammers usually do not have full access to your device. They just want you to think they do. Instead, they rely on information gathered from older data breaches where passwords or email addresses were leaked years ago. By inserting one of those old passwords into the message, the criminal hopes you’ll believe they truly hacked your device and panic into paying.
Pressure to act fast
Like many scams, urgency is part of the trick. The email may claim you only have 24 or 48 hours before your data is exposed. Some messages even say the hacker recorded you through your webcam or installed spyware on your device. That really would be creepy, but it’s not likely to be true.
The goal is simple: To scare you into sending money before you have time to question the threat.
What you should do instead
If you receive one of these messages, experts say the safest response is not to engage at all.
Take these steps instead:
Do not reply or pay the ransom. Paying only encourages more of the same behaviors.
Delete the message and mark it as spam. If you have the option to block the sender, that’s not a bad idea.
Change any passwords mentioned in the email, especially if you still use them. If they have them, someone else may too, so just take the time to change them.
Use strong, unique passwords for every account.
Turn on two-factor authentication whenever possible.
Don’t let fear do the work for them. Extortion scams succeed because they play on fear and embarrassment. The message may sound convincing, but in most cases it’s simply a bluff designed to shake money loose. Taking a moment to pause, verify, and protect your accounts can keep scammers from turning an empty threat into a costly mistake.