PanicStation.org
us Technology & digital loss

What to do if…
you receive an extortion message claiming your files were copied and you are unsure if it is real

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Do not reply or pay. Save the message, then check your key accounts and device from a clean device before making any decisions.

Do not do these things

  • Do not pay, even if the message uses a countdown or threatens embarrassment.
  • Do not reply, argue, request proof, or try to negotiate.
  • Do not click links, open attachments, scan QR codes, or install tools mentioned in the message.
  • Do not change passwords on a device you think may be infected; use a clean device.
  • Do not immediately wipe, factory-reset, or throw away devices before saving basic evidence.
  • Do not trust anyone who contacts you offering guaranteed recovery, tracing, or deletion for a fee.

What to do now

  1. Create a safer pause. If you clicked a link, opened an attachment, installed anything, or typed a password after receiving the message, disconnect that device from the internet and stop using it for passwords or banking until it is checked.
  2. Save evidence without engaging. Screenshot the message, keep the original email or direct message if you can, and record the sender, date, time, crypto wallet, payment instructions, links, and any file names they mention.
  3. Check whether the threat has real proof. Do not ask the sender for proof. From your own records, look for whether they named real private files, showed a real sample, used a current password, or only used generic claims such as “I copied everything” or “I recorded you.”
  4. Check your email account first from a clean device. Review recent sign-ins, unfamiliar devices, recovery email or phone changes, filters, forwarding rules, and connected apps. Remove anything you do not recognise.
  5. Lock down the accounts that matter most. Change your email password first, turn on multi-factor authentication, sign out of other sessions where available, then change any other accounts where you reused that password.
  6. Check cloud storage and file-sharing accounts. Look for recent activity, new shared links, unknown collaborators, unexpected downloads, and connected third-party apps. Remove access you do not recognise.
  7. Check the affected device carefully. Use built-in security software or a trusted security tool you already know, update the operating system and browser, and avoid “recovery” tools advertised by search results or sent by the attacker.
  8. If this involves work, school, or a shared organisation device, report internally now. Contact the IT or security team using a normal trusted channel. Do not send the attacker’s links or files to personal accounts.
  9. Report it through USA channels. File an internet crime complaint with the FBI’s Internet Crime Complaint Center and report the scam to the FTC. If someone claiming to be IC3, the FBI, or a recovery service asks for crypto, gift cards, or a fee, treat that as another scam.
  10. If money or identity information is exposed, add one protective step. Check recent bank and card activity. If you shared a Social Security number, financial login, or identity document, use the official identity-theft recovery route and consider a fraud alert or credit freeze.

What can wait

  • You do not need to decide now whether to pursue the sender.
  • You do not need to publicly respond or warn everyone immediately.
  • You do not need to wipe devices before checking accounts and saving evidence.
  • You do not need to prove the message is fake before you take basic account-safety steps.

Important reassurance

Extortion messages are written to make you panic and act quickly. Many use old leaked passwords, generic threats, and copied wording sent to many people at once. Slowing down, saving evidence, and checking your accounts is a safer response than paying or replying.

Scope note

These are first steps only. If you confirm real access to files, accounts, workplace systems, school systems, or sensitive personal data, later decisions may need specialist cybersecurity, legal, or identity-theft help.

Important note

This guide is general information, not legal, financial, professional cybersecurity, therapeutic, or other professional advice. If you are in immediate danger or someone is threatening imminent physical harm, call 911.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us