About this tool
Why an email quoting your old password is almost always a mass-mailed bluff, and the steps that actually reduce your risk.
An email that opens with a password you recognise and demands cryptocurrency is a mass-mailed extortion attempt built on a leaked credential list, not on access to your device. This page lists the ten hallmarks of that automated version — an old password, no evidence attached, nothing personal beyond the password, a crypto address, a 48-hour clock, a forged From line showing your own address — and reports how many of them your message matches. It also separates the real risk, which is password reuse and credential stuffing, from the claimed one, and gives the reporting routes for the US, UK and India.
Open Sextortion Email Anatomy Explainer on AltFTool — it loads instantly in your browser.
Under "Check the message against the pattern", tick each hallmark your email shows — a password you stopped using years ago, no video or file included, a bitcoin demand, a 24 to 72 hour deadline, a From line showing your own address — and tick the separate red box only if genuine intimate images were actually shown.
Read the "Bluff hallmarks present" count out of 10 and the band beside it, from "Matches the mass-mailed bluff almost exactly" down to "Does not fit the bluff pattern", then fill "Accounts using that password" and "Of those, with two-factor authentication".
"Openable with the password alone" shows what the leak actually costs you, "Copy result" puts the score, band and "What not to do" list on the clipboard, and "Where to get help" gives ic3.gov, Action Fraud and cybercrime.gov.in.
The password is real and the surveillance is not — the tool makes that distinction explicit instead of leaving you to guess.
The output is a concrete clean-up: which accounts share the password, which have a second factor, and how long changing them takes.
If genuine intimate material was actually shown, the guidance switches to image-based abuse reporting rather than treating it as a bluff.
Almost certainly not. These campaigns take address-and-password pairs from old website breaches and send millions of identical messages; the password is the only genuine item in the email. If no video or screenshot was actually attached and the message contains nothing personal beyond that password, there is no evidence of any access to your devices.
No. The From header of an email is free text and can be forged by any sender, which is why domains publish SPF, DKIM and DMARC records to fight it. Check your Sent folder: the message will not be there. Changing your password and turning on two-factor authentication is still worth doing.
No. There is nothing to buy back — the recording does not exist — and paying identifies your address as one that responds, which usually brings more demands. Instead, change the quoted password everywhere it is still used, enable two-factor authentication, and report the message.
Change the leaked password on every account that still uses it and stop reusing it; turn on two-factor authentication on email and banking first; check a breach-notification service to see which site exposed the password; and report the message to your national cybercrime body — ic3.gov in the US, Action Fraud in the UK, or cybercrime.gov.in and the 1930 helpline in India. If someone has genuinely shared intimate images of you, that is a crime — contact the police, and use StopNCII.org, or NCMEC's Take It Down service if the person depicted is under 18.