Home Articles Get your free assessmentComing soon

Tag: extortion

  • The Blackmail Email Every Pastor Eventually Gets

    The Blackmail Email Every Pastor Eventually Gets

    It arrives at 11:40 on a Tuesday night, which is not an accident.

    The subject line is your own old password. Not a password you use now — one you recognize, from years ago, from an account you’d half forgotten. Seeing it sitting there in a subject line does something physical.

    The message says the sender has had access to your devices for months. It says a program on your computer turned on your camera and recorded you. It says there is a list of your contacts — your congregation, your board, your family — and that everything will go to all of them unless a payment in cryptocurrency arrives within 48 hours.

    If you are a pastor, an executive director, or a board chair, there is a good chance you have already received one of these, or will. And there is a very good chance you told no one.

    This article exists mostly for that second part.

    What the message actually is

    These emails are sent by the million. They are not written for you. Nobody selected you, studied you, or sat outside your house. A list of email addresses was purchased, a template was filled in automatically, and the send button was pressed on all of it at once.

    A typical one reads something like this:

    I know [password] is your password. I placed malware on an adult site you visited and it recorded you through your camera. I also copied your contact list. You have 48 hours to send $1,900 in Bitcoin to the address below. If you pay, I delete everything. If you tell anyone, I send it immediately.

    The FBI has been warning about this family of scam since at least 2016, when it published an alert on extortion emails tied to high-profile data breaches. A later alert describes the same tactic directly — messages claiming “I have a recorded video of you,” made more convincing by including “the recipient’s user name or password” taken from a breach.

    The New York State Police, warning residents about the same automated campaigns, stated the bottom line without hedging: despite these claims, the scammer does not have access to the victim’s device or personal information.

    Where the password came from

    This is the detail that makes the email feel real, and it has a boring explanation.

    A data breach is what happens when a company that stored your information gets broken into and that information is taken. Not your computer — theirs. A retailer, a forum, a fitness app, a hotel chain, a professional association, a church management platform. If you made an account there years ago, your email address and password were sitting in their database, and when that database was stolen, yours went with it.

    Those stolen databases get combined, resold, and eventually circulated freely. Millions of email-and-password pairs, sitting in files anyone can obtain.

    So the scammer’s software takes a line from one of those files, drops the password into a template next to the matching email address, and sends. That’s it. The password in your subject line is evidence of one thing only: that a company you once did business with was breached, probably a long time ago, possibly before you were in your current role.

    It is not evidence of a camera, or malware, or anyone watching anything.

    Some versions include your home address instead, or as well. Same explanation — addresses are in those same breached records, and in a hundred commercial marketing databases besides.

    The version with a photo of your house

    A newer variant, which the New York State Police specifically flagged, includes a photo of the recipient’s home.

    It is startling by design. It is also nothing more than an address run through publicly available street-level map imagery — the same pictures anyone can pull up of any address in the country, automatically, at scale. The photo proves the sender has your address. Your address is in the breached data. The chain ends there.

    Knowing that in advance takes most of the force out of it. That is the entire reason this section exists.

    What to actually do, in order

    Do not reply. Not to argue, not to deny, not to ask what they have. Any response tells an automated system that a live human read the message, and moves your address onto a much more valuable list.

    Do not pay, and do not negotiate. The FBI’s guidance on these schemes is explicit: do not communicate with the perpetrators, and do not pay the ransom, because the funds go on to finance further criminal activity. Payment also marks you as someone who pays, which is followed by another demand.

    Check the password. Go to haveibeenpwned.com — a free, long-established service that lets you enter an email address and see which known breaches it has appeared in. It will usually name the company and the year, which turns an unnerving mystery into a mundane fact you can look at.

    Change that password anywhere it is still in use. This is the one genuine action item in the whole episode. If the password in that email is still protecting your church email, your bank, your donor database, or anything else, change it today. Different password for every account — which in practice means a password manager, because nobody can hold forty of them in their head.

    Turn on multi-factor authentication on your email and anything financial. That’s the extra code or phone tap after the password. Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. It means a stolen password on its own is no longer enough to get into anything, which is exactly the situation you want to be in the next time a database somewhere is breached — and there will be a next time.

    Report it. File at ic3.gov. The FBI asks that you include the email with its header information and the cryptocurrency address, and use the keyword “Extortion E-mail Scheme.” Your report takes five minutes and joins thousands of others that let investigators trace where the payments go.

    Then delete it and block the sender.

    The part that matters most: tell someone

    Here is the thing the scam is actually built on. Not malware. Not surveillance. The fear of being seen.

    The message is engineered around a specific instruction — don’t tell anyone — because isolation is the mechanism. A person who forwards the email to a colleague within ten minutes almost never pays. A person who sits with it alone at midnight sometimes does.

    For church and nonprofit leaders this pressure lands harder than it does on most people, and it’s worth saying why. Your role is bound up with your reputation in a way that an accountant’s isn’t. You have a congregation, a board, a family, and a sense that the position requires you to be beyond question. That’s precisely the leverage the sender is counting on — and they’re counting on it without knowing a single thing about you.

    So say it plainly, in a staff meeting or an elders’ meeting, before anyone receives one:

    If you get one of these, forward it to me or to [name] the same day. Nobody who receives one of these has done anything wrong. Everyone gets them.

    Say the last part out loud, because it is true and because the person who eventually needs it will not be in a state to work it out for themselves. Receiving a threatening email is not a moral event. It means an address of yours is on a list, along with tens of millions of others.

    If you lead an organization, receiving one yourself is a gift of a teaching moment. Mentioning it — briefly, matter-of-factly, without drama — at the next staff meeting does more to protect your people than any policy document. It tells them this happens to leaders too, and that the response here is a shrug and a report, not shame.

    If a threat is ever genuinely credible

    Almost all of these are bluffs. Not all threats are.

    If someone contacts you with something specific and real — an actual image, an actual private message, knowledge that could only come from an actual relationship — that is a different situation, and it is not one to handle alone or by paying.

    It is a matter for law enforcement, and for one trusted colleague or board member you tell immediately. Contact your local FBI field office or file at ic3.gov, and preserve everything: the messages, the account names, the timestamps. Do not delete, and do not pay. Paying an extortionist who genuinely holds something has never once ended the demands.

    And if the person being threatened is a minor, or if a minor is involved in any way, that goes to law enforcement immediately — not to an internal conversation first.

    The instinct in all of these cases is silence, and silence is the one thing that reliably makes it worse. Whatever the circumstances, a leader facing this should have at least one other person in the room.

    What to do this week

    Take the ten minutes: put your work email address into haveibeenpwned.com, see which breaches it turns up, and change any password from that list still in use. While you’re there, turn on multi-factor authentication for your email account if it isn’t already on.

    Then, at your next staff or board meeting, spend sixty seconds saying the sentence out loud — if you ever get a threatening email demanding payment, forward it to me the same day; everybody gets these and nobody is in trouble. That sentence is the whole defense, and it has to be said before it is needed.

    MissionDefend’s free assessment walks through the basics in plain English — how your organization handles email, donations, member data, and accounts — and hands back a baseline score with a ranked list of what to fix first. Password reuse and missing multi-factor authentication are usually near the top of that list, and they are usually the cheapest things on it to fix.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: FBI Internet Crime Complaint Center, Extortion E-mail Schemes Tied to Recent High-Profile Data Breaches; FBI Internet Crime Complaint Center, Online Extortion Scams Increasing During The Covid-19 Crisis; New York State Police, New York State Police warns of nationwide automated sextortion scams; Microsoft, mandatory multifactor authentication guidance.