
The “I’ve hacked your devices” email is a common sextortion scam that falsely claims a hacker infected your computer, recorded you through your webcam, or stole compromising information. The message is designed to create panic by mentioning passwords from old data breaches, claiming to have installed spyware such as Pegasus, or spoofing your own email address. In almost every case, the scammer has not hacked your devices or recorded you—they’re relying on fear to pressure you into paying cryptocurrency. The safest response is to ignore the email, never pay the ransom, change any exposed passwords, enable two-factor authentication, and scan your devices if you’re concerned.
It usually starts with a message in your inbox. Someone says they've hacked into your computer, stolen your passwords, and used your webcam to record private moments.
These emails are often full of threats, tech-sounding language, and specific details to make them seem real. Then comes the demand: send money or they'll expose everything.
These kinds of emails are scary. But in most cases, they're fake. Here's what you need to know about this type of scam, what to do if you get one, and how to protect yourself going forward.
Related: 41 Million Suspicious Emails Reported in the UK. How Can You Stop the Phish in 2025?
This is part of a common scam known as sextortion phishing—emails designed to shame, shock, and scare you into paying.
Scammers send out thousands of emails like this, hoping that fear and embarrassment will make someone pay up. They often use strong, threatening language and pretend to have hacked your webcam, microphone, and online accounts.
In reality, they usually haven't hacked anything. They're bluffing.
Sometimes, to make the scam more convincing, they'll include a password you've used in the past. They get these from old data breaches and try to scare you into thinking they've gained access to your devices.
These emails work because they create instant fear. Even if you've done nothing wrong, it's hard not to panic when someone claims to have private access to your life.
Some people freeze. Others pay, just to make it go away. But sadly, paying doesn't guarantee anything. In fact, it may encourage scammers to target you again.
Related: Fake Antivirus Pop-Ups vs. Real Security Alerts: How to Tell the Difference
The language is usually threatening and dramatic, trying to scare you into acting quickly. They'll say things like "I've been watching you for months" or "With one click, I'll send this to your contacts."
Here are some signs it's fake:
Related: Scam Trends of The Week: 7 Real Scam Emails You Need to Avoid
First of all—don't reply and don't send money. That only confirms you read the message and might make you a bigger target later.
Instead, take a moment to breathe and make sure your accounts are safe. Run a full security check on your devices. If the email listed an old password you still use, change it right away—especially on important accounts like email or banking.
Even if the message was fake, it's a good chance to make your online life more secure. Turn on two-factor authentication where possible. Avoid using the same password across multiple sites. And keep your software updated.
Related: 'Your Account Has Been Hacked': Crypto and Bank Phishing Scams Surge Across Australia
Sometimes, it's hard to know if a message is a scam—especially when it sounds urgent or threatening. That's why you can use dedicated tools to check if it's real or not before you act.
Scams like this feed on fear and confusion. But with the right tools—and a clear head—you stay in control.
In most cases, yes. Emails claiming “I’ve hacked your devices” or “I recorded you through your webcam” are common sextortion scams designed to scare you into sending cryptocurrency. Scammers often include an old password leaked in a previous data breach or spoof your email address to make the threat seem real. If the email doesn’t provide genuine evidence that your device was compromised, don’t reply or pay the ransom. Instead, change any reused passwords, enable two-factor authentication, and scan your device if you’re concerned.
Yes. You should not reply, negotiate, or send money. Paying does not prove the scammer will delete any supposed files or stop contacting you—in fact, it may encourage further extortion attempts. Delete the email, report it as spam or phishing, update any exposed passwords, and enable two-factor authentication on your important accounts. If the email includes one of your old passwords, treat it as a sign that your credentials may have been exposed in a previous data breach rather than proof your device was hacked.
Apple does not send random emails, text messages, or pop-ups claiming your iPhone has been hacked or infected with malware. If Apple identifies a serious security threat, such as a mercenary spyware attack, it notifies affected users through their Apple ID account, by email, and by iMessage. Unexpected pop-ups, browser alerts, or emails claiming your iPhone has been hacked are much more likely to be scams than legitimate Apple notifications.
You probably received it because scammers send millions of fake hacking alerts hoping a small percentage of people will panic and pay. These messages often claim your phone is infected, your camera was activated, or your personal data has been stolen to pressure you into acting without thinking. In some cases, the scammer may know your email address or an old leaked password, but that doesn’t mean they have access to your phone. If you’re unsure whether a message is legitimate, don’t click any links and use Bitdefender Scamio to check it before responding.
tags
Cristina Popov is a Denmark-based content creator and small business owner who has been writing for Bitdefender since 2017, making cybersecurity feel more human and less overwhelming.
View all posts