What to do if…
you receive an extortion message claiming your files were copied and you are unsure if it is real
Short answer
Do not reply or pay. Preserve the message, then check your key accounts from a clean device and use the UK reporting routes.
Do not do these things
- Do not pay, even to make it stop; payment can invite more demands.
- Do not reply, negotiate, click links, open attachments, scan QR codes, or call numbers in the message.
- Do not forward the message to friends or colleagues to ask if it is real.
- Do not change passwords on a device you think may be infected; use another trusted device.
- Do not delete the original message until you have saved evidence and reported it.
What to do now
- Pause the contact. Do not answer the sender. If you opened an attachment, clicked a link, scanned a QR code, or typed in a password, disconnect that device from Wi-Fi and mobile data and stop using it for account changes.
- Save the evidence. Take screenshots of the message, the sender address or handle, payment details, dates and times. Keep the original email or message for now.
- Report the message safely.
- For a suspicious email, forward it to [email protected].
- For a suspicious text, forward it to 7726.
- For an in-app message or direct message, use the platform’s report function and block the sender.
- Look for signs it may be a bulk scam. If the message gives no real filenames, no unique screenshot of your files, and no accurate private details, treat it as likely scam while you check. If it includes an old password, that is often from a past data breach and is not proof they are inside your device now.
- Check your email account first, from a clean device. Look for unfamiliar sign-ins, unfamiliar devices, new recovery details, and forwarding rules or filters you did not create.
- Check cloud storage and file accounts. Review recent activity, shared links, connected apps, and devices signed in to services such as iCloud, Google, Microsoft, Dropbox, or any work file system you use.
- Lock down important accounts. Change your email password first. Then change any reused passwords, turn on two-step verification where available, and sign out of other sessions where the service offers that option.
- Check the device only after accounts are safer. Run updates and a reputable security scan. If you see unknown administrator accounts, disabled security tools, repeated sign-ins you do not recognise, or files changing without you, stop troubleshooting and get help from a trusted repair professional or cyber incident responder.
- If this involves work or school systems, report it internally now. Use your organisation’s IT, security, or safeguarding route. Do not try to handle a possible organisational breach privately.
- If money, identity, or accounts are at risk, report it as cybercrime or fraud. In England, Wales, or Northern Ireland, use Report Fraud. In Scotland, report cybercrime to Police Scotland. If there is immediate danger, call 999.
What can wait
- You do not need to decide today whether to make public statements or pursue the sender.
- You do not need to wipe your devices immediately; evidence and account control come first.
- You do not need to contact the sender to test whether they are real.
- You do not need to solve every account at once; start with email, cloud storage, banking, and any account using the same password.
Important reassurance
These messages are often sent in bulk and are written to make you panic and pay quickly. You can slow the situation down, preserve what matters, and check for real compromise step by step.
Scope note
These are first steps only. If you confirm files were accessed, money was lost, work systems were involved, or sensitive personal data may have been exposed, later decisions may need specialist technical, organisational, legal, or victim-support help.
Important note
This guide is general information, not legal, medical, financial, therapeutic, cyber security, or other professional advice. If you believe you are in immediate danger, call 999.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.