How to train staff to respond to sextortion email scams

Sextortion email scam training for 2026: teach staff to recognise bulk extortion emails, refuse the payment demand, preserve evidence and report within minutes.

Sextortion email scams claim a criminal has recorded compromising footage of the recipient through their webcam and threaten to publish it unless a payment arrives, usually in cryptocurrency. This 2026 guide trains staff to recognise the pattern, refuse the demand and report the email through the right channel within minutes.

TL;DR

Why this matters

The National Anti-Scam Centre issued an urgent warning about a major bulk email extortion campaign after Scamwatch received hundreds of reports in a single week from people targeted by criminals claiming to have compromising images or videos taken through their webcam. The Centre found no evidence the senders had any real access to the devices they named.

The emails work because they arrive at a personal moment. A message that names your birth date, your street and a password you retired years ago feels like proof, so the sender counts on panic instead of a webcam. In reality those details come from old data breaches sold in bulk, merged into thousands of near-identical threats.

For an employer the damage is not only the money. A frightened employee may hide the email, pay from a personal account on a work device, or click a link inside the message. Start with security awareness training so the team treats a threatening email as a reportable event rather than a private embarrassment.

What you'll need

Never forward a live sextortion email around the office as a warning. Use a redacted screenshot or a cleaned-up example instead.

Step 1: Name the pattern

Show the class of email rather than one message. A bulk sextortion email claims the sender hacked the recipient's webcam, recorded them visiting an adult website, and will send the footage to contacts unless a cryptocurrency payment lands within a deadline, often 24 to 48 hours.

Point out the tells: a password that is years old, a sender address unrelated to the claim, a deadline built to stop thinking, and a payment method that is hard to reverse.

Expected outcome: Staff can list the four tells without the example on screen. Common mistake: Treating one convincing detail, such as a real old password, as proof the whole threat is genuine.

Step 2: Teach the three refusals

Give staff a fixed sequence: do not pay, do not reply, do not click anything in the email. A reply confirms the address is live. A payment invites follow-up demands. Links and attachments carry the usual malware risk on top of the bluff.

Expected outcome: Staff state the three refusals in order. Common mistake: Replying to ask whether the sender is serious.

Step 3: Explain where the details come from

A real-looking password does not mean a webcam was hacked. Large data breaches have exposed hundreds of millions of email addresses alongside passwords and personal details, and criminals merge that data into mail-merge tools that send thousands of personalised threats at once.

Teach the test: the email knows old data, not current access. If a password in the message is still in use anywhere, that is a password problem to fix, not evidence of a recording.

Expected outcome: Staff can explain the bluff to a colleague in one sentence. Common mistake: Treating a matching password as proof the device is compromised.

Step 4: Preserve, then report

Ask staff to keep the original email rather than deleting it. A screenshot plus the sender address and the date is enough for most reports; IT may want the full headers.

Reporting moves the fear out of the employee's head. Internally the report goes to the agreed security route; externally it goes to Scamwatch or the national reporting service. Phishing simulations can rehearse the same moment in a safe drill, because the skill that matters is reflex, not analysis.

Expected outcome: A report reaches security within 10 minutes of the email arriving. Common mistake: Deleting the email in disgust and telling nobody.

Step 5: Rehearse the scenario

Run a two-minute drill. The learner opens a simulated sextortion email containing a plausible old password and a payment deadline, then walks the sequence: refuse, preserve, report, and get back to work. Repeat twice a year and vary the details so the drill does not become predictable.

Expected outcome: Staff complete the sequence unprompted during the drill. Common mistake: Making the example so obvious that the drill never tests composure.

Step 6: Handle the emotional side

Say plainly in training that receiving one of these emails is not a sign of gullibility and carries no blame. The people most damaged by sextortion emails are those who stay silent, pay quietly, or spend days worrying about a recording that does not exist.

Point to support channels for anyone genuinely distressed, and ask managers not to treat the topic as a joke. Humour in a team meeting teaches people to hide the next one.

Expected outcome: Staff know the response is no-blame before an incident happens. Common mistake: Managers joking about extortion emails in front of the team.

Step 7: Target the follow-up

Review which teams report threats quickly and which reports arrive late. Late reporting usually signals fear, not carelessness. Use human risk reporting to find the teams that need a refresher and measure whether report times improve after the drill.

Expected outcome: Follow-up reaches hesitant teams instead of everyone equally. Common mistake: Treating a single loud report as evidence the whole organisation is safe.

Troubleshooting

The email includes a password the employee still uses

Treat it as a credential exposure from a data breach. Change the password everywhere it is reused and check for unexpected sign-ins. The webcam claim remains empty.

An employee already paid

Contact the bank or payment provider immediately, report the payment through the agreed channel, and check the device for anything the employee clicked. Respond without blame so the report stays honest.

The same sender writes again after a report

Block and report again. Repeat contact after a non-payment is normal for bulk campaigns and confirms the bluff failed.

A staff member wants to investigate the sender

Do not engage. Replying to trace a criminal confirms a live address and invites more mail. Security can review the headers without contacting anyone.

Tools and resources

What to do next

Run one no-fault drill in the next 30 days and measure how fast a simulated sextortion email gets reported. Under 10 minutes is a workable 2026 benchmark; use the result to set the next Cyber Aware training reminder.

FAQ

What is a sextortion email scam?

A sextortion email scam is a message claiming the sender recorded compromising footage of the recipient and will publish it unless a payment, usually in cryptocurrency, arrives. Nearly all bulk versions are bluffs built on old data breach details.

Are sextortion emails real?

The threats are almost never real. Investigations of large campaigns found no evidence criminals had access to the webcams or computers they claimed to have hacked, and the personal details come from public data breaches.

Should staff pay a sextortion demand?

No. Payment invites further demands and marks the recipient as someone who pays. Staff should refuse, keep the email and report it through the agreed route.

What if the email shows a real password?

The password came from a data breach, not from watching the employee. Change it everywhere it is reused; the recording claim remains empty.

Where should sextortion emails be reported in Australia?

Report internally first, then to Scamwatch. Reports let authorities track campaigns and warn the next batch of recipients.

How often should sextortion training run?

Run the drill twice a year and refresh it whenever a large extortion campaign makes headlines, because that is when inboxes fill with copies.

One last thing

A sextortion email is engineered to be handled alone, in silence, late at night. Training that makes the first step 'tell someone' defeats the scam more reliably than any filter.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.