# How did this extortionist get my (possibly) password?

**URL:** <https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102>\
**Category:** Factual Questions\
**Created:** [October 17, 2018, 6:16pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102 "2018-10-17T18:16:30Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [October 17, 2018, 6:16pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/1 "2018-10-17T18:16:30Z")

</div>

On Oct. 1 I received an email that went to my Outlook Junk folder. I was reviewing the folder today and ran across it. The subject line was

Your password is \<password\>

where \<password\> represents a password that is one that I think I have used in the past but do not believe is on a currently active account. But it was definitely not one this guy just came up with at random.

The rest of the email is nonsense. I would not have given it a moment’s thought except for the password. Obviously I didn’t pay and nothing happened, but where did this guy get a password that I may have used for something at some point, associated with my work email address?

A couple of days before that I got one with the same scam, but different wording. This time they spoofed my email address to “prove” that they had control of my email account. They also included a password, one very similar but not identical to any I have used. But, again, it does not look like they got it by guessing.

> [@Scammer](#):
>
> I do know \<password\> is your pass. Lets get right to the purpose. You may not know me and you’re most likely thinking why you’re getting this email? No-one has compensated me to investigate about you.
> 
> actually, I installed a software on the xxx videos (adult porn) site and you know what, you visited this site to have fun (you know what I mean). While you were watching videos, your internet browser began functioning as a Remote control Desktop with a keylogger which provided me with accessibility to your display and web camera. Just after that, my software program collected every one of your contacts from your Messenger, Facebook, and e-mail . Next I made a video. First part shows the video you were viewing (you’ve got a fine taste lol . . .), and second part displays the view of your cam, yeah it is u.
> 
> You actually have a pair of choices. We should understand each of these solutions in particulars:
> 
> First alternative is to neglect this e-mail. As a consequence, I am going to send your very own video recording to all your your personal contacts and just think concerning the awkwardness you experience. Not to mention if you happen to be in an important relationship, how it will eventually affect?
> 
> Number two solution should be to compensate me $5000. Let us call it a donation. In this instance, I most certainly will straight away delete your video. You will continue your daily life like this never occurred and you surely will never hear back again from me.
> 
> You’ll make the payment via Bitcoin (if you don’t know this, search for “how to buy bitcoin” in Google).
> 
> BTC Address: \<bitcoin code\>  
> [CASE-sensitive so copy and paste it]
> 
> If you may be planning on going to the law enforcement officials, look, this email cannot be traced back to me. I have dealt with my moves. I am just not attempting to demand much, I simply want to be paid for.
> 
> You now have one day to make the payment. I have a special pixel in this mail, and now I know that you have read through this email message. If I don’t get the BitCoins, I will, no doubt send your video to all of your contacts including members of your family, coworkers, and so on. Nonetheless, if I receive the payment, I’ll destroy the video right away. If you want proof, reply Yup! then I will send out your video to your 6 contacts. This is the non-negotiable offer and thus don’t waste mine time and yours by replying to this e-mail.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [October 17, 2018, 6:21pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/2 "2018-10-17T18:21:56Z")

</div>

[Existing thread.](https://boards.straightdope.com/sdmb/showthread.php?t=859017)

Basically, they got your password from some big data breaches years ago.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [October 17, 2018, 6:43pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/3 "2018-10-17T18:43:15Z")

</div>

There’s a part of me that kind of admires the cleverness, here. What can you do with a hijacked LinkedIn password that’ll be profitable? Not much… unless you can use it to convince a mark that you have something much more valuable.

---

<div class="post-metadata">

**Author:** ![filmore](https://avatars.discourse-cdn.com/v4/letter/f/7993a0/32.png) [@filmore](https://boards.straightdope.com/u/filmore)\
**Post date:** [October 17, 2018, 6:48pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/4 "2018-10-17T18:48:16Z")

</div>

There are different ways for a website to store your password:

1. Store it in clear text
2. Store it with a trivial modification
3. Store it with a complex modification

If hackers steal the user database for the website, they have access to the same password information. If the password is in clear text or is encrypted in a way that it can be figured out, hackers can figure out your password for that website. In addition, they likely have all the other user details you registered with, like your email address. So now they can send you spam with your password that you recognize.

This is also why it’s so dangerous to use the same password everywhere. If the hackers figure out your password from some benign website, they can then try to log in on other sites with your email/pw combination. So they’ll go to amazon, gmail, all the banking websites, investment websites, etc. If you use the same password everywhere, they’ll be able to log into all those accounts.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [October 17, 2018, 6:49pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/5 "2018-10-17T18:49:36Z")

</div>

Thanks, makes sense.

---

<div class="post-metadata">

**Author:** ![Projammer](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/projammer/32/559_2.png) [@Projammer](https://boards.straightdope.com/u/Projammer)\
**Post date:** [October 17, 2018, 7:12pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/6 "2018-10-17T19:12:19Z")

</div>

Fortunately most of the main sites recognize when an attempt is made from an unknown browser and will text you an additional code to enter before they allow access. That is apparently not as secure as it once was, but it’s far better than nothing.

---

<div class="post-metadata">

**Author:** ![markn\_1](https://avatars.discourse-cdn.com/v4/letter/m/f9ae1b/32.png) [@markn\_1](https://boards.straightdope.com/u/markn_1)\
**Post date:** [October 17, 2018, 7:17pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/7 "2018-10-17T19:17:58Z")

</div>

I hope it goes without saying that the second paragraph of the email is all lies. They have no video. Just ignore it. I’ve gotten several of these.

---

<div class="post-metadata">

**Author:** ![Jackmannii](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jackmannii/32/311_2.png) [@Jackmannii](https://boards.straightdope.com/u/Jackmannii)\
**Post date:** [October 17, 2018, 7:43pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/8 "2018-10-17T19:43:17Z")

</div>

> [@Scammer](#):
>
> While you were watching videos, your internet browser began functioning as a Remote control Desktop with a keylogger which provided me with accessibility to your display and web camera. Just after that, my software program collected every one of your contacts from your Messenger, Facebook, and e-mail . Next I made a video. First part shows the video you were viewing (you’ve got a fine taste lol . . .), and second part displays the view of your cam, yeah it is u.

Minimal embarrassment aside, it’s not really worth $5K for me to avoid having contacts know that I watch spaniel puppy videos on Facebook. ⭕smack:

---

<div class="post-metadata">

**Author:** ![Mr.Bill](https://avatars.discourse-cdn.com/v4/letter/m/5f9b8f/32.png) [@Mr.Bill](https://boards.straightdope.com/u/Mr.Bill)\
**Post date:** [October 17, 2018, 7:43pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/9 "2018-10-17T19:43:55Z")

</div>

Is there any such thing as a “special pixel” which can function to let the sender know that an e-mail has been read?

---

<div class="post-metadata">

**Author:** ![filmore](https://avatars.discourse-cdn.com/v4/letter/f/7993a0/32.png) [@filmore](https://boards.straightdope.com/u/filmore)\
**Post date:** [October 17, 2018, 7:53pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/10 "2018-10-17T19:53:31Z")

</div>

> [@Mr.Bill](#):
>
> Is there any such thing as a “special pixel” which can function to let the sender know that an e-mail has been read?

Yes, but it requires your email reader to display images. Many email programs do not show images by default for just this reason. The email reader just shows you the text, which doesn’t require any outside connections. But if you allow it to load images, then it will download any images configured in the email. To track you, spammers will put 1 pixel images in the email with unique names for each email. If the image server gets a request for that image with the unique name, they know the email was read (or at least the image was requested).

---

<div class="post-metadata">

**Author:** ![Mr.Bill](https://avatars.discourse-cdn.com/v4/letter/m/5f9b8f/32.png) [@Mr.Bill](https://boards.straightdope.com/u/Mr.Bill)\
**Post date:** [October 17, 2018, 8:14pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/11 "2018-10-17T20:14:21Z")

</div>

> [@filmore](#):
>
> Yes, but it requires your email reader to display images. Many email programs do not show images by default for just this reason. The email reader just shows you the text, which doesn’t require any outside connections. But if you allow it to load images, then it will download any images configured in the email. To track you, spammers will put 1 pixel images in the email with unique names for each email. If the image server gets a request for that image with the unique name, they know the email was read (or at least the image was requested).

Interesting. Sounds like a good reason to set my browser to not download images.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [October 17, 2018, 8:28pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/12 "2018-10-17T20:28:39Z")

</div>

No.  
This email we are talking about, not the web. Websites already know that you have visited.

---

<div class="post-metadata">

**Author:** ![Darren\_Garrison](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/darren_garrison/32/92_2.png) [@Darren\_Garrison](https://boards.straightdope.com/u/Darren_Garrison)\
**Post date:** [October 17, 2018, 9:22pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/13 "2018-10-17T21:22:02Z")

</div>

> [@](#):
>
> Next I made a video. First part shows the video you were viewing (you’ve got a fine taste lol . . .), and second part displays the view of your cam, yeah it is u.

Well, we know that somebody watches _Black Mirror_.

---

<div class="post-metadata">

**Author:** ![iamthewalrus\_3](https://avatars.discourse-cdn.com/v4/letter/i/258eb7/32.png) [@iamthewalrus\_3](https://boards.straightdope.com/u/iamthewalrus_3)\
**Post date:** [October 17, 2018, 9:58pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/14 "2018-10-17T21:58:35Z")

</div>

May I recommend [haveibeenpwned.com](https://haveibeenpwned.com/).

This site is run by cybersecurity researcher and expert Troy Hunt. If you register with your email address, he will email you whenever a new data breach is discovered in the wild with your email in it. It will also show you existing breaches that you’re email was in, and (I think) the password associated with that breach if it’s known.

You can use this to go change your passwords when data is released.

And of course you’re using separate passwords for every service, right? So that when one site is breached none of your other passwords are in jeopardy.

ETA: I mistakenly claimed Brian Krebs ran this site. Oops. Messing up my email/password/security researchers.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [October 18, 2018, 12:45am UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/15 "2018-10-18T00:45:00Z")

</div>

> [@iamthewalrus\_3](#):
>
> And of course you’re using separate passwords for every service, right?

Of course.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [October 18, 2018, 12:53am UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/16 "2018-10-18T00:53:31Z")

</div>

> [@filmore](#):
>
> To track you, spammers will put 1 pixel images in the email with unique names for each email. If the image server gets a request for that image with the unique name, they know the email was read (or at least the image was requested).

All they know for sure is that an email client downloaded the images, which can happen without a human ever opening the email. I think it may be used more often to validate that an email address is live then to determine if someone read it. There is no sure-fire way to know someone read your email. (A company I worked for also used this trick on our web pages for a third-party analytics firm to track traffic to our site.)

---

<div class="post-metadata">

**Author:** ![Saint\_Cad](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/saint_cad/32/18907_2.png) [@Saint\_Cad](https://boards.straightdope.com/u/Saint_Cad)\
**Post date:** [October 18, 2018, 2:11am UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/17 "2018-10-18T02:11:11Z")

</div>

> [@Chronos](#):
>
> What can you do with a hijacked LinkedIn password that’ll be profitable? Not much… unless you can use it to convince a mark that you have something much more valuable.

Hope you use that password on multiple sites

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [March 23, 2019, 5:12pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/18 "2019-03-23T17:12:56Z")

</div>

I am still getting these. Is there a way to deposit $0.01 into the Bitcoin account?

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [March 23, 2019, 6:59pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/19 "2019-03-23T18:59:31Z")

</div>

> [@CookingWithGas](#):
>
> I am still getting these. Is there a way to deposit $0.01 into the Bitcoin account?

As Grand Moff Tarkin once said: “You’re far too trusting.”

You really think that these emails will stop if you send them money? If anything, they are likely to multiply beyond measure if you “bite.”

---

<div class="post-metadata">

**Author:** ![filmore](https://avatars.discourse-cdn.com/v4/letter/f/7993a0/32.png) [@filmore](https://boards.straightdope.com/u/filmore)\
**Post date:** [March 23, 2019, 8:03pm UTC](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102/20 "2019-03-23T20:03:19Z")

</div>

Is the Bitcoin account the same in all the emails? But I suppose with Bitcoin, it doesn’t really matter as accounts can be created at will.

One possibility is that the database with your info is making its way through the hacker community. Different hackers could be sending out the same email to all the same people. There are likely automated scripts that will do all the work for the hacker. All the hacker has to do is point the script at the database and give it the Bitcoin account to insert into the email. So you shouldn’t assume that it’s just one hacker sending these emails and you just need to pay off that one hacker. Even if he went away, there are lots more who will be doing the same thing.

[Next page](https://boards.straightdope.com/t/how-did-this-extortionist-get-my-possibly-password/823102.md?page=2)
