logo
search
Suspicious Login Issues

How to Handle a Microsoft Account Sextortion Scam Email

Maira MehtabMaira Mehtab Sep 22, 2026 869 views

Question details

The user received a threatening sextortion email that appears to be sent from their own Microsoft or Outlook account, claiming their device is infected with Pegasus spyware.

Product
Microsoft Account / Outlook
Device & OS
not provided
Scenario
Receiving a threatening phishing email claiming device compromise and demanding cryptocurrency payment.
Observed behavior
A scam email arrives in the inbox, often spoofing the user's own email address, attempting to extort money by threatening to release compromising material.
Before you start

Do not panic, reply to the sender, click on any links, or download any attachments in the email. Remember that this is a common mass-phishing tactic, not a targeted hack.

Solution 1Recommended

Identify the Scam and Secure Your Microsoft Account

The most effective way to deal with this phishing attempt is to ignore the empty threats, delete the email immediately, and strengthen your account security.

Sextortion emails often spoof your own email address to make the threat look authentic. Claims of Pegasus spyware or having access to your webcam are completely fabricated to induce panic.

1
Do not reply or pay

Never engage with the sender or send any cryptocurrency payments. Paying them only marks you as a willing target for future scams and confirms your email is active.

2
Delete the email

Move the scam email directly to your Trash or Junk folder to avoid accidentally clicking any malicious links or embedded tracking pixels.

3
Enable Multi-Factor Authentication (MFA)

Log in to your Microsoft account security dashboard, navigate to Advanced Security Options, and turn on two-step verification for an extra layer of defense.

4
Update your password

Change your Microsoft account password to a strong, unique combination of letters, numbers, and symbols through the account settings page.

Check Data Breaches: You can use trusted services like 'Have I Been Pwned' to see if your email address or password was exposed in a known data breach, which is often how scammers obtain your contact information.
Free Microsoft Office alternative

Switch to WPS Office for a Secure Document Experience

If you are evaluating your digital security and looking for a reliable, cost-effective alternative to Microsoft Office, WPS Office offers a comprehensive desktop suite for Word, Excel, and PowerPoint files without the heavy subscription requirements.

  1. 1. Visit the official website: Go to the official WPS website to download the secure WPS Office installer.
  2. 2. Install the suite: Run the downloaded installer and follow the on-screen instructions to set up WPS Office on your device.
  3. 3. Open and encrypt documents: Start using WPS Writer, Spreadsheet, or Presentation, and utilize the built-in password encryption to secure your private files.
Highly compatible with Microsoft Office formats (DOCX, XLSX, PPTX)Built-in document encryption to keep your sensitive files secure locallyFree and lightweight office suite for PC, Mac, and mobile devicesFamiliar user interface allowing for seamless migration
microsoft office alternative - wps office

Frequently Asked Questions

How did the scammer send an email from my own Microsoft account?

Scammers use a technique called 'email spoofing' to forge the 'From' address so it looks exactly like your own email address. In reality, the email was sent from an external, unauthorized server.

Should I be worried about the Pegasus spyware claim in the email?

No. Pegasus is highly sophisticated, expensive spyware typically used against high-profile targets like journalists or politicians. Mass-email scammers falsely claim to use it purely as an intimidation tactic to scare you into paying.

What should I do if an old password is included in the scam email?

If the email includes a real password you recognize, it means your credentials were leaked in a past, unrelated data breach. Immediately change that password on any websites or accounts where you are still using it, and enable two-factor authentication.