What to Do About a Blackmail Email Sent From Your Own Address
Question details
The user received a blackmail or Bitcoin extortion email that claims their account has been hacked and appears to be sent from their own email address.
- Product
- Email Service
- Device & OS
- not provided
- Scenario
- Receiving a suspicious extortion email demanding cryptocurrency, seemingly originating from the user's personal or work email address.
- Observed behavior
- The email arrives in the inbox showing the user's own email address in the 'From' field, accompanied by threats of hacked accounts and demands for Bitcoin payment.
Do not panic or send any money. This is likely a common tactic called 'email spoofing' where scammers forge the sender address to make it look like they have access to your account.
Secure Your Account and Gather Evidence
Follow these immediate steps to ensure your email account is secure and to preserve evidence of the spoofed email for support or IT analysis.
In most cases, the attacker does not actually have access to your account. They are manipulating the email headers to fake the sender information. It is critical that you do not interact with the attacker.
Do not reply to the sender, click on any links, open any attachments, or send money/Bitcoin to the provided wallet address.
Keep the original message in your inbox. Extract and save the complete email headers, which contain the true routing information. Share these headers only through an official, private support channel if requested by your IT department or email provider.
Log into your email provider's security dashboard (e.g., Microsoft account security page) and review your recent sign-in activity to verify if there were any successful unauthorized logins.
If you notice suspicious login activity or just want to be safe, immediately change your account password to a strong, unique phrase. Then, enable multifactor authentication (MFA) to prevent future unauthorized access.
Protect Your Documents with WPS Office
While you are securing your email account from spoofing threats, make sure your local files are also handled by a secure, reliable productivity suite. WPS Office is a highly compatible, lightweight, and free alternative to Microsoft Office that includes built-in document encryption.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install the Software: Run the downloaded setup file and follow the straightforward on-screen instructions to install the suite on your device.
- 3. Secure Your Files: Open your documents in WPS Office and use the 'Encrypt' feature under the 'Menu' to add password protection to your highly sensitive files.

Frequently Asked Questions
How did they manage to send an email from my own address?
The attackers use a technique called 'email spoofing.' They use specialized software to forge the 'From' address so it displays your email, hoping to trick you into believing your account is compromised. In reality, the email was sent from an external server.
Should I reply to the extortion email to tell them I know it's a scam?
No. Replying to the email, even to confront the sender, confirms to the scammers that your email address is active and monitored. This can lead to more spam and targeted phishing attempts.
Is my computer infected with malware or a virus?
Receiving a spoofed extortion email does not mean your device is infected. These are mass-mailed scams sent to thousands of users whose email addresses were found in public data breaches. However, you should never download attachments from these emails.
Do I need to delete my email account after receiving this?
No, deleting your account is unnecessary. Simply check your recent sign-in activity, change your password, and enable multifactor authentication (MFA) to ensure your account remains fully secure.




