Skip to content

ACTIVE CRISIS

A scammer said they have my passwords — what do I do now?

You're in the right place. This is one of the most common scare tactics scammers use. In most cases, they are bluffing — but the right response is the same whether they are or not: change your passwords now, and do not pay them anything.

In an active crisis?

  • Call your bank
  • Call the platform (Amazon, PayPal, MobilePay, etc.)
  • Call local police

Step 1 — Do not pay, do not respond

Do this now: Do not send any money. Do not reply to the scammer's message or email. Do not click any link they sent. Paying does not make them go away — it tells them you will pay, and they will ask for more.

The most common version of this scam is an email that includes one of your real passwords — usually an old one from a data breach — to make the threat seem credible. This is called a "sextortion" or "password scam" email. The password is real; the rest of the threat is almost always fake.

Important: Scammers buy lists of leaked passwords from old data breaches and send mass emails to thousands of people. They do not know who you are, and they almost certainly do not have access to your accounts or devices. The password in the email is the only real thing they have.

Step 2 — Change the password they mentioned immediately

Do this now: If the scammer showed you a real password, change it on every account where you use it. Even if it is an old password, change it everywhere it appears. Use a different, unique password for each account.

You can check whether your email address has appeared in a known data breach at haveibeenpwned.com — a free service run by a security researcher. If your email is there, it tells you which breach exposed your data, so you know which passwords to prioritise.

Step 3 — Secure your most important accounts

Do this now: Change the passwords on your email, bank, and any account that holds money or personal information. Then turn on two-factor authentication (2FA) on each of them. Use an authenticator app rather than SMS if the service offers it.

Your email is the most important account to secure. If a scammer gets into your email, they can reset passwords on every other account. Start there.

Important: If the scammer claims to have accessed your computer or phone, and you have reason to believe they did (for example, you installed software they told you to), follow the steps on the remote access scam page as well.

Step 4 — Report it

Report the scammer to the authorities in your country. Forward the scam email as an attachment if you can.

You're safer once you've done this: You did not pay. You changed the password they mentioned. You secured your most important accounts with new passwords and 2FA. That is the right response.

What happens next

In the vast majority of cases, these scammers send one email and move on. If you do not pay and do not respond, you are very unlikely to hear from them again. They are running a mass operation — they move to the next target.

If you receive further threats, do not engage. Save the messages as evidence and report them. Do not pay.

This is not your fault. Your password appeared in a data breach at a company you trusted — that is on them, not you.

Related situations

This page was last reviewed: June 26, 2026.
Crisis pages are drafted with AI assistance, then reviewed line-by-line by the editor, sourced against official reporting authorities, and tested for tone and clarity before publication.