Sextortion: what to do in the first hour, the first day, and the first week
If someone is threatening to release intimate images or video of you unless you pay them, this page is the sequence that actually works. Read the first section, act on it, then come back for the rest.
The three things not to do
Do not pay them. Not the first ask, not the tenth, not a "final small payment to make it go away." Paying does not end it. It confirms that you pay, and the demands escalate or your details get sold to another operator who starts a fresh cycle. Federal victim-guidance from the FBI's Internet Crime Complaint Center has been consistent on this point for years.
Do not respond after the first refusal. The conversation is scripted. Everything they say to you, they have said to other people that same day. Every reply you send tells them you are still engaged. Silence starves the interaction.
Do not delete anything. Not the messages, not their profile, not the screenshots. Deleting removes the evidence that every later step depends on. Block them, yes. But capture everything first.
The first hour
Screenshot everything. Every message, every threat, every payment demand, every profile page, every username. Full-screen captures with timestamps visible, not crops. If they contacted you from multiple accounts, capture all of them.
Save the payment address exactly as given. Crypto wallet, CashApp tag, PayPal handle, bank details, whatever it is. That string is one of the most useful things you can hand to investigators, because the same wallet usually appears across many victims. It is how isolated reports get linked into an actual case. If you already sent money, save the transaction ID too.
Move the evidence off your phone. Email it to yourself, put it in a cloud folder, print it if that is easier. Two copies minimum, at least one somewhere that is not the device you are panicking on.
Lock down your accounts. Change passwords on email, social, and banking. Turn on two-factor authentication using an authenticator app rather than SMS, because SMS can be defeated by a SIM swap. Log out of active sessions everywhere.
Block them on every platform. Then close the direct messages on any account they might jump to next.
Tell one person. Not everyone. One. A friend, a partner, a parent, an adult you trust if you are a teenager. Sextortion works because it isolates you, and breaking that isolation is the single most protective thing you can do. The person you tell does not need to fix anything. They need to know so you are not carrying it alone.
The first day
Report the account to the platform where they contacted you. Every major platform now has a sextortion-specific or non-consensual-imagery report path that is separate from general abuse reporting, and it is handled by a different team on a faster queue. Using the generic abuse form is one of the most common reasons victims conclude that "reporting does nothing."
Report to the FBI's Internet Crime Complaint Center at ic3.gov if you are in the United States. It is free, it takes about ten minutes, and it is the mechanism through which repeat operators get identified.
If you are under 18, or the person being threatened is under 18: stop here and go to takeitdown.ncmec.org. That is the National Center for Missing and Exploited Children's free tool. It generates a digital fingerprint of the images on your own device, so you never send the images anywhere, and that fingerprint is used to block distribution across participating platforms. NCMEC also files removals directly. This is the correct channel and it is not the same as an adult NCII case. IntimaShield does not handle content involving minors and will route you to NCMEC.
If you are 18 or older and worried they may post: register your images with StopNCII.org. Same model. The hash is generated locally on your device, StopNCII never receives the images themselves, and participating platforms block matching uploads before they go live. You do this yourself. It takes a few minutes and it is free.
Expect the threats to escalate in the first 24 to 48 hours after you stop responding. A countdown will start. They will claim to have already contacted your friends or family. Most of that is bluff, some of it is not, and your response is the same either way: no reply, no payment, evidence preserved.
The first week
Most volume operators move on within about 48 hours once you stop feeding them. Their model depends on extracting money quickly from many people, and a person who has gone silent is not worth continued effort.
If they do follow through and post something, your situation changes from an extortion problem to a takedown problem, which is a different and more tractable thing. The moves:
- Record every URL where content appears, and do not revisit those pages. Every visit is traffic that funds the host.
- File through each platform's NCII channel specifically. On mainstream platforms this frequently resolves within days.
- If the content lands on a pirate leak host that ignores standard reporting, the levers move up the stack: the CDN in front of the site, the domain registrar's abuse contact, the payment processor if the site sells subscriptions, and search-engine de-indexing to remove the discovery surface.
- If a covered US platform fails to remove within 48 hours of a proper notice, that is reportable to the Federal Trade Commission under the TAKE IT DOWN Act.
If you already paid
You were manipulated by people who do this professionally. The correct move now is exactly the same as if you had not paid: stop, block, preserve evidence, report. Do not send more. Do not negotiate. Do not apologize to them for stopping.
Include the amount and the transaction details in your IC3 report. Recovery is unlikely, but the financial trail is genuinely useful to investigators building cases against the operators.
Why this sequence works
Sextortion is a volume business. Operators run the same script against many people at once, and they win when a victim panics, isolates, and pays. The sequence above breaks all three. The checklist replaces panic with a series of concrete actions. Telling one person breaks the isolation. Refusing to pay removes the only thing they actually want.
The people who stay stuck are usually the ones who paid once and then felt they could not stop, or who told nobody and tried to manage it alone. Neither of those is a character flaw. They are the predictable result of a script designed to produce them.
Where a takedown service fits
If content has been posted and you are facing a spread across multiple hosts, particularly offshore ones that ignore standard reporting, that is when handing the work off becomes worth considering. Our Emergency Takedown files across the host, the CDN, the domain registrar, the payment processor, and search-engine de-indexing in parallel, and the case stays open until every URL is removed, confirmed dead, or every escalation channel has been exhausted. Pricing runs from $499 for content on one to five domains up to $1,999 for thirty-one or more.
What we commit to is the pursuit at every layer, evidenced by a per-case dispatch log you can read at any time. Not a guaranteed outcome, because on genuinely bulletproof hosts nobody can honestly promise one.
If nothing has been posted yet and you are in the threat stage, you do not need a takedown service. You need the checklist above, and you need to not pay.