May 14, 2025

What to Do If You Are Being Blackmailed in the UK

What to Do If You Are Being Blackmailed in the UK

Being blackmailed can create intense pressure, particularly when the threat involves intimate images, personal information, damaging allegations, confidential business material or a demand for money.

The person making the threat may impose a short deadline, claim that disclosure is imminent or attempt to isolate you from anyone who could help. This urgency is often intended to force a decision before the situation has been properly assessed.

The first priority is to pause.

Do not allow embarrassment, fear or pressure to push you into an immediate payment or response. Preserve the evidence, secure any affected accounts and obtain appropriate advice before deciding what to do next.

What is blackmail under UK law?

In England and Wales, blackmail is an offence under section 21 of the Theft Act 1968.

The offence involves making an unwarranted demand with menaces with a view to gain or with the intention of causing loss. Whether conduct meets that legal definition depends on the demand, the threat and the surrounding circumstances.

Blackmail and extortion are often used interchangeably, but they are not always identical. Blackmail generally involves an unwarranted demand supported by a threat, often involving disclosure of private, damaging or sensitive information. Extortion is a broader term that may also include threats of physical harm, property damage, commercial disruption or other consequences intended to force payment or action. The precise legal position depends on the conduct, the demand and the jurisdiction involved.

A blackmailer may threaten to:

  • Publish private photographs, videos or messages.
  • Contact family members, colleagues, clients or an employer.
  • Make an allegation to the police, a regulator or the media.
  • Release confidential business or client information.
  • Damage a person’s professional or personal reputation.
  • Continue harassment unless money is paid.
  • Disclose information obtained from an account or device.
  • Take another harmful action unless the recipient complies.

Not every dispute involving a demand or threatened action amounts to blackmail. Where serious allegations, contractual rights or legal proceedings are involved, advice should be obtained from a solicitor.

Some online threats may involve harassment, impersonation or doxxing rather than blackmail. Doxxing generally refers to the publication or threatened publication of private identifying information, such as a home address or contact details. Where there is no demand for money, property or another action, the conduct may fall outside the legal definition of blackmail but could still involve harassment, stalking, malicious communications, data misuse or another offence. The correct reporting and legal response will depend on the circumstances.

What should you do if you are being blackmailed?

Do not respond under pressure

A blackmailer may set a deadline measured in hours or minutes and claim that any delay will result in immediate disclosure.

Before replying:

  • Avoid arguing with or threatening the person.
  • Do not make admissions simply to calm the situation.
  • Do not agree to a payment or meeting without advice.
  • Do not send further photographs, documents or personal information.
  • Take time to record what has happened and preserve the communication.

In some cases, no further engagement will be appropriate. In others, a limited holding response or communication through a solicitor may be considered.

The correct approach depends on the nature of the demand, the available evidence and the risk of escalation.

Assess whether the threat may be a bluff

Some blackmail and sextortion emails are sent in large numbers without the sender possessing the material they claim to hold.

The message may include an old or current password, a home address or other personal information obtained from a historic data breach. That information can make the threat appear more credible, but it does not automatically prove that the sender has accessed a device, activated a camera or obtained intimate material.

Indicators of a mass-distributed bluff may include:

  • Generic wording that contains few details specific to the recipient.
  • Claims of device access without supporting evidence.
  • An old password that has previously appeared in a data breach.
  • A demand for cryptocurrency sent with a short deadline.
  • Claims that the sender knows whether the email has been opened.
  • No sample of the material said to exist.

Do not assume the threat is genuine, but do not ignore exposed credentials either.

Change any password quoted in the message wherever it remains in use, enable multi-factor authentication and review the relevant accounts for unfamiliar sessions or recovery details.

A threat supported by genuine private material, recent account information or evidence of unauthorised access should be treated differently from a generic email containing information available through an earlier data breach.

Preserve the complete evidence

Do not delete messages, accounts or profiles before the evidence has been saved.

Preserve:

  • Full message histories.
  • Emails and available email headers.
  • Usernames, profile links and account names.
  • Telephone numbers and email addresses.
  • Call logs and voice notes.
  • Photographs, videos or documents supplied by the blackmailer.
  • Payment demands and deadlines.
  • Bank details or cryptocurrency wallet addresses.
  • Links to posts, websites or online profiles.
  • Details of any payment already made.
  • A dated chronology of contact and escalation.

Where possible, export complete conversations rather than saving only isolated screenshots.

A screenshot can show that a message existed, but the complete conversation may provide important context about how contact began, when the demand was made and how the threat developed.

Secure affected accounts

The blackmailer may have obtained information through a compromised email account, social-media profile, cloud-storage service or device.

Take proportionate steps to secure access:

  1. Change passwords on affected accounts.
  2. Use a different password for each service.
  3. Enable multi-factor authentication.
  4. Review active sessions and connected devices.
  5. Remove unfamiliar recovery addresses or telephone numbers.
  6. Check email accounts for unexpected forwarding rules.
  7. Review social-media privacy and contact settings.
  8. Secure connected banking or cryptocurrency accounts.
  9. Preserve relevant access logs where available.
  10. Seek cyber-security support if compromise is suspected.

Changing a password may not be sufficient where an attacker retains an active session, controls a recovery method or has access to the underlying device.

A physical bug sweep is not normally the appropriate response to an online account compromise. Digital-device or cyber-security concerns may require separate technical assessment.

Do not provide further material

A blackmailer may ask for additional images, identity documents, passwords or private information as proof of cooperation.

Providing more material can increase their leverage.

Do not send:

  • Additional intimate photographs or videos.
  • Passport or driving-licence copies.
  • Banking credentials.
  • One-time security codes.
  • Email or social-media passwords.
  • Cryptocurrency recovery phrases.
  • Remote access to a computer or phone.
  • Information about family members, colleagues or clients.

Preserve the request as evidence instead.

Should you pay a blackmailer?

Payment does not guarantee that the threat will end.

The blackmailer may retain copies of the material, demand more money or contact the victim again later. A payment may also demonstrate that the pressure has been effective.

A 2025 case in Lanarkshire illustrates this risk. A victim reportedly paid £4,500 after being threatened with the disclosure of an intimate photograph. Rather than ending the matter, the payment was followed by repeated demands over several weeks before the victim’s family intervened and the incident was reported. The case does not prove that every payment will lead to further demands, but it shows why payment should not be treated as a guaranteed resolution.

However, cases differ, and decisions should not be made from general advice alone. The appropriate response may depend on:

  • The credibility of the threat.
  • Whether the person appears to possess the material claimed.
  • The identity or likely location of the blackmailer.
  • The risk of immediate physical or reputational harm.
  • Whether payment has already been made.
  • The involvement of a child or vulnerable person.
  • Advice from the police or a solicitor.

Be particularly cautious where payment is requested through:

  • Cryptocurrency.
  • Gift cards or vouchers.
  • Money-transfer services.
  • Several unrelated bank accounts.
  • Third parties said to be agents or intermediaries.
  • Additional fees after an earlier payment.

Keep a record of every payment instruction, even where no money is sent.

When should blackmail be reported to the police?

Blackmail is a serious criminal offence.

Consider contacting the police where:

  • Money or another benefit is being demanded through threats.
  • There is a risk of physical harm.
  • The blackmailer knows your home, workplace or current location.
  • A child or vulnerable person is involved.
  • Intimate images are being threatened or distributed.
  • Accounts or devices have been compromised.
  • The behaviour is escalating.
  • A payment has already been made.
  • Other people may also be at risk.

Where there is an immediate danger to life or personal safety, call 999.

For non-emergency matters, use the appropriate police reporting route. Cyber-enabled or fraud-related conduct may also need to be reported through the relevant national reporting service.

A report does not guarantee that the person will be identified or that disclosure can be prevented. It creates an official record and allows the authorities to assess the evidence and risk.

What if the threat involves intimate images?

Blackmail involving intimate photographs or videos is often described as sextortion.

The material may be genuine, fabricated or digitally manipulated. The person may threaten to send it to relatives, friends, colleagues or social-media contacts unless a payment is made.

Take the following steps:

  • Do not send further intimate material.
  • Preserve the profile, messages and threatened content.
  • Record any bank account or wallet used in the demand.
  • Secure email, social-media and cloud-storage accounts.
  • Review whether the content may have been obtained through account compromise.
  • Report the profile and material through relevant platforms.
  • Seek police, legal or specialist advice where appropriate.

Detailed sextortion guidance should sit on a separate cornerstone page. This article should remain focused on the broader response to blackmail.

What if the allegation is false or disputed?

Some threats involve allegations of criminal, professional or personal misconduct.

Do not assume that the best response is to argue directly with the person or publish your own account online.

Preserve:

  • Communications before and after the alleged event.
  • Relevant location, travel or booking records.
  • Photographs or videos.
  • Names of potential witnesses.
  • Messages referring to money or another demand.
  • Threats to contact an employer, relative, regulator or authority.

Obtain legal advice where a serious allegation has been made or threatened.

The priority is to preserve the complete evidence and avoid messages that could later be taken out of context.

What if confidential business information is threatened?

Corporate blackmail may involve stolen data, internal documents, intellectual property, executive communications or threats to contact customers, regulators or the media.

A business response may require coordination between:

  • Senior management.
  • Legal advisers.
  • Cyber-security specialists.
  • Data-protection or compliance personnel.
  • Communications advisers.
  • Insurers.
  • Law enforcement.

The organisation may also need to consider whether regulatory, contractual or data-breach reporting obligations apply.

Knowledge of the incident should be controlled, but relevant information should not be withheld from those responsible for legal, regulatory or security decisions.

How specialist blackmail support may help

A structured blackmail response may include:

  • Assessing the demand, deadline and threatened consequences.
  • Preserving and organising communications.
  • Reviewing aliases, online identities and digital activity.
  • Examining available corporate and public records.
  • Assessing whether an account or device may have been compromised.
  • Supporting a controlled communication strategy.
  • Coordinating with solicitors or cyber-security specialists.
  • Preparing a clear chronology and evidence summary.
  • Monitoring for publication or escalation.
  • Supporting police liaison where appropriate.

Private investigators do not have unrestricted access to telecommunications records, private banking information or platform-held subscriber data.

Open-source and corporate-record research may identify useful connections or inconsistencies, but it may not establish who controls an anonymous account. Formal disclosure or law-enforcement powers may be required.

Conflict International’s Blackmail and Extortion Resolution Service supports individuals, families, executives and organisations facing sensitive threats involving money, reputation, private material or confidential information.

No adviser can guarantee that the person responsible will be identified, that material will never be disclosed or that contact will permanently stop.

Common mistakes to avoid

When facing a blackmail demand, avoid:

  • Paying immediately without assessing the wider risk.
  • Deleting messages or accounts.
  • Sending further private material.
  • Threatening the blackmailer.
  • Making admissions simply to delay disclosure.
  • Installing software at the person’s request.
  • Sharing the matter widely before a response plan exists.
  • Assuming that payment guarantees deletion.
  • Using a provider that promises a guaranteed outcome.
  • Publishing accusations without legal advice.

Take the next step

A controlled response should focus on:

  1. Preserving the evidence.
  2. Securing relevant accounts and devices.
  3. Assessing the credibility and capability of the person making the threat.
  4. Obtaining legal advice where allegations or proceedings are involved.
  5. Reporting immediate safety or criminal concerns.
  6. Developing a proportionate communication and protection strategy.

If you are facing a blackmail demand, threatened disclosure or extortion attempt, contact Conflict International in confidence to discuss the available evidence, immediate risks and appropriate next steps.

Get a quote today!

Can we help you? Contact us in confidence. We are always happy to help and give you an indication of how we may be able to assist.

Please provide a summary of the situation. Why do you believe you are being targeted? Mention any specific events or data breaches that may have preceded the threat.

What does the perpetrator claim to possess? (e.g. Sensitive corporate data, private imagery/video, proprietary intellectual property, or confidential correspondence).

How was initial contact made, and which platforms are currently being used for demands? (e.g. WhatsApp, Telegram, LinkedIn, encrypted email, or social media). Please include any known usernames or handles used by the perpetrator.

What is the nature of the demand (financial, specific action, etc.)? Have any deadlines been set, or has any payment already been made?

 

Need our help?
Get a free consultation today.

Get started
© 2026 Conflict International · Privacy Policy · Cookie Policy · Website by ghostwhite