The “We Hacked Your Webcam” Email Scam Is Back, and It’s Evading Filters
A wave of extortion emails claiming to have hacked your webcam and recorded compromising footage is landing in inboxes right now, including past Proofpoint’s filters. Nobody has hacked anything. It’s a mass-blasted bluff, deliberately engineered to slip past automated scanning. Here’s exactly how it does it, and what to do if you get one.
actually compromised
packed into a single email
stacked in the same message
What the Email Says
The message claims the sender has hacked your device, installed spyware, recorded you through your webcam while visiting adult websites, and will share the footage with your entire contact list unless you pay a ransom, usually a specific amount in Bitcoin, with a short deadline attached.
I have to share bad news with you. A few months ago, I gained access to the devices you use for internet browsing. Since then, I’ve been tracking your online activity.
Here’s what happened: I purchased access to compromised email accounts from other hackers online, which let me log into your account ([email protected]). Within a week, I had installed remote access software on every device you use to check that email, made possible because you clicked a link from your own inbox.
This software gives me control over your device, including your microphone and camera, and I have copied your files, photos, browsing history and contact list to my own servers. It updates itself constantly, so your antivirus will never catch it.
While monitoring your activity, I noticed you visit certain websites regularly, and I’ve recorded footage I don’t think you’d want shared with your contacts, family or colleagues.
If you have doubts, I can prove it. Unless you transfer the equivalent of $XX,XXX in Bitcoin within 48 hours, everything gets sent to everyone in your contact list.
It’s written to feel personal and technical, mentioning “Cobalt Strike,” antivirus evasion, “driver-based” malware, and even including your real email address in the body to make the threat feel credible.
This is a mass-blasted extortion template sent to thousands of people at once. Nobody has hacked your webcam. Nobody has your browsing history. It’s a bluff that relies entirely on fear and embarrassment to get you to pay before you stop and think.
The adult-content angle above is the most common version of this scam, but it’s just one variant of the same template. Other versions swap the threat entirely, claiming to have evidence of an affair, financial fraud, illegal activity, or stolen confidential business data, or threatening to contact family, colleagues, clients or your employer directly. The specific threat changes to whatever the scammer thinks will scare the recipient most. The structure, the fake technical detail, the Bitcoin demand and the countdown, stays exactly the same. If you or your team see any version of this pattern, the advice below applies regardless of what it claims to have on you.
Why This One Is Getting Past Proofpoint
This particular campaign uses two separate, deliberate techniques to defeat content-based email filters. Both are visible once you look under the hood.
Hidden junk-text spans
The real message is broken into small fragments, with random junk strings stuffed in between each one inside hidden <span> elements, set to zero width, zero height, and overflow hidden. A human sees clean text. A scanner sees scrambled noise.
Invisible Unicode padding
The plain-text version of the email is padded to over 57,000 characters with a repeating invisible Unicode character. The real message is diluted to a tiny fraction of the total content, enough to throw off keyword and density-based detection.
Looking at the email’s actual HTML source reveals the technique in full. A human reading the email in Outlook never sees any of the padding, the CSS hides it completely, so the message reads as normal, clean text. But to an automated content scanner reading the raw text or HTML, the message looks something like this:
0665107308-JJCGOJWHYY I 2082986722-QPOMNJZONQ h 1934715761-SXZMCEBHQT av 2550121649-ECHXDRRTNX e ...
That’s meaningless noise to a filter doing keyword or pattern matching, the extortion language and Bitcoin demand are still technically present, just diluted and scrambled so they don’t match known scam signatures cleanly.
Thousands of repetitions of a single invisible character
Decoding the plain-text MIME part reveals it isn’t gibberish, it’s a Unicode “variation selector,” a type of character normally used to modify how an adjacent emoji renders, but invisible on its own. Repeated thousands of times and mixed with plain spaces, it bulks the message out enormously while a human sees nothing but blank space. The real scam text barely registers against the sheer bulk of invisible filler.
Between the hidden-span trick in the HTML and the invisible-character padding in the plain-text part, this email was clearly built by someone who understood exactly how content filters work, and engineered around them. That’s exactly why judgement matters as much as filtering.
What to Do If You Get One
-
Don’t pay, reply, or click anything
There’s nothing to negotiate with. Paying doesn’t make it stop, it often just marks you as a responsive target for more scams.
-
Don’t panic over a real password or email address
These are almost always pulled from old, publicly leaked data breaches, unrelated to any actual current access to your systems.
-
Report it to IT or your MSP
So it can be reviewed and, where needed, added to filtering rules for everyone else in the business.
-
Delete it
Once reported and reviewed, there’s no further action needed.
The Bigger Picture
Email scams like this succeed by targeting people, not systems, no amount of filtering technology fully replaces a moment of “does this actually make sense?” before reacting. If something in your inbox is designed to make you panic and act fast, that’s the biggest red flag of all.
If you’re ever unsure whether an email is legitimate, forward it to your IT team before doing anything else.
Not sure if an email in your inbox is legitimate?
Technicalities can review it, explain what’s actually going on, and make sure your filtering is tuned to catch the next one. Get in touch to start the conversation.
Get in Touch