Someone obtained my iCloud password through an old data breach connected to one of my email addresses. They accessed private videos and my phone contacts, then sent blackmail messages from multiple spam accounts. I contacted the police before responding to any ransom demands, but the attackers later distributed the photos. I've also contacted Apple, but I'm worried about what else I can do to secure my accounts, preserve evidence, limit further sharing, and report the sextortion.
4 Answers
The police response may feel invasive, but keep working through the case and ask for the report number and the investigator’s contact information. Don’t blame yourself or assume that being an adult means the crime cannot be investigated. If the threats are causing a crisis, reach out to someone you trust or a local crisis service while handling the technical and legal steps.
Do not reply, pay, or negotiate with the attackers. Save the messages, sender addresses, payment demands, timestamps, and URLs before blocking them. Change your Apple Account and email passwords from a trusted device, make every password unique, enable two-factor authentication, review trusted devices and recovery methods, revoke unfamiliar sessions, and check whether any email-forwarding rules were added. Report the incident to your local police and the appropriate national cybercrime or sextortion reporting agency; adult victims can still report these crimes.
Ask investigators how they handle sensitive digital evidence and whether you can submit files through a secure evidence process rather than sending unnecessary copies. Keep the original messages and files unchanged, and make a written timeline of the breach, threats, contact attempts, and distribution. You can also report copied intimate images to the services hosting them and use an image-removal or hash-based prevention service where available.
The likely entry point was the reused password from the old breach. Change the password for that email first, then update every account that used the same or a similar password. Check your email for unauthorized forwarding, recovery addresses, and login alerts, and consider using a password manager to create different passwords everywhere.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures