I'm using Windows 11, and someone claims they accessed my computer, recorded me viewing adult websites, and obtained my passwords. Some files or messages also appeared on my desktop, and they say the malware is driver-based. The passwords they listed are real, although I'm not sure whether the recording or malware claims are genuine. Is this a common blackmail scam, or should I treat my computer as compromised? What steps should I take to secure my accounts and remove any possible malware?
3 Answers
Do not pay or continue communicating with the sender. Paying rarely ends the demands, and the message itself is not proof that they have a video. Preserve the email and any suspicious files as evidence, but avoid clicking links or attachments. After securing your accounts, update Windows and your applications, run an offline antivirus scan, and consider reporting the extortion attempt to the relevant cybercrime authority.
Files appearing on the desktop do not prove that someone recorded you or installed driver-level malware. They could be a ransom note, a downloaded file, or something created by a compromised cloud-sync account. Don’t open or run them, and check their exact filenames, extensions, creation dates, and whether they are inside a OneDrive or other synced folder. Disconnect the computer from the internet if you see signs of active compromise, then scan it with trusted security tools or reinstall Windows from official installation media if you cannot establish that it is clean.
This is a very common extortion scam. The recording claim is usually a bluff, and real passwords may have come from an old data breach or phishing rather than from the alleged video. However, if any passwords are current, assume those accounts are at risk. Change them from a different, trusted device, use a different password for every account, sign out other sessions, and enable authenticator-based MFA where available. A password manager can help generate and store unique passwords.
The passwords they listed are definitely ones I still use, and the files appeared directly on my desktop. Does that mean the malware claim is real?

Would reinstalling Windows deal with a supposed driver-based infection?