Sextortion: What to Do First and How to Preserve Evidence of Online Blackmail
A new profile, a few days of friendly messages, an invitation to move to a private video call. Then the tone shifts without warning: the person on the other side claims to have recorded everything and demands money to keep the video away from the victim's contact list. This is sextortion, and it reaches far more people than the silence of those who experience it would suggest. Europol tracks online sexual coercion and extortion as a persistent threat across the European Union, while the FBI has issued repeated national alerts about financially motivated sextortion targeting teenage boys.
Anyone caught inside that conversation searches for one thing: what to do about sextortion, right now. And almost everyone reacts exactly the way the blackmailer hopes. They delete the chat, close the profile, block the account or pay. Each of those moves, taken on instinct within minutes, destroys the only thing that lets investigators trace the offender: the digital trail of the extortion. Even people composed enough to save a few screenshots end up with something fragile, because a manually captured screen is a copy with no guarantee about its origin, its date or its integrity, and it can be challenged on exactly those grounds.
The correct sequence is the opposite of instinct: secure the evidence first, then block and report. And securing it does not mean filing it in a folder on your phone. It means capturing it at the source with a forensic method that fixes its content, its provenance and the exact moment it existed, so that it holds up in front of law enforcement and, later, in front of a court.
How online blackmail works and why the first reaction destroys the evidence
Sextortion is extortion built on the threat of publishing intimate images or video. The offender obtains the material through deception rather than by breaking into a device, then uses it as leverage for a payment demand. The window between the threat and the victim's reaction lasts minutes, and that is exactly where the evidence is either saved or lost.
Sextortion is now tracked as a distinct category in international threat reporting. Europol's Internet Organised Crime Threat Assessment identifies online sexual coercion and extortion of minors as a persistent threat across the European Union, driven by organised groups operating at scale from outside Europe. In the United States, the FBI and Homeland Security Investigations received more than 13,000 reports of online financial sextortion of minors between October 2021 and March 2023, involving at least 12,600 victims, predominantly boys, and linked to at least 20 suicides. The National Center for Missing and Exploited Children has recorded a comparable pattern, with reports of financial sextortion rising sharply year over year. What every one of these sources notes is the same thing: the reported figures represent a fraction of the real total, because shame keeps most victims from coming forward at all.
The recurring pattern: contact, trust, threat
The script barely varies. An attractive profile approaches the victim on a social network or a dating application, usually with photographs stolen from other users. A few days of intense conversation follow, often moved to a different messaging platform than the one where contact began. Then comes the proposal of a private video call or an exchange of images. On the other side a camera is recording, or a pre-recorded video is played to simulate a real person.
At that point the tone changes. A screenshot from the video appears, alongside a list of the victim's contacts scraped from their public profile and a payment demand with a short deadline, often just a few hours. The time pressure is not incidental. It exists precisely to stop the victim from thinking, asking for help and documenting what is happening.
Paying, deleting, closing the profile: three mistakes that help the blackmailer
The first mistake is paying. Law enforcement guidance is consistent across jurisdictions: giving in does not end the matter, it sustains it, because it confirms to the offender that the leverage works and opens the way to further, more insistent demands.
The second mistake is deleting. The conversation contains the elements that make identification possible: account identifiers, digital wallet addresses or payment references, message timestamps, unintentional geographic clues. Erasing them hands the offender impunity.
The third mistake is closing the profile, whether the victim's own or the one used to make contact. That account is part of the scene that needs to be documented. Blocking the offender is correct, but it belongs after the capture, not before it.
What preserving evidence actually requires
Victims are routinely told to "keep the evidence" and "take screenshots". The instruction is right and incomplete. Keeping a file is not the same as being able to prove what that file represents, and the gap between the two only becomes visible when someone contests it.
The three questions every digital exhibit has to answer
Any digital item offered as proof has to survive three questions, whatever the legal system.
- Where did it come from? Nothing inside a saved image ties it to the web address or application it was taken from.
- When did it exist? A file's creation date reflects the device clock, which anyone with access to the phone can change.
- Has it changed since? Without a reference value fixed at capture time, no one can demonstrate that the image was not edited afterwards, and editing a screenshot is within anyone's reach.
Authentication standards and why a plain screenshot struggles
International practice converges on the same requirement. Under Rule 901 of the United States Federal Rules of Evidence, the party offering an item must produce evidence sufficient to support a finding that it is what they claim it is, and the rule specifically contemplates authentication through distinctive characteristics or through a process whose reliability can be shown. Regulation (EU) No 910/2014, known as eIDAS, gives qualified electronic time stamps a presumption of accuracy as to the date and time they indicate and as to the integrity of the data they are bound to.
ISO/IEC 27037, the international standard on the identification, collection, acquisition and preservation of digital evidence, sets out the principles that determine whether a digital exhibit will be treated as reliable: the process must be auditable, repeatable, reproducible and justifiable, and every handling step must be recorded, as set out in the guidance on the ISO/IEC 27037 standard. A screenshot captured by hand on a personal device fails all four criteria, not because the content is false, but because nothing about the method allows an independent party to verify it. This is why the practical question in a sextortion case is never "did you keep the messages", but "can you demonstrate that these messages are exactly what you received, and that they existed before the account disappeared".
| Criterion | Manual screenshot | Certified capture at the source |
|---|---|---|
| Content origin | Not documented | Web address or application recorded during capture |
| Date and time | Device clock, alterable | Qualified time stamp issued by a trusted provider |
| Integrity | Cannot be verified afterwards | Cryptographic fingerprint comparable at any time |
| Effect of a challenge | Burden falls on the victim, often requiring a technical expert | Immediate technical verification against the certificate |
| Context of the page or chat | Only the framed portion | Full sequence plus the offender's profile |
What certified evidence at the source actually is
Certified evidence at the source is a copy captured at the moment the content is visible, through a process that records where it came from, computes a cryptographic fingerprint of it and binds a qualified time stamp to it. From that point on anyone can verify independently that the material has not changed by a single byte and that it already existed in that form at that date. It is the difference between saying "this is the conversation I received" and being able to demonstrate it without asking anyone for a leap of faith. TrueScreen works on exactly this step: it is a data authenticity platform that captures digital content using a forensic method and seals it by integrating the electronic seal and qualified time stamp of third party qualified trust service providers under the eIDAS framework. The result is a file that is defensible from the moment it is created, with no need for reconstruction later.
Capturing the conversation and the offender's profile
The first thing to capture is the conversation in full, not the individual threatening messages. The complete sequence shows how the relationship was built, the moment the request changed in nature and the link between the two phases, which is what makes the extortion design visible. Certified chat capture fixes the exchange as it stands, including visible dates and identifiers.
The offender's profile comes immediately after, and it is the most volatile part of the scene. Accounts used for sextortion are abandoned quickly, often within hours of the payment demand. A certified copy of the profile page, with the username, the images and the capture date, preserves something that may not exist the following day. The same logic applies to digital identity theft and cloned accounts, where the speed of capture decides whether anything will be left to show.
Digital seal, time stamp and chain of custody
Two distinct elements are applied to the captured content. The digital seal guarantees that the package has not been altered after capture: any modification, down to a single character, makes verification fail. The qualified time stamp fixes the moment the capture took place, using a time reference that does not depend on the clock of the victim's phone.
Around these two elements the chain of custody is built, meaning the record of every step from capture to delivery. It answers the question every defence lawyer asks: who had access to this material, when, and with what opportunity to interfere. With the TrueScreen application the entire sequence runs on the victim's own device and ends with a downloadable certificate, without the victim having to interact any further with the blackmailer or send the material to a third party.
From threat to report: how it plays out
Someone receives a message at 11pm with a screenshot from the video call and a demand for 500 euros by the following morning. Instead of replying, they open the certification application and capture the full conversation, the offender's profile page and the message containing the payment details. The whole operation takes a few minutes. Only then do they block the contact and stop responding.
The next morning they walk into the police station with a file containing three certified captures, each carrying a verifiable date. When the account is deleted two weeks later, the content is already fixed and no one can argue it was constructed after the fact. The same approach applies to other relationship driven frauds, as seen in romance scam cases where evidence has to be certified before reporting, and it extends to online reputation protection when the material ends up circulating anyway.
Sextortion evidence: what to preserve and in what order
Order matters as much as content. This is the sequence that maximises what investigators can use without exposing the victim any further.
- Do not reply and do not pay. Every reply feeds the negotiation and eats into the time available to document.
- Capture the full conversation, from the first message to the last, not just the threat.
- Capture the offender's profile: username, images, page address, any linked accounts.
- Capture the payment demands: wallet address, card number or reference of the service used.
- Capture any evidence of distribution, if the material has already been published or sent to third parties.
- Block the contact and temporarily restrict your social profiles, without deleting them.
- Report to law enforcement, attaching the certified captures, and notify the platforms in parallel.
- Store the certificates somewhere separate from the phone, together with receipts for any payments already made.
Where minors are involved the sequence stays the same, but the report is filed by whoever holds parental responsibility and the platform should be alerted at the same time, since removal timelines for content depicting minors are considerably shorter.
The point of the whole procedure is singular: to reach the people investigating with material that does not have to be taken on trust. Blackmail runs on haste and shame, and it counts on the victim destroying the traces without any help. Reversing that mechanism takes a few minutes and one counterintuitive decision: document first, react afterwards.

