In most sextortion cases the threats are not carried out — especially once the target stops engaging and stops paying. But there are signals that change the calculation, and reading them correctly is the difference between sensible silence and a serious mistake. Here's what specialists actually look at.
The short answer, before the longer one
If you're trying to decide right now whether the person threatening you will follow through, the rough probability — in most sextortion cases — is low, and gets lower the longer you don't engage. The economics favour the attacker giving up on a non-paying target and moving on to easier ones.
But "rough probability" isn't good enough when it's your photos. So the rest of this guide is about how specialists actually read individual cases — which signals point toward bluff, which point toward higher risk, and what to do once you've made that read.
How specialists read these cases
When a specialist looks at a sextortion case in the first hour, they're reading several signals to estimate how likely the threats are to be carried out. None of them is decisive alone; the pattern across them is what matters.
Signals that suggest a bluff (most cases)
- Generic, templated language. "I have all your information. I will send your photos to everyone you know." Identical phrasing across thousands of cases — because it's literally copy-pasted from scripts. Templated language strongly suggests an organised group running volume attacks, where the script depends on victims who pay quickly.
- No proof offered, or only partial proof. A bluff often involves the attacker claiming to have content they don't have, or having far less than they imply. If they had everything they claim, they'd usually show it.
- Aggressive deadlines that keep moving. "You have 24 hours" followed by another 24 hours, followed by another. Real follow-through usually doesn't come with sliding deadlines.
- They demand payment in cryptocurrency or untraceable methods. Standard for organised scam operations. Not a signal of willingness to leak — just a signal of intent to extract payment.
- They have no apparent connection to your life. Random accounts, no shared social circle, no obvious motive beyond money. The threat is purely transactional, which means the cost-benefit doesn't favour leaking once payment stops being likely.
Signals that suggest higher risk
- Personal motivation beyond money. Ex-partner. Someone you rejected. Someone with a grievance. When the motivation isn't purely financial, the cost-benefit math changes — the attacker may follow through even without payment because the leak itself is the goal.
- Demonstrated access to your social network. They name your sister. They reference your employer. They've already messaged one of your contacts. This is a different kind of threat — they've shown they can reach the audience they're threatening to reach. For one specific flavour of this, where the threat is that they know your address or general area, see what it actually means when a blackmailer says they know where you live.
- They've already shared a small piece publicly. A "proof of seriousness" leak — a partial share, a screenshot to one contact, content posted to a small site — usually indicates they're willing to do more, or that they're part of an operation that does this routinely.
- They have content you don't recognise sending. If they claim to have content that wasn't from a Snapchat conversation but from a hacked account, a deepfake, or a recorded video call, the situation is different and the threat assessment changes.
- Repeated, escalating contact over weeks. Most volume-scam attacks fade within days when not paid. Sustained, personalised pressure over weeks usually means it's not a volume scam.
What changes the assessment
A few things that often look like signals but aren't reliable:
- How angry they sound. Anger is part of the script. It feels personal, but the messages screaming threats are almost always templated.
- Threats to contact specific people. Saying "I'll send to your boss" is in every script. Whether they actually can — by having found your employer's contact — is the real signal.
- Claims about how much content they have. Inflation is the default. "I have all of it" usually means they have one piece and want you to assume they have more.
What does change the assessment in real time:
- Whether the threats keep coming after you stop replying. Most scam-operation threats fade within 2–7 days of silence — the full day-by-day timeline is here. Persistent contact past that window suggests something different.
- Whether they ever provide proof of access. A specific detail about your life that they couldn't have got from your public social media, or evidence of content they shouldn't have, raises the assessment.
- Whether they try different channels. Initial threat via one platform, then escalation via a second, then a third — this is a script signal, suggesting an organised approach moving through their playbook rather than a personally motivated attacker.
If you'd rather have a specialist read the signals in your case directly, they can be on a call with you within the hour.
Get an honest read on your case →What to do with the assessment
This is where the analysis becomes actionable.
For most cases (templated, volume-scam pattern): the right move is preserving evidence, going silent, not paying, and waiting through the typical 2–7 day attrition window. Most of these cases die quietly. Platform reports through the right channels speed the process; sometimes account-level action removes the attacker entirely.
For cases with personal-motivation signals: the response is different. The cost-benefit math doesn't favour the attacker giving up just because money stops being likely. The work shifts toward preparing for the possibility that the threat is carried out — pre-emptive private conversations with people who matter to you, evidence preservation for any legal action, platform-level reporting, and in some cases targeted communication that's been carefully thought through.
For cases where some content has already been shared: the work shifts to containment and removal — different again from threat-stage cases.
The honest position: most threats aren't carried out, but some are. The reason specialist input matters is that the difference matters enormously for what you do next — and reading the signals correctly requires having seen many cases, not just the one in front of you.
A note on intuition
Many people come into a specialist conversation saying "I just know they'll do it." Intuition isn't useless, but it's also not what the cost-benefit calculation usually shows. Intuition in a panicked state tends to assume the worst because the worst feels safer to prepare for. The pattern across thousands of cases is more reassuring than the panic suggests — but the right response in your case still depends on reading the specifics.
One message is enough to start. A specialist will read your specific case and tell you what the realistic risk actually is.
Speak to a specialist →Common questions
What's the actual percentage of sextortion threats that get carried out?
There isn't a clean public statistic and any specific number would be misleading. What's observable: in cases handled correctly from the first hour, the large majority resolve without the content being leaked. In cases where the target engages, pays, or panics into mistakes, outcomes are worse. The variable that matters most is not chance — it's the response.
How long do I have to decide what to do?
The first 24 hours are the highest-risk decision window — most costly mistakes (paying, deleting evidence, deleting accounts) happen here. After that the urgency drops sharply. Specialists can usually read a case in 30–60 minutes, so there's no reason to make irreversible decisions alone in the first hour.
What if they've already messaged one of my contacts?
This is a higher-risk signal — they've demonstrated capability beyond just words. But it doesn't mean a full leak is coming. Often the contact-message is itself the leak, used to pressure you into paying. The strategy needs adjusting: pre-emptive private conversation with that contact may be appropriate, evidence preservation becomes more important, and platform-level reporting on the messaging channel they used becomes urgent. Specialist input is especially valuable in this scenario.
Should I just pay and end it?
The pattern across cases is clear: paying makes outcomes worse, not better. It marks you as a paying target and the demands either restart or your details get passed to other operators — the fuller reasoning is here. The exceptions where a specific, specialist-guided communication is right are rare and need judgement on the specifics, not a panic decision to pay.
What if I'm completely sure they're real and serious?
That sureness in a panicked state is unreliable — almost everyone in a sextortion situation feels certain the threats are real, because that's the emotional state the attack is designed to produce. The honest path is to act on the assumption the threat could be real (preserve evidence, prepare for the worst case) while not acting on the assumption it's certain (don't pay, don't make irreversible decisions). Specialist input is the cleanest way to separate fear from signal.
If most threats aren't carried out, why do specialists still treat them seriously?
Because "most" isn't "all." The job of specialist work isn't to dismiss threats — it's to read the specifics, prepare for the realistic worst case, and produce the best outcome for your case rather than the average case. The advice is calibrated to the situation, not to a statistic.
What if I missed the first 24 hours and have already replied or paid?
It happens often. The situation is still recoverable — the response just shifts. Stop the pattern (don't pay again, don't keep replying), preserve everything from the existing conversation, and bring in specialist help. People who have already paid still see most cases resolve, especially when the pattern of engagement gets cleanly broken.