How can you respond to extortion and privacy threats in companion apps?
An extortion message can arrive inside a companion app, by email, or through a social account linked to the same display name. It may threaten to publish a chat, private image, contact list, location clue, or real identity unless you pay, send more material, or complete another task. The message is evidence of a threat; it is not automatically proof that the sender controls your account or possesses everything claimed. That distinction matters. A rushed reply can reveal which facts are accurate, add a working phone number, or create a new payment trail. The safest useful posture is deliberate: reduce contact, preserve only the relevant record, verify account activity through official controls, and report through channels suited to the content and your jurisdiction.
Freeze the exchange without testing the sender's claims
Do not bargain, send another image, share a verification code, install a tool, or open a link supplied as proof. FTC, eSafety, Swiss NCSC, and Police.uk guidance all point away from paying or providing more material. That does not mean you should delete the conversation immediately. First capture the account name, profile URL or ID, message sequence, time, demand, payment destination, and any content URL. If a screenshot would reproduce sensitive material, store it privately and do not forward it through ordinary group chats. Avoid telling the sender which employer, relatives, phone number, or social account is real. Once the useful record is stable, use the app's block or contact controls according to its current design.
Build two columns: claims and independently verified events
In the first column, list exactly what the sender says: “I have your contacts,” “I logged in,” or “this file is public.” In the second, record only facts you can verify through a trusted route: an unfamiliar session in the app's security page, a password-reset email you requested, a live public URL, or a contact who actually received something. Do not follow the sender's login link; open the official app or type the service address yourself. This prevents an unverified claim from driving unnecessary disclosure. It also reveals when the incident includes account compromise, in which case password, session, recovery, and connected-app actions belong in the parallel account-security track rather than in the conversation with the sender.
Preserve a minimum useful evidence packet
A workable packet usually includes the sender identifier, full URL where available, dates and time zone, a short unbroken message sequence, the demand, destination account or wallet, and the confirmation number from any platform report. Preserve original filenames or message exports when an official channel requests them, but do not create extra copies merely for reassurance. The Swiss NCSC and eSafety materials both support keeping contact and transaction context. Write a simple chronology while it is fresh. If money was already sent, keep the payment record and contact the payment provider through its independently verified channel; do not accept a “refund” route supplied by the sender. Evidence needs vary by service and jurisdiction, so follow the receiving authority's instructions rather than guessing at a legal standard.
Use separate routes for content, account, and external help
A platform report can address an account, message, shared image, or policy violation; an account-security form can address a takeover; a specialist removal service may accept image hashes or URLs; and police or consumer agencies handle matters within their remit. These routes are not substitutes for one another. Submit the smallest relevant set of information and keep each receipt. If an image is already public, record its direct URL before asking for removal. If the threat concerns other kinds of private chat or identity data, use the app's privacy and abuse categories instead of forcing it into an image-only route. For immediate physical danger, use the emergency service where you are; otherwise use the official non-emergency path that applies to your location.
Close the privacy gaps the message exposed
Review the companion profile's display name, discoverability, connected social accounts, contact permissions, photo access, location access, active sessions, recovery email, and third-party sign-ins. Change a reused or exposed password from a trusted device, revoke unfamiliar sessions, and enable the strongest supported additional authentication method after confirming recovery options. Ask trusted contacts not to engage with a suspicious message and to send you the direct URL rather than redistributing the material. These actions reduce future routes; they cannot guarantee that a sender has no prior copy. Record what you changed so you can distinguish a new event from the original incident.
Track outcomes without repeatedly reopening the threat
Create a small incident board with rows for platform report, content URL, account review, payment-provider contact if relevant, external report, and follow-up date. Mark only observable results: receipt issued, content unavailable at a checked URL, session revoked, or request awaiting review. Do not repeatedly message the sender to test whether they still respond, and do not ask friends to search widely for the material; both can create more exposure. Policies and reporting forms change, so retain the page title, URL, and submission time rather than assuming a screenshot of an old instruction remains current. The goal is not a promise of total removal. It is a controlled response that limits new disclosure and keeps the next decision evidence-based.
Common questions
Should I pay to prevent publication?
Regulator guidance advises against paying or sending more material. Payment does not establish that the sender will stop, and it can create another demand or reveal usable payment information.
Should I delete the threatening conversation?
Preserve the minimum useful sequence, identifiers, URLs, and transaction details first. Then use the product's block, delete, and report controls with awareness that deletion may affect your access to the record.
Does a threat prove my companion-app account was hacked?
No. Check sessions, recovery events, connected apps, and public URLs through official channels. Treat verified account compromise as a separate response track.
