A new wave of sextortion emails is using the familiar “Hello pervert”/“I recorded you” template, falsely claiming the recipient was infected via a drive-by exploit and recorded through their webcam. To increase credibility, the messages include a real password associated with the target and demand payment (e.g., $800 in Bitcoin) to prevent alleged video/data release; the password reuse strongly suggests sourcing from previous data breaches and credential dumps rather than any actual device compromise.
Guidance for recipients emphasizes treating these messages as scams: do not pay, stop engagement, preserve evidence, and report to appropriate authorities (e.g., FBI IC3 in the US). Separately, phishing activity impersonating United Healthcare has been observed using a “free Oral-B toothbrush” lure and IPv6-mapped IPv4 literals (e.g., http://[::ffff:5111:8e14]/ → 81.17.142.20) to obfuscate scam infrastructure and route victims to rotating landing pages aimed at stealing PII and payment card data—a distinct fraud technique from the sextortion emails but similarly focused on social engineering and monetization.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Security analysis reported that at least one sender appeared to be using real passwords harvested from publicly accessible disposable inboxes on FakeMailGenerator. The exposed passwords were included in the sextortion emails to make the threats appear more credible.
By March 2026, a new wave of sextortion emails using the subject line 'You pervert, I recorded you!' was circulating. The messages reused the long-running 'Hello pervert' scam format, falsely claiming webcam compromise and demanding $800 in Bitcoin within four days.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.