Skip to main content
web60

Infrastructure

Website Hacked Extortion Email: How to Verify the Threat Before You Pay a Cent

Ian O'Reilly··13 min read
A large navy envelope pressing against a cluster of teal network nodes and soft overlapping circles on an off-white background

The myth goes like this: anyone who emails to say they have hacked your website must have hacked your website. Why else would they know your address, your domain, maybe even an old password of yours? So the reasoning runs, and it is exactly the reasoning the sender is counting on. These emails arrive through contact forms and inboxes every week. They name your domain. They claim a vulnerability was exploited and your database copied. They demand somewhere between a few hundred and a few thousand dollars in Bitcoin, set a deadline, and promise to leak your customer records, email your clients and wreck your Google rankings if you miss it.

Almost all of them are bluffs. Almost all. That second word is why this article exists, because the correct response is not "pay" and it is not quite "delete and forget" either. It is verify.

Consider a typical case. A Leitrim glamping site, a week into taking October mid-term bookings, gets a contact-form message at 6am saying the booking database has been dumped and will be sold unless a Bitcoin payment arrives within 72 hours. The owner has guests' names, phone numbers and arrival dates on that site. Panic is the natural reaction. It is also the one the sender designed the message to produce.

Myth One: "They Know My Domain, So They Got In"

They know your domain because your domain is public. That is the whole point of a website. The best-documented version of this scam has been circulating since at least the spring of 2020. BleepingComputer reported at the time on a campaign demanding roughly USD 1,500 to USD 3,000 in Bitcoin, threatening to leak databases, notify customers and get sites de-indexed with "blackhat" techniques. Patchstack, a WordPress security vendor, analysed a near-identical wave in 2021 and made the point that should end most of these panics: people who did not own a website at all received the same email. Wordfence documented another round in January 2023, delivered through site contact forms, again with no sign of tampering on the sites named.

Think about what that delivery method tells you. Contact forms are built to accept messages from anyone. An automated script can visit thousands of WordPress sites, find the form, paste in the template with the domain name swapped in, and move on. No vulnerability is needed. No access is gained. Your domain appears in the message because the script read it off the page it was standing on.

A real compromise looks different. Attackers who actually get in tend to stay quiet, because a hidden foothold is worth far more to them than one ransom demand. We covered that pattern in detail in our piece on how WordPress sites get hacked without the owner noticing: spam pages injected deep in the site, redirects that only fire for mobile visitors from Google, admin accounts nobody created. Loud announcements are rare. Quiet persistence is the business model.

Myth Two: "They Quoted My Password, So It Must Be Real"

This is the variant that gets people. The email includes a password you recognise, sometimes a current one. It actually comes from somewhere far more mundane. Large services get breached, and the email addresses and passwords from those breaches circulate in criminal databases for years. A scammer matches your business email address to an old breach record and pastes the password into the template. It proves they have a leaked list. It does not prove they have been anywhere near your website.

You can verify this yourself. Have I Been Pwned, the free breach-notification service run by security researcher Troy Hunt, will tell you which known breaches your email address appears in. If the password in the threat matches an account you held with a breached service, you have found the source.

That said, do not treat this as a reason to relax entirely. If the quoted password is one you still use anywhere, and especially if it is the one for your WordPress admin, your hosting account or your email, change it today and switch on two-factor authentication where the service supports it. The extortion is fake. The exposure of that password is real, and the next person to find it may not bother sending an email first.

Flat illustration of a teal envelope standing apart from a teal, cream and navy shield on a warm grey background
The threat arrives by email. The evidence, if there is any, lives on your server.

Myth Three: "Paying Makes It Go Away"

Paying does not buy silence. It buys a place on a list of people who pay.

An Garda Síochána is unambiguous on ransom demands: do not pay, because there is no guarantee you get anything in return. The corollary is obvious enough. Paying once tells the sender, and whoever they sell their list to, that you are worth trying again. Patchstack's look at the Bitcoin wallets in the 2021 campaign found that only a handful of recipients had paid, which tells you two things. Most owners correctly ignored it. And the few who paid handed money to someone who had nothing to sell them.

Ask yourself what the sender could actually deliver for the payment. If they have no copy of your database, there is nothing to delete. If they do have a copy, nothing stops them selling it anyway. Either way, the euro leaves your account and the risk stays exactly where it was.

Myth Four: "So It Is Always Fake and I Can Just Delete It"

This is the myth on the other side, and it is the one I would most like to correct.

Real extortion against websites exists. Cloudflare's DDoS threat report for the second quarter of 2025 found that around a third of the attacked customers it surveyed in June of that year said they had been threatened with, or hit by, a ransom DDoS attack, with that figure up sharply on the previous quarter. Cloudflare's numbers come from its own customer base, which skews larger and more exposed than a typical high-street business, so treat them as a sign of direction rather than your personal odds. But the direction is clear enough.

Abstract flat illustration of teal network nodes around a protected central block on a warm stone grey background
Most threats are bluffs. Verification is how you find the one that is not.

And some of the people behind these demands are not bluffing. Ireland's National Cyber Security Centre, in its guidance for small businesses, describes a code hosting company whose attacker got into the cloud control panel and demanded a ransom. When the company refused, the attacker deleted most of its data and its backups.

The lesson is not that every threatening email is real. It is that you should never decide whether it is real by guessing. Ten minutes of verification turns a frightening email into either a deleted message or an incident you caught early. Both outcomes are better than lying awake.

Verifying an Extortion Threat in Five Steps

This is the process I would want any website operator to run, in this order, before they reply, pay or forget.

  1. Preserve. Do not reply, do not click any link in the message, and do not delete it yet; forward it to yourself or save it, because if it turns out to be real, Gardaí will want the original.
  2. Verify the claim. Look for actual proof: a real excerpt of your customer data, a file path that exists on your site, a screenshot of your admin area; generic threats with no evidence are the signature of the bulk campaign.
  3. Inspect the production environment. Log in and look at the list of administrator users, recent posts and pages, and plugins you did not install, then open Google Search Console and look at the Security Issues report, which is where Google flags hacked content it has found.
  4. Confirm your rollback point. Find out when your last clean backup ran, where it is stored, and whether you or your host can restore from it today; a backup stored on the same server as the site is the first thing a real attacker deletes.
  5. Rotate and report. Change the passwords for your WordPress admin, hosting account and email, enable two-factor authentication where available, and report the email to your local Garda station if it contained real data or if you paid anything.

If step two produces nothing, and steps three and four come back clean, you are almost certainly looking at the bulk scam. Delete it and get on with your day.

If anything in step three surprises you, stop there and get help. An unknown admin account is not a cosmetic conflict. It is evidence.

What a Host Should Be Doing Before the Email Arrives

Every one of those five steps is easier on some hosting than on others. The criteria are worth spelling out, because they apply whoever runs your site.

  • Backups that run every night on their own, stored away from the site itself and restorable in one action rather than one support ticket.
  • Scheduled malware scanning, so that "has anything changed?" has an answer before you even ask.
  • Brute-force protection at the server level, so the password-guessing that precedes many real compromises is blocked before it reaches your login page.
  • A support team you can actually reach, in your own time zone, who will read the email with you rather than reply with a knowledge-base link.

For the glamping site in our example, the difference is stark. On a host that ticks those boxes, the owner forwards the email to support, the team confirms no admin changes and a clean nightly backup from a few hours earlier, and the whole thing is closed before the first guests arrive for breakfast. On a bargain shared host with backups stored on the same machine and nobody answering the phone, the same email produces a day of dread and no certainty at the end of it.

Web60 was built to meet that standard. The platform runs automatic nightly backups, malware scanning and fail2ban intrusion prevention on Irish infrastructure, takes safety snapshots automatically before updates and restores, and puts a real Irish support team on the other end of the ticket. All of that is included in the €60 a year, alongside the AI builder that gets the site live in the first place. Our complete guide to WordPress security and backups covers how those layers fit together if you want the longer explanation.

What Verification Cannot Tell You

Honesty matters here, so let me be clear about the limits. A clean malware scan and an unchanged admin list are strong evidence that your site has not been tampered with. They are not proof that nobody ever copied data from it. A competent intruder who read the database and left without changing anything would leave little for a scan to find. Server logs help, and a good host can review them with you, but no tool turns "probably not" into "certainly not".

Backups have their own limit. A nightly backup protects you up to last night. If you restore after a real incident, any bookings or orders taken since that backup need to be re-entered by hand, so know where to find them in your email notifications before you press the button.

And at a certain scale the job changes. A large online retailer that genuinely attracts ransom DDoS threats needs a dedicated DDoS mitigation service and its own security staff watching traffic around the clock, and enterprise security providers suit that workload better than any all-inclusive platform. Most local businesses are nowhere near that point. For them, the bulk extortion email is by far the more likely visitor, and the five steps above are enough to deal with it.

The Practical Upshot

An extortion email is a test of your process, not of your nerve. If you know where your backups are, who to call and what to check, a threatening message becomes a ten-minute verification job and a deleted email. If you do not, it becomes a sleepless night spent guessing.

The next time one lands in your inbox, the decision in front of you is a small one: run the five steps, look at what you actually find, and let the evidence, not the deadline in the email, decide what happens next.

Frequently Asked Questions

Someone emailed saying they hacked my website and want Bitcoin. Is it real?

In the vast majority of cases, no. Bulk campaigns send the same template to thousands of site owners through contact forms, and people without websites have received identical messages. Look for real proof, such as an actual extract of your data, and run the verification steps in this article before you decide anything.

Should I reply to a website extortion email?

No. Replying confirms that your address is monitored and that you are worried, which marks you as a better target. Save the email in case you need it as evidence, but do not engage with the sender.

How did the scammer get my old password?

Almost certainly from a breach at another service where you used the same email address. Check your address on Have I Been Pwned to see which breaches include it, then change that password anywhere you still use it and turn on two-factor authentication where available.

How do I check if my WordPress site has actually been hacked?

Review your administrator user list for accounts you did not create, look for plugins and pages you did not add, and open the Security Issues report in Google Search Console. A malware scan from your host adds another layer. If anything unexpected turns up, contact your host before changing anything else.

Should I report a website extortion email to the Gardaí?

If the email contains genuine data from your business, if you paid anything, or if your site shows signs of compromise, report it to your local Garda station. A bulk scam with no evidence behind it usually only needs deleting, though keeping a copy does no harm.

Will paying the ransom stop them leaking my data?

There is no guarantee, and An Garda Síochána advises against paying any ransom. If the sender has nothing, you have paid for nothing. If they do have data, payment does not stop them selling it, and it marks you as someone likely to pay again.

Sources

IO
Ian O'ReillyOperations Director, Web60

Ian oversees Web60's hosting infrastructure and operations. Responsible for the uptime, security, and performance of every site on the platform, he writes about the operational reality of keeping Irish business websites fast, secure, and online around the clock.

More by Ian O'Reilly →

Ready to get your business online?

Describe your business. AI builds your website in 60 seconds.

Build My Website Free →
Buy NowTry Free
Website Hacked Extortion Email: Verify Before You Pay | Web60