Every guide says talk to your child. Treasury wrote down what it looks like in your bank app.
A notice to financial institutions describes the payments in this crime with unusual precision, including what gets typed in the memo field and what time of night it happens. It is the most concrete detection guide for parents that exists, and it was not written for parents.
What this is
In financial sextortion a criminal poses as someone else, obtains a sexual image, then demands money to keep it private. Paying does not end it. The US Treasury's financial crimes bureau states that despite receiving an initial payment "the perpetrator will often continue to demand more payments", and independent analysis of child-protection reports found 27 percent of those who paid faced further demands. The same Treasury notice, published 8 September 2025, tells banks what the money looks like, and a parent can see the same things: a run of small round-dollar payments, 10 to 50 dollars, through apps like Cash App to someone never paid before, often late at night, sometimes with a memo reading "please stop" or "delete the pictures". The conversation is hidden. The transaction history is not. If a threat has arrived, do not pay, do not delete anything, and report it at tips.fbi.gov and report.cybertip.org.
This is not the bitcoin email
Worth separating these two immediately, because they share a name and almost nothing else.
The mass-emailed threat, the one claiming your webcam was recorded and demanding bitcoin, is a bluff. The sender has your email address from a breach and nothing else, and we have written about why that email is safe to ignore. Nobody is watching. Nothing exists.
What this article is about is the other thing. Here a person has spent hours or days talking to the victim, usually behind a fake profile of a young woman, and the material generally does exist. Treasury's notice defines it as perpetrators using fake personas to coerce victims into creating sexually explicit images or videos, then threatening to release the material to friends and family unless the victim pays.
The bluff costs the sender nothing and is sent to millions. This one is targeted, patient and personal, and it has killed teenagers.
The document that describes it best was written for banks
On 8 September 2025 the Financial Crimes Enforcement Network, the Treasury bureau known as FinCEN, published a notice on financially motivated sextortion, reference FIN-2025-NTC2. Its purpose is to tell financial institutions how to spot the payments and file reports on them.
Which means it does something almost no consumer guidance does. It describes the crime from the side that leaves records.
It opens with scale. In 2024 the FBI received nearly 55,000 reports of crimes related to sextortion and extortion, with financial losses totalling $33.5 million. The notice describes that as "a 59 percent increase in the number of reports received in 2023", so the jump is in how many people reported, not in the money.
It notes that while minors, especially boys aged 14 to 17, are particularly vulnerable, "many victims being over the age of 18".
And one set of numbers worth putting in front of anyone who believes reporting is pointless. Between October 2021 and July 2025, Homeland Security Investigations received 8,483 tips related to sextortion, leading to 854 victim identifications, 232 criminal arrests, 96 indictments and 16 convictions. The offenders are usually overseas and many are never caught, so this is not a promise. But people do get identified and arrested, and that only happens because somebody reported.
What the money looks like, in a parent's own account
FinCEN lists red flag indicators for banks. Read them as a parent and they stop being compliance language.
- A customer, "especially a customer who is a minor with an account co-signed by a parent or guardian", makes a series of low, round-dollar peer-to-peer transfers, between 10 and 50 dollars, totalling hundreds of dollars or less, over a short period.
- They go to someone the customer has no prior transaction relationship with.
- The person receiving the money rapidly transfers it onward to another account. That is a money mule, and FinCEN records that mules typically keep a 20 percent fee.
- The payments carry memos indicating extortion. FinCEN's own examples are "delete the pictures" and "please stop".
- They typically occur during late night and early morning hours.
Sit with the fourth one. A teenager, at two in the morning, typing please stop into the memo box of a payment app, because it is the only place they can say it. That is in a Treasury document, as a detection signal for compliance teams.
It is also sitting in a family's transaction history, where a parent could read it tonight.
Why the amounts are so small, and why that is the cruelty
The instinct when watching for financial harm to a child is to watch for something large. That instinct fails completely here.
FinCEN records that minors typically pay between 10 and 50 dollars, while adult victims pay between 500 and 2,500. The reason is set out plainly: minors do not have access to large amounts of money, or have none at all, so "a negotiation process normally ensues until the perpetrator and victim agree upon a dollar amount".
Read that again. The offender works out how little the child has, and takes that.
And then one more sentence, which is the hardest in the notice: "In some cases, minor victims may steal money from family members to meet the perpetrator's demands." A child taking small amounts from a parent's purse is a behaviour most families would read as a discipline problem. It can be a distress signal.
So the thing to look for is not a number that is big. It is a pattern that is small, repeated, and nocturnal.
Paying is documented not to work
This is usually asserted. It is worth showing that it is recorded.
FinCEN: "Despite receiving an initial payment, however, the perpetrator will often continue to demand more payments from the victim."
And from the other direction, the child-protection data. Thorn's June 2024 study of NCMEC CyberTipline reports found that roughly one in three reports carrying impact information mentioned making payments, and that "payments often did not stop the harassment": 27 percent of victims who mentioned paying went on to describe ongoing demands after that first payment.
The same study recorded an average of 812 sextortion reports a week to NCMEC in the last year of data it analysed, with 90 percent of victims detected in those reports male and aged 14 to 17, and 47 percent of reports showing ties to Nigeria and Côte d'Ivoire.
Paying tells the offender two things: the threat works, and this person can find money. Neither of those makes them stop.
They may have sent nothing at all
This section exists because of what it removes.
The whole crime runs on the victim's belief that they did something unforgivable and cannot tell anyone. Often that belief is not even accurate about the facts.
FinCEN records that "when potential victims refuse to send sexually explicit material, perpetrators have used manipulated content to extort these individuals", and that since April 2023 the FBI has seen an increase in victims reporting fake images or videos created from content posted on their social media or from non-explicit photos.
So a young person can do the right thing, refuse, and still receive a threat with a convincing image attached. Generative tools made that cheap, the same shift we traced in deepfaked video calls used against companies. If someone is being threatened with an image they never created, they have still been targeted, and none of it is their fault.
The first hour, in order
If this is happening right now, the order matters more than the detail.
- Stop paying. If money has gone already, send no more. The documented pattern is that payment invites more demands.
- Do not delete anything. Not the messages, not the account, not the profile. That is the evidence. Screenshot the profile, the threats and any payment details first.
- Report the account on the platform using its own safety feature. FinCEN lists this explicitly as a step for anyone being exploited.
- Report it to law enforcement. The FBI at tips.fbi.gov or 1-800-CALL-FBI. NCMEC's CyberTipline at report.cybertip.org. The DHS Know2Protect tipline on 833-591-KNOW. A young person can call NCMEC directly on 1-800-THE-LOST.
- Say the thing that matters. An adult telling a frightened teenager that they are not in trouble and that this is a crime committed against them does more work than any of the steps above.
Take It Down, and the fear it removes
The objection that stops families using removal services is understandable: I am not sending that picture to anyone else.
You do not have to. NCMEC runs a free service at takeitdown.ncmec.org, and its own documentation is explicit that "your image or video will remain on your device and will not be submitted as part of this process."
What gets submitted is a hash, described in their words as "a digital fingerprint" unique to that file, which is added to a list participating platforms can match against. The hash cannot be turned back into the image. NCMEC's own description is direct: "Take It Down is a free service" and "You can remain anonymous while using the service and you won't have to send your images or videos to anyone." The site is offered in a long list of languages, Arabic, Hindi and Chinese among them.
Be honest about the limits too, because they are on NCMEC's own page. The hashing "will not work on encrypted platforms or surfaces", so it cannot reach encrypted apps, and it covers participating platforms only. It reduces spread. It is not an eraser, and anyone promising one is lying.
It applies where the person was under 18 when the imagery was made, including adults reporting material created when they were minors.
It is not only teenagers
The public conversation is almost entirely about boys of 14 to 17, and that is where the most acute harm sits. But FinCEN says in its opening paragraph that perpetrators "can target anyone, with many victims being over the age of 18", and the adult payment range it records, 500 to 2,500 dollars, is not a footnote.
An adult in this position often does not recognise it as the crime they have read about, because everything they have read was about children. The advice does not change. Do not pay, keep the evidence, report it. The shape that leads adults here is the same one behind romance approaches that turn into money and pig butchering: a patient stranger, a fast-deepening relationship, and a request that arrives once trust has.
Where a link checker helps here, and where it plainly does not
This one needs an honest scope, and the honest answer is that most of this crime is somewhere we cannot reach.
We cannot see a direct message. We cannot tell whether the profile talking to someone is real, and no browser extension can. The grooming, the threat and the payment all happen inside apps, and nothing on this page changes that. The defences that matter here are a conversation that has already happened before the threat arrives, and a transaction history somebody looks at.
There is one part that is ours. These approaches frequently move the target off-platform, to a link, and that link is sometimes a fake login page built to take the account first, or a page that harvests more material. Layer 1 runs local URL checks in the browser before a page renders. Layer 2 checks the address server-side against reputation sources, our blocklist and a brand database of more than 550 names. Layer 3 is the AI deep scan, which reads what a page actually serves, one free scan a day for everyone and unlimited on Premium at $14.99 a year across up to three devices.
That is genuinely useful at one moment in a long sequence, and it would be dishonest to present it as more. If a link arrives in a conversation like this one, it is worth checking before it is opened. Everything else here is human.
Was a link sent in the conversation?
Paste it here before anyone opens it. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup.
Frequently asked questions
What is financial sextortion?
A criminal takes on a fake persona, usually a young woman, persuades someone into sending a sexual image, then threatens to send it to their friends and family unless they pay. The US Treasury's financial crimes bureau defines it in a September 2025 notice as perpetrators using fake personas to coerce victims into creating explicit material, then threatening to release it unless the victim provides payment. It is different from the mass-emailed bitcoin threat, where the sender has nothing and is bluffing. Here the material usually exists, or has been fabricated from ordinary photos.
How can a parent actually notice it?
In the payment history, because the conversation is hidden but the money is not. Treasury's notice tells banks to watch for a customer, especially a minor on an account co-signed by a parent, making a series of low round-dollar transfers between 10 and 50 dollars through peer-to-peer apps to someone they have never paid before, with the recipient rapidly moving the funds on again. It also names two details a parent can see directly: payment memos carrying messages such as delete the pictures or please stop, and transfers that typically happen late at night or in the early hours of the morning.
Why are the amounts so small?
Because the offender negotiates down to whatever the victim can reach. Treasury records that minors typically pay between 10 and 50 dollars while adult victims pay between 500 and 2,500, and that because minors have little or no money a negotiation usually happens until a figure is agreed. The same notice records that some minor victims steal money from family members to meet the demands. So a parent watching for a large unexplained loss will never see this. The signal is not the size of one payment, it is a pattern of tiny ones.
Does paying make it stop?
The evidence says no. Treasury states plainly that despite receiving an initial payment the perpetrator will often continue to demand more payments from the victim. Thorn's analysis of NCMEC CyberTipline reports found that 27 percent of victims who mentioned paying went on to describe further demands after that first payment. Paying confirms to the offender that the threat works and that the victim can find money, which is the opposite of an ending.
What if my child never sent an image?
They can still be targeted, and this matters because it removes the assumption of blame. Treasury's notice records that when potential victims refuse to send explicit material, perpetrators have used manipulated content instead, and that since April 2023 the FBI has seen an increase in victims reporting fake images or videos built from ordinary photos taken off their social media accounts. Refusing is the right decision and it does not always prevent the threat arriving.
What should happen in the first hour?
Stop paying, keep everything, and report. Do not send money, and if money has already been sent do not send more. Do not delete the messages or the account, because that is the evidence, and take screenshots of the profile and the threats. Report the offender's account using the platform's own safety feature. Report to the FBI at tips.fbi.gov or by calling 1-800-CALL-FBI, and file with NCMEC at report.cybertip.org. A young person can contact NCMEC directly on 1-800-THE-LOST. If the images are of someone who was under 18, takeitdown.ncmec.org can help have them removed, and the image never leaves the device.