Active Incident? 24/7 Response →
SleuthX

Confidential forensic response

Sextortion Investigation & Response

A digital-forensics team preserves the messages, attachments, and platform metadata to court-ready, forensically sound standards — prepared to support admissibility under FRE 901/902 — identifies how the leak happened, and coordinates takedowns and legal escalation, confidentially and often through your counsel.

Preserve the evidence first.

The single most useful thing you can do in a sextortion case is to stop, preserve, and decide with help — in that order.

Before you reply, pay, or delete anything, the threat itself should be captured: every message, the platform metadata, the sending-account details, and attached files with their hashes intact.

That preserved record is what later supports a platform takedown, an FBI IC3 referral, or a civil action.

Acting first and reacting second is what keeps a private incident from becoming a public one.

If a minor is involved — if you are under 18, or you are a parent and the person targeted is your child — please start on our safety-first page for minors and families instead.

It has the right crisis resources, captures nothing, and carries no tracking.

You are not in trouble, and the help there is free.

Why paying usually backfires

Paying tends to confirm you are extortable, raises the demand, and can land you on a network “suckers list” sold across operators — we have seen a first payment turn into months of rising asks.

Payment also moves over cryptocurrency rails that are forensically traceable.

Non-payment plus quiet legal escalation is consistently the better outcome, but preserve the threat first and decide with counsel.

Already paid? It is not too late — the transaction becomes traceable evidence, and stopping any further payment is the first priority.

Find the source, then lock it down

We audit your own digital surface to find how the material got out — a compromised email or iCloud, a monitored device, exposed cloud storage, or a former contact who kept access — then rotate credentials, revoke sessions, and remove monitoring software while preserving the evidence.

We also run lawful attribution analysis (wallet tracing, IP geolocation, infrastructure overlap); the individual operator is rarely identifiable, the network usually is.

What we coordinate

We hand the preserved evidence and findings to your counsel and coordinate the steps that sit outside digital forensics: platform trust-and-safety takedowns, an FBI IC3 referral, and — where a matter needs field investigation — a licensed private investigator who works under their own license, their contract, and their report.

Realistic expectations up front: attribution supports legal process, it is not a guaranteed name and address.

Where the leak exposed more than the threatened material, our digital forensics for individuals and privacy and exposure services close the surface that let it happen.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

How we handle a sextortion case

Frequently asked about sextortion response

Should I pay a sextortion demand?
Generally no. Payment confirms you are extortable, tends to raise the demand, and can land you on a network "suckers list" that is sold across operators. The payment also flows over cryptocurrency rails that are forensically traceable. Non-payment plus quiet legal escalation is consistently the better outcome — preserve the threat first, then decide with counsel.
I already paid. Is it too late to do anything?
No. Preservation and attribution still matter after a payment — the transaction itself becomes traceable evidence, and stopping further payments is the first priority. Preserve every message and receipt, make no further payments, and bring in a forensic investigator and counsel. We have seen a first payment turn into months of rising asks; the sooner the record is locked down and the demand is met with legal escalation instead of money, the better the outcome.
What should I do in the first hour?
Stay off the keyboard with the attacker — one short, neutral acknowledgement at most, and none is better once the threat is preserved. Then bring in a forensic investigator and counsel in the same hour. The investigator preserves the messages, files, and metadata with hashes intact; counsel handles legal exposure and any disclosure obligations.
Can the person behind it be identified?
The individual operator rarely; the network usually. Attribution uses crypto-wallet tracing, IP geolocation, language patterns, infrastructure overlap with known operations, and platform records, written up as a package that supports an FBI IC3 referral, a civil action, and platform takedowns. We set expectations up front: attribution supports legal process, it is not a guaranteed name and address.
How is confidentiality handled?
Engagements run under attorney-client privilege through your counsel where appropriate. NDAs are executed before substantive discussion, communication runs over signal-grade channels rather than plain email, and findings are written only for the people who need them. Your name and your case never appear in any marketing material.
What does it cost?
Sextortion response is scoped after a confidential intake call rather than sold off a price list, because scope changes with what we find. Done-for-you forensic work starts from a $5,000 refundable engagement retainer, with device-examination packages from $3,000 and $400/hr flat for anything beyond; ongoing monitoring or expert-witness availability is scoped separately. The first call is free and NDA-protected.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Get a confidential response

A direct, confidential conversation with the team that reviews every case. NDA-protected, often coordinated through your counsel. Confidential · court-ready forensics · no name in any marketing.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 15-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management