Sentinel Vault
← All field notes
Fraud & Crime Trends · August 10, 2026

The Sextortion Numbers Nobody's Talking About: Why Older Victims Lose the Most

An older adult's hands holding a glowing smartphone at a dark wooden table at night, with reading glasses, a checkbook, and a coffee mug nearby, and a faint network of connected points visible in the blurred background, illustrating organized sextortion targeting adults.

Most of what gets written about sextortion focuses on one picture: a teenage boy, a fake girlfriend, a threat that arrives within hours of a single photo. That picture is real, and it is the majority of what I see. But it is not the whole story, and the part that gets left out changes how I think everyone should be warned about this.

The FBI's Internet Crime Complaint Center received more than 75,000 sextortion submissions in 2025. Buried in that report is an age breakdown that surprised me even after years of working these cases. Victims under 20 filed 11,316 reports and lost a combined $1.3 million. Victims 60 and older filed roughly half as many, 6,121, and lost $14.9 million, nearly eleven times as much. Do the math per case and the gap gets sharper. The average loss for a victim under 20 was around $115. For a victim over 60, it was around $2,433, more than twenty times higher.

Same crime. Same script, almost word for word, in most cases. Wildly different outcome, and it comes down to one thing: who has money to take.

I want to be clear about why this matters, because it is not a statistics exercise. Every public conversation about sextortion right now, mine included, is aimed at parents and teenagers. That's necessary. It is also incomplete, and the group losing the most per person is one nobody is specifically warning.

How the operation actually works

Here is what the mechanics actually look like, based on both my own casework and research from groups that track this at scale. Thorn's research into NCMEC's sextortion data found that in cases where the method was specified, 70 percent started with the perpetrator posing as a young person and trading images first, before any threat appeared. It is not a stranger demanding a photo cold. It is a conversation that feels mutual right up until it isn't. NCMEC's own 2025 data shows offenders increasingly move that conversation to encrypted messaging apps quickly, specifically because it is harder to trace and harder for platforms to report.

Why paying doesn't end it

Once a threat lands, the instinct almost everyone has is to pay and make it go away. Thorn's data on this is the number I'd want every reader to actually absorb: among victims who paid, 27 percent faced continued demands afterward anyway. Paying is not the end of the transaction. It is proof the account works, and proof gets used again. NCMEC states this plainly in their own guidance to victims: cooperating or paying rarely stops the blackmail.

It was never personal

None of this is personal, and that is the part that is genuinely hard to internalize in the moment. A large share of these operations trace back to organized networks, not lone predators. Thorn's research found ties to Nigeria and Côte d'Ivoire in nearly half of cases where origin could be established, consistent with a string of federal cases in the last two years charging members of coordinated sextortion rings rather than individuals acting alone. These are volume operations. The script doesn't change whether the person on the other end is 16 or 66. What changes is what happens after the threat lands, because a 45-year-old with a mortgage and a job to protect and a retiree with real savings both look, from the other side of the screen, like someone with something to lose and a way to pay for it to stay hidden.

That is the actual difference between the age groups in the data. It was never that older adults are more gullible. It's that they have more to take, and shame does the rest of the work keeping them quiet about it.

What actually helps

In the order it matters most:

Stop responding the moment a threat appears. Don't negotiate, don't explain, don't ask what they want. Every message you send is more data about how you react.

Do not pay, and if you already have, do not assume the next payment is the one that ends it. The data says it usually isn't.

Screenshot everything before you block. Then block, on every platform they have access to, not just the one where it happened.

Report it. IC3.gov for adults, NCMEC's CyberTipline at report.cybertip.org for anyone involving a minor. Both exist specifically for this and both feed real investigations.

Tell someone. The single biggest factor in these cases resolving without a lasting financial or personal cost is getting another person involved early, before the isolation the scammer is counting on has time to set in.

If you supervise employees, run a family business, or manage anyone with independent access to money, this is worth a conversation that goes further than "protect the kids online." The person with the most to lose in your organization may not be who you'd expect.

Frequently asked
Is sextortion only a risk for teenagers?
No. FBI data from 2025 shows victims across every age bracket, and victims over 60 lost more money on average per case than any other age group, despite filing fewer reports overall.
Does paying a sextortion demand make it stop?
Usually not. Research from Thorn found that 27 percent of victims who paid faced continued demands afterward. NCMEC's own guidance states that cooperating or paying rarely stops the blackmail.
Where should sextortion be reported?
Adults can report to the FBI's Internet Crime Complaint Center at IC3.gov. Any case involving a minor should also go to the National Center for Missing & Exploited Children's CyberTipline at report.cybertip.org.
Are these scams run by individuals or organized groups?
Research and recent federal cases point to organized, often international networks running these operations at volume, using consistent scripts across many victims rather than individually targeting people.
About the author
Pete Hish, Sentinel Vault founder
Taught by Pete Hish · Founder

A working cyber-fraud supervisor, not a vendor consultant.

US Army veteran. Active sergeant supervising a cyber and fraud investigations team at a large Southern California law-enforcement agency. Ten-plus years inside the cases that hit small businesses, families, and public-sector agencies first. The training is shaped by what actually goes wrong, not what vendor decks predict.

Certified Cybersecurity SpecialistCertified Cyber Fraud SpecialistCalifornia POST Certified Instructor
Hacked or Hardened? book cover
Prefer the long-form version?

Hacked or Hardened? covers these patterns end-to-end — the four ways small businesses get hit, what to fix first, and how to lead through an incident.

Related field notes
Next step

Want this kind of analysis for your team?

A 2–4 hour cyber risk briefing: the threats specific to your business, the controls that actually pull their weight, and a 90-day action plan.