Hi Greg, I’m sorry to hear about this and that we didn’t get back to you sooner.
You’re not alone. This is one of the most common scam emails going around right now.
What you’re dealing with
This is almost certainly a ransom scam email, not an actual RAT (Remote Access Trojan) infection. The scammers send these out in bulk, often using an old, leaked password of yours (from a data breach years ago) to make the threat feel credible. They claim to have “proof” and demand payment, usually in crypto, but they don’t actually have access to your device.
A few reasons this points to a scam rather than real compromise:
- iPhones are sandboxed. A RAT installed remotely without you clicking anything or installing a rogue app is extremely rare.
- These emails are template-based. Thousands of people report getting nearly word-for-word identical messages.
- Real attackers with actual access rarely announce themselves. They monetize quietly instead.
What we’d recommend
- Don’t pay. Paying confirms your email is active and often leads to more attempts, not fewer.
- Check haveibeenpwned.com with your email address to see which old breaches your password came from. That’s likely the source.
- Since you’re already running Norton 365, run a full scan just to be thorough and confirm there’s nothing on the device.
- Check your iPhone for anything unfamiliar under Settings > General > VPN & Device Management (rogue configuration profiles are one of the few ways an iPhone can be compromised) and Settings > Face ID & Passcode for any devices you don’t recognize.
- Report the email. Forward it to reportphishing@apwg.org and file a report at IC3.gov (FBI’s Internet Crime Complaint Center). It won’t get your money back, but it helps track patterns.
- Block and delete rather than reply. Replying, even angrily, confirms the address is monitored.
On the phone number
You likely don’t need a new number unless the harassment is coming through texts or calls, not just email. A new number is a bigger hassle (updating every account, bank, contact) than the scam itself usually warrants.
What you’ve already done right
Password changes, locking cards, and being cautious were smart moves, even if this turns out to be a bluff. Better safe than sorry. You can dial some of that back once you confirm nothing unusual shows up in a scan or the breach check.