# Unopened CEO “we have video” emails

2026-09-17

How to tell commodity sextortion from a real kompromat threat before anyone opens a link — and when a public-company executive should stop DIY and bring counsel.

Canonical: https://www.fabiocti.com/notes/unopened-ceo-video-emails/
Author: Fabio Correia

A CEO gets mail claiming there is hotel video. A honeytrap. A recording from Beijing, or Dubai, or “the building across the street.” Dozens of messages. Sometimes they arrive every hour. Nobody has opened them. The question is always the same: is it real, or is it phishing?

Most of the time it is phishing. That is not a vibe. It is what the headers usually say.

Real hidden-camera extortion against hotel guests does exist. Chinese prosecutors broke up rings in 2025 that fitted spy devices in five-star rooms in Beijing and other cities. The *shape* of the claim is not science fiction. It is also an easy story to invent, because it is culturally sticky and it lands hardest on a married, conservative, public-company executive.

So the first job is not to debate the encounter. It is to read the mail without touching the bait.

## Do not open it

Preserve the messages. Do not reply. Do not click the video link. Do not open the attachment “so we can see if it’s real.” Do not forward the live links into Slack, WhatsApp, or a personal Gmail so a coach can take a look.

If this is a public-company executive, treat that as a constraint, not a vibe. You are trying to find out whether the sender has anything, not whether the CEO had a bad night.

The original messages, as `.eml` files, with full headers, are enough to start. You do not need the alleged video to triage the claim.

## What the subject line is doing

Commodity sextortion is a script. The subject says they have video. The body says they will send it to a spouse, a board, or a church. There is a wallet, a deadline, a countdown. The details of the encounter are vague, or they are details anyone could have scraped from a booking, a visa stamp, or LinkedIn.

A real operator who filmed something tends to prove it early: a crop, a timestamp, a room number, a detail that was not in the press. They do not need to email every hour. Volume is what you do when you have a template and a list.

Hourly cadence is a tell. So is a sender who claims to be in Beijing and routes like a bulk phishing run. So is “open this link to see the video” as the only evidence.

## Why IT often calls it phishing — and is often right

On Microsoft 365 / Exchange Online, this mail is a known class. Secure Email Gateways, Defender, and add-on filters (Proofpoint, Mimecast, Sendio, whatever is in front of the tenant) see the same lures all week: stolen-video pretence, crypto demand, lookalike domain, freshly registered infrastructure.

IT is not being naive when they say “typical phishing.” They are matching it to a pile of identical junk. For a frightened executive, that answer feels too small. For the mailbox, it is usually the correct label.

The mistake is stopping at the label. “Phishing” describes the *delivery*. It does not answer whether this particular sender also has a file, or whether the CEO’s personal accounts are already burned, or whether the next message will land on a journalist instead of on the gateway.

## What an independent CTI pass still checks

Before anyone opens a link:

**Authentication.** SPF, DKIM, DMARC on the received copy. Failures do not prove innocence — criminals spoof — but a clean pass on a lookalike domain tells you this was built, not just blurted.

**Headers.** Received chain, originating IP, sending platform, reply-to versus from, message-id. You want the original `.eml`, not a screenshot, not a forwarded “FW:” that stripped the hop list.

**Infrastructure.** Domain age, registrar, hosting, reuse of the same wallet or landing host across other video-extortion runs. Commodity kits repeat themselves. A unique host with no siblings is more interesting than a blast.

**The claim, as text.** Did they name the hotel, the city, the date, a companion, a physical detail — or did they say “we have video” and outsource the rest to panic? Specificity is not proof. Absence of specificity is a tell.

**What they are not doing.** A sender who will not send a still, will not describe the room, and will only perform via a link is selling the click. That is the job of the lure.

You can do all of that without the alleged file, without mailbox admin rights, and without putting internal IT on a thread the executive wants kept off the company tenant.

## When to stop DIY

Stop when any of these are true:

The mail is landing on a public-company officer and someone is already talking about “not discoverable.” That is a counsel problem, not a Telegram problem. An NDA is confidentiality. It is not attorney-client privilege. If privilege matters, outside personal counsel retains the assessor and defines the scope in writing *before* the `.eml` files move.

A still or a clip actually appears — not a link, a still. Then you are no longer in template-land. Preserve it. Do not authenticate it by clicking wherever it lives. That is when you want a forensic copy and a lawyer in the room.

The executive has already replied, paid, or clicked. The triage changes. You are now looking at what they gave away.

IT has already called it phishing and the human still cannot sleep. A second pair of eyes on the headers is cheap compared with a CEO making a decision from shame. That is a discrete assessment, not an incident-response circus.

If you are a coach, an EA, or a GC holding unopened CEO sextortion mail: do not open it to be helpful. Export the `.eml`. Ask whether this needs to be counsel-directed. Then get someone who reads threatening email for a living to say, in writing, whether the threat has a body or just a subject line.

The video is the hook. The headers are the case.
