Four shapes, and the distinction that decides everything after hour one
A demand for money backed by a threat to a business's search visibility or online reputation is extortion, and in the United States the federal statute for it is the Hobbs Act, 18 U.S.C. section 1951. Four fact patterns recur, and the handling diverges once you know which one you have:
- The retrospective link demand. Someone claims to have already pointed spam links at you and wants payment to remove them.
- The prospective link threat. The message arrives before any links exist. The sender says they are about to build tens of thousands and will stop for a fee. Frequently nothing has been built and nothing will be; the message went to a scraped address list.
- Pay-to-remove content. Damaging material about you is published, made to rank, and then offered for removal at a price. This variant has the most law behind it and the highest success rate, because the damaging page genuinely exists and genuinely ranks.
- The post-intrusion demand. The site was compromised - injected pages, redirects, a defacement - and the message follows. This is an intrusion investigation before it is a search problem, and the Computer Fraud and Abuse Act, 18 U.S.C. section 1030, is in play from the first minute.
The distinction that matters for handling: in shapes 1 and 2 the threatened harm is usually illusory, and in shapes 3 and 4 it is real. The extortion is equally criminal in all four. A threat that cannot be carried out is still a threat made to obtain money.
This page is general information, not legal advice, and not a substitute for counsel or for law enforcement. I am not a lawyer, and nothing on this site is the practice of law. Whether a particular demand is a chargeable crime depends on the jurisdiction and on the facts. Nothing below is written in the imperative: it describes what victims who preserved their position actually did, in the order they did it. Anyone who has received a demand needs a lawyer, and where the demand is credible, a call to law enforcement - not a web page.
Hour zero: the two things that are not done
Payment is not made. The reasoning is below, at length, because "don't pay" as a slogan persuades nobody who is frightened.
No reply goes out from the business account, and certainly not an angry one. A reply confirms the address is live and monitored, marks the recipient as responsive, and creates a record that the sender controls and the victim does not. Asking for proof is a reply. Negotiating for time is a reply. If a response is ever appropriate, it is one counsel drafts after the evidence is secured, and there is almost never a reason for it to leave in the first hour.
Everything else in the first day is a sequence, and the sequence matters more than the speed. The two irreversible mistakes - paying and deleting - both happen in the first ten minutes, before anyone has thought about order.
Hours zero to two: preserve the message, then freeze deletion
The demand itself is the single most important artifact in the matter, and it is the one most easily lost.
- The message is exported with full headers - in Gmail, Show original; in Outlook, the internet headers - and saved as a file rather than left in a mailbox subject to an auto-purge rule. Headers carry the sending IP, the relay path and the authentication results, which is the material a law-enforcement referral is actually judged on. A forwarded copy loses them.
- A cryptographic hash of the exported file is recorded with the date and time it was taken, so the file can later be shown to be unaltered. The evidence preservation guide covers why that matters under the Federal Rules of Evidence.
- Attachments, any claimed list of links, any payment instrument - wallet address, account, transfer reference - and any stated deadline are captured verbatim. A cryptocurrency address is traceable and is exactly the kind of identifier that links one complaint to thirty others.
- Screenshots are taken showing the URL bar, the account and the system clock.
Then deletion stops, everywhere. Mailbox retention and auto-delete rules covering the relevant accounts are suspended - this is the moment a legal hold begins if litigation or a referral is even possible, because the obligation attaches when litigation is reasonably anticipated rather than when it is filed. The hosting provider and the CDN are asked in writing to extend log retention and preserve what they currently hold; access logs are commonly rotated within days, and the written request is itself evidence of when preservation began. And nobody deletes, cleans up or rewrites anything on the site.
Hours two to six: verify, before believing any of it
Almost every claim in an extortion message is checkable, and most of them fail the check. That determination changes the handling, so it comes before the response, not after.
- Search Console, Security and Manual Actions, Manual actions. This is the only place a Google penalty is confirmed. "No issues detected" means no manual action exists, whatever the message asserts. Most of the fear in a demand dissolves in the minute that check takes.
- Security issues, in the same place, confirms or excludes the fourth shape.
- External links, top linking sites, plus a third-party index exported with the export date recorded, compared against whatever domain list the sender supplied. A sender who cannot produce links that actually exist is bluffing.
- Analytics and rank data against dated update timelines. A drop that coincides with a confirmed core update and precedes the message is not evidence that the threat is credible. Treating an email and a drop in the same week as cause and effect is the most common analytical error on this page's subject.
What the Google reporting channels will not do, at any point in this sequence, is arbitrate the demand. No such process exists.
Hours six to twelve: contain, but only in the shape that needs it
This step applies to the post-intrusion shape and to nothing else, and it has one rule: preserve first, then remediate.
Imaging or snapshotting the compromised system, and copying the logs off it, comes before credential rotation and before cleanup. The order is not fussiness. Cleanup destroys the evidence of the intrusion, and the intrusion is the prosecutable part - a spam link is not a federal offense, while unauthorized access causing damage to a server used in interstate commerce is. A site owner who discovers injected content, deletes it within the hour and rotates every password has done the right operational thing and the wrong evidentiary one, and there is no way to get that back.
Where the two genuinely conflict - the site is down, the injected pages are damaging customers, waiting is not an option - an image or snapshot taken before cleanup resolves the conflict. It costs minutes and it preserves everything.
Hours six to twenty-four: counsel, insurance, then reporting
Counsel comes before the referral, not after. Counsel decides what goes into a report, whether a civil claim is realistic, whether any public statement is made, and whether the investigation's own communications are privileged. That last question is prejudiced permanently by how the first day is structured, and it cannot be repaired later. Whether any of it is actionable, and what a referral should say, depends on the jurisdiction and on the specific facts - which is why this sequence ends at counsel rather than at a form.
Insurance is checked on day one. Cyber and crime policies frequently cover extortion and incident-response costs, and their notification clauses are often time-limited, so a late notification can forfeit cover. Policy terms vary entirely and nothing here says any particular policy covers anything - this is a prompt to read yours, in the first day rather than the second week.
Knowledge is contained internally. The people who need to know are counsel, the incident responder, and whoever owns the decision. Wide circulation produces discoverable speculation and, occasionally, a leak back to the sender.
Then the report. And after the report, monitoring and preservation continue rather than stopping - the reason is in the prosecution record below.
Why paying fails, in six specific ways
The nearest thing to an official US government position on an analogous problem is the FBI's, on ransomware: "The FBI does not support paying a ransom in response to a ransomware attack. Paying a ransom doesn't guarantee you or your organization will get any data back." That statement is about ransomware, not about search extortion, and stretching it would be dishonest. The reasons specific to this subject stand on their own:
- You are buying nothing enforceable. No mechanism exists by which a payer can compel removal, verify removal, or recover the payment. No public case exists of a payer obtaining verified removal of a link campaign.
- In the link shapes you are usually buying relief from a harm that was never going to happen. Since Penguin 4.0 in 2016 Google's stated model has been devaluation of manipulative links rather than demotion of the site they point at, and its published response to the 2014 mass campaign was that its algorithms are designed to stop this kind of activity causing problems for site owners.
- Payment marks the payer. An address that pays goes on a list, and the second demand is larger. In the pay-to-remove variant that is the entire business model rather than an unfortunate side effect.
- Payment funds the next campaign, and in aggregate is the reason these campaigns keep being sent at all.
- Payment can create its own exposure - sanctions screening, accounting treatment and disclosure obligations, depending on the payee and the business. That is counsel's question, and it is a real one.
- Payment removes you from the pattern. A prosecutor's leverage comes from the aggregate across victims. A quiet payment takes one victim out of the aggregate, which is precisely the outcome the sender is buying.
The honest exception, which deserves stating rather than hiding. In the pay-to-remove shape the harm is real and present, and a business watching a defamatory page rank for its own name is under genuine pressure that no amount of reasoning about link devaluation touches. The answer is still not payment - it is the suppression and legal routes on the SERP defamation page, plus a referral, because paying a pay-to-remove operator is exactly the conduct a state attorney general charged as extortion, money laundering and identity theft in May 2018.
Where a demand actually gets reported
The Department of Justice publishes a routing table for computer and internet crime. It directs computer intrusion to the local FBI office, the Secret Service and the Internet Crime Complaint Center, and internet fraud to those plus the Federal Trade Commission. There is no row headed "internet extortion"; the routing for these shapes is the same set.
The Internet Crime Complaint Center (IC3) takes complaints at ic3.gov, with the form itself at complaint.ic3.gov. IC3 states that complaints filed there "are analyzed and may be referred to federal, state, local or international law enforcement and partner agencies for possible investigation." Set expectations honestly, because the alternative is a victim who feels ignored and stops cooperating: IC3 also states that "due to the massive number of complaints we receive each year, IC3 cannot respond directly to every submission." A filed complaint is a data point in a pattern, not a case opened on your behalf. That is not a reason to skip it - the pattern is exactly what makes these prosecutions possible - but a victim expecting a call back will be disappointed, and telling them so in advance is a service.
The local FBI field office. Where the sender is domestic and identifiable, the figure is real, or there is an intrusion component, a direct call to the field office is materially more effective than a form alone. The FBI's own guidance pairs the two: contact your local field office or file at ic3.gov.
The state attorney general's consumer protection division. State prosecutors have brought these cases - the pay-to-remove charges of May 2018 are the documented example, and charges are allegations rather than findings. Not every state has a functioning intake for this, and this research pass surveyed none of them beyond that one action.
Local law enforcement. Often dismissed as pointless, and often it is - but a local report generates a report number, and report numbers are what insurers, banks and platforms ask for. It costs an hour.
The Federal Trade Commission, at reportfraud.ftc.gov, does not resolve individual complaints either; it builds cases from patterns. It is the right place for the review-extortion variant, because the FTC's 2024 rule on consumer reviews and testimonials reaches the use of unfounded or groundless legal threats, physical threats, intimidation or certain false public accusations to prevent or remove a negative consumer review. That URL was displaying a government shutdown notice on 3 September 2026 and directing visitors to consumer.ftc.gov, so check it before relying on it.
What prosecutors have done, and what the system will not do for you
United States v. William Laurence Stanley - the federal prosecution of a self-described black-hat search practitioner who extorted businesses by threatening to publish damaging material about them - is the case worth knowing, and the link removal extortion page holds the record. What belongs here is what it teaches someone deciding whether to report.
The conviction exists because somebody reported
The firm that had already paid, and then went to the FBI, is the only reason there is a guilty plea, a 37-month sentence and $174,888 in restitution to cite at all. No report, no case, no record for any later victim to point at.
The case was built on the aggregate, not on one victim
Prosecutors put the victim count at 40 to 45 and aggregate losses above $230,000. A single victim with a five-figure demand is rarely enough to open a federal file; that same victim's complaint sitting in a database alongside thirty others describing the same sender is a different proposition entirely. That is the real argument for filing when nothing seems likely to come of it, and it is a far better argument than "it might help you."
Retaliation is real, and separately prosecutable
Stanley targeted the company that reported him after his conviction, and was convicted by a federal jury of witness retaliation on 19 April 2017 for doing so. A victim weighing whether to report needs both halves of that: retaliation happens, and retaliating against someone for giving information to federal law enforcement is itself a felony carrying up to ten years. Monitoring and preservation continue after the report for exactly this reason - the second wave becomes evidence in a file that already exists.
A cross-border element is an obstacle, not a bar
Payments in that matter went abroad by money transfer, and a co-defendant was arrested overseas, extradited and pleaded guilty. In a small case, distance is usually fatal. In a serious one it demonstrably is not.
What the criminal system will not do
It will not restore your rankings, remove the content, or move on your timetable - that prosecution ran from indictment in March 2014 to sentencing in January 2016. And in a criminal case you are a witness, not a client: you do not control charging, plea or restitution, and restitution ordered is not restitution collected. The civil track runs in parallel and has the same defect from a different angle, because a civil claim needs a defendant with a name, and identifying a throwaway address means a Doe action and a platform subpoena before there is a case to bring. The legal theories guide sets out what those claims require, and is candid that it cites no decided negative SEO ruling under any of them.
Frequently asked questions
Should I pay to make it stop?
No, and the reasoning matters more than the instruction. You cannot compel removal, verify removal or recover the money; in the link shapes the threatened harm is usually one that would never have materialized; a paying address is a marked address and the next demand is larger; and payment removes you from the aggregate of victims that makes a prosecution possible. Counsel should also be asked about sanctions and disclosure exposure before any payment is even discussed.
Should I reply and ask for proof?
Asking for proof is still a reply. It confirms your address is live and monitored, restarts the clock on the sender's terms, and creates correspondence they control. Verification comes from your own data instead: the Manual actions report, your links report and a dated third-party export tell you whether the claimed links exist without giving the sender anything.
Is it worth reporting a small demand?
Yes, and aggregation is the reason. Federal cases in this area are built from many complaints describing one sender, not from a single five-figure demand. IC3 states plainly that it cannot respond directly to every submission, so expect no reply - the value of filing is that your payment address, your headers and your dates join a pattern somebody else may already be assembling.
Will they retaliate if I report them?
It has happened, in the one federal prosecution there is to cite, and it produced a second conviction: retaliating against a person who gives information to federal law enforcement is itself a felony. Plan for the possibility rather than let it deter you. Keep brand monitoring, review monitoring and link monitoring running after you file, and keep preserving, because the second wave is evidence in a file that already exists.
Can Google do anything about an extortion email?
No. Google operates no process that arbitrates an extortion demand and never has. The spam report exists for spam, returns nothing to the reporter, and per Google's own documentation the submission text is sent to the reported site owner if a manual action issues - so writing a spam report about your extortionist means writing your extortionist a letter.
The email says my rankings will drop next week. How do I know if it is real?
Check the Manual actions report first, because that is the only place a Google penalty is confirmed. Then compare any domain list the sender supplied against your links report and a dated third-party export - a sender unable to show links that are really there is bluffing. Finally, check your traffic against the published update calendar before treating the message and a drop in the same week as cause and effect.