Online Blackmail / Extortion
Online blackmail (including “sextortion”) typically involves threats to publish private images or information unless money is paid. Depending on facts, PECA dignity, modesty, stalking, or fraud provisions may be discussed alongside other criminal law. Do not assume every threat message automatically satisfies a particular section.
Safety-first guidance
LawHub does not advise paying extortionists. Preserve the threat messages, payment instructions, and identities used. If there is an immediate risk to safety, contact local police in addition to any cybercrime filing.
Applicable PECA provisions
Links open LawHub’s National corpus text for PECA 2016. Read the full section before relying on a short label.
Evidence checklist
- Threat messages with timestamps
- Wallet/bank details demanded
- Any images already circulated (store securely; limit further sharing)
Practical next steps
- Stop engaging with the extortionist where safe to do so.
- Preserve evidence and seek urgent legal advice for high-risk cases.
- File an official complaint; consider counsel for sensitive evidence handling.
Related cybercrime topics
Find a cyber crime lawyer
Directory results only include advocates who self-reported Cyber Crime & Online Fraud (or the broader Cyber / Technology Law tag). LawHub never infers specialization from names, bios, or cities.
Sources & provenance
- The Prevention of Electronic Crimes Act, 2016 (Pakistan Code consolidation) — Ministry of Law and Justice, Government of Pakistan (Pakistan Code). National corpus consolidation_date 2025-02-07; source_id pakistancode-peca-2016.
- Prevention of Electronic Crimes (Amendment) Act, 2025 (Act No. II of 2025) — Majlis-e-Shoora (Parliament) / Senate Secretariat gazette publication. Presidential assent and Gazette Extra. publication 29 January 2025; [94(2025)/Ex. Gaz.].
- NCCIA online complaint portal — National Cyber Crime Investigation Agency (complaint.nccia.gov.pk). Host complaint.nccia.gov.pk resolves on the public DNS (Cloudflare). Bot fetches may receive HTTP 403; users should open the official domain in a browser and follow current on-site instructions.