Earlier quoted context omitted.
1) Send the SHA1 hash of a message in which you detail what you're going to do (locations, time, etc.). 2) Do whatever you're planning to do. 3) Transmit another message to the company you're blackmailing in which you reveal the message that matches the original SHA1 hash.
Ok, but why use a broken hash algorithm?
Because you're not actually trying to encrypt anything.