A sextortion email campaign is exploiting data previously leaked by the ShinyHunters extortion group, using breached email addresses to make fraudulent blackmail threats appear credible. The emails demand $2,000 in Bitcoin but do not originate from ShinyHunters itself, according to reporting from BleepingComputer.
The messages claim the sender is ShinyHunters and assert that recipients’ devices were compromised after their email addresses were obtained from breached corporate databases. BleepingComputer confirmed that in at least some cases, the targeted email addresses genuinely appeared in data previously leaked by ShinyHunters, but found no evidence linking the campaign to the group. When contacted, ShinyHunters denied any involvement.
Leaked data referenced in the emails has been tied to breaches at Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill. The emails are sent from throwaway addresses using names like “ShinyHunters” or “You’ve Been HACKED,” with the subject line “Information about your online security.”
False claims of device access
The messages claim attackers installed an “exploit” on the victim’s phone and computer, granting access to the microphone, camera, keyboard, photos, browsing history, conversations, and contact list. Senders then allege they recorded the recipient visiting adult websites and threaten to distribute intimate footage to friends, family, and colleagues unless $2,000 in Bitcoin is paid within 48 hours. Victims are also warned not to contact police, reply, or reset their devices.
There is no evidence the senders ever accessed recipients’ devices, cameras, or personal activity. The scam relies solely on publicly leaked email addresses and breach company names to create a false sense of targeted surveillance.
Campaign traced to April
Reports indicate the campaign began in April, with users and organizations flagging the emails across forums. Betterment confirmed some clients received the threatening messages and publicly stated that possessing an email address does not grant the ability to install malware or access a device. The company advised recipients not to reply, pay, click links, or open attachments, and to report interactions to its fraud team.
Sextortion scams referencing leaked breach data are not new; similar campaigns generated over $50,000 in a single week when they first emerged in 2018. Security professionals note this variation illustrates how previously published breach data can be repurposed by unrelated actors long after the original incident. Recipients are advised to delete such emails without responding or paying.
