ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after o…
Intelligence analysis by Llama

ShinyHunters data leaks are being used to send sextortion emails demanding $2,000 in Bitcoin. The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after obtaining their email addresses from breached company databases.
Imagine you got an email saying that someone hacked into your computer and recorded you doing something private. They're threatening to share it with your friends and family unless you pay them $2,000 in Bitcoin. But the thing is, there's no proof that they actually hacked into your computer or recorded anything. They're just using information from a data breach to make the email look more convincing.
Analysis
A $2,000 Sextortion Scam Fuelled by ShinyHunters Data Leaks
The recent surge in sextortion emails demanding $2,000 in Bitcoin has been linked to the use of email addresses exposed in data breaches leaked by the ShinyHunters extortion group. These emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after obtaining their email addresses from breached company databases.
However, the messages appear to be sent by someone who downloaded data previously leaked by ShinyHunters rather than by the extortion group itself, using the exposed email addresses to make the threats appear more legitimate. BleepingComputer has seen leaked data from the Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill breaches used in this sextortion email campaign.
For some recipients, BleepingComputer confirmed that the email addresses targeted by the sextortion emails were actually included in the associated data previously leaked by ShinyHunters. Extortion gangs often warn victims that refusing to pay will expose their customers and employees to additional abuse once stolen data is published. While those claims are intended to pressure organizations into paying, this campaign illustrates how leaked data can later be repurposed by unrelated threat actors for malicious purposes.
While the use of a recipient's leaked email address may make these emails appear more convincing, there is no indication that the sender compromised recipients' devices, installed malware, accessed their cameras, or monitored their activity on adult websites. BleepingComputer contacted the ShinyHunters extortion group, which denied any involvement in the sextortion email campaign.
Fake ShinyHunters Sextortion Emails
The emails seen by BleepingComputer are sent from random email addresses using the names 'ShinyHunters' or 'You've Been HACKED' and have the subject 'Information about your online security.' The messages claim to be from the ShinyHunters hacking group and state that the attackers gained access to the recipient's devices several months earlier.
The sender then names a company whose data was previously published by ShinyHunters, claiming that the breach allowed them to access the recipient's email account. We are the ShinyHunters hacking group. A few months ago, we gained access to your devices and started monitoring your online activities. What happened: We gained access to the Cargurus.com database where you have an account and easily accessed your email. You weren't very careful about the links you opened. A week later, we installed an exploit on your devices, including your phone, giving us access to your microphone, camera, keyboard, and all your data. We have your photos, browsing history, conversations, and contact list.
The email falsely claims that the attackers later 'installed an exploit' on the victim's computers and phones, allowing them to access the microphone, camera, keyboard, photos, browsing history, conversations, and contact list. The sender then claims to have recorded the recipient visiting adult websites and threatens to share intimate videos with their friends, colleagues, and family. To prevent the alleged release of these compromising videos, the victim is told to send $2,000 in Bitcoin within 48 hours.
A Campaign That Started in April
The sextortion campaign appears to have started in April, with numerous people and organizations reporting similar messages or warning recipients to ignore them. One person who received an email referencing the Betterment breach posted about it on the Betterment Reddit. Betterment responded that it was aware some clients had received threatening emails claiming to come from a hacking group.
These messages are part of a common extortion scam designed to intimidate recipients,' Betterment said. 'Please note, knowing an email address does not provide the ability to install malware or access someone's device.' The company advised recipients not to reply, send payment, click links, or open attachments and to delete the email. Betterment also asked customers who had interacted with the message to contact its fraud team.
Although their email address may have appeared in one of the published data leaks referenced in the email, this does not mean the sender compromised their devices, recorded videos, or obtained any of the other information described in the message. Recipients of these messages should not pay the ransom or respond to the sender.
Key points
- Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.
- The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after obtaining their email addresses from breached company databases.
- There is no indication that the sender compromised recipients' devices, installed malware, accessed their cameras, or monitored their activity on adult websites.
- The campaign appears to have started in April, with numerous people and organizations reporting similar messages or warning recipients to ignore them.
If this development plays out positively, it could lead to increased awareness and education among the public about the risks of data breaches and the importance of protecting personal information. This could also lead to more effective measures being taken to prevent and respond to data breaches, ultimately reducing the impact of these types of scams.
If this development plays out negatively, it could lead to a surge in sextortion emails and other types of scams, causing significant financial and emotional harm to individuals and organizations. It could also lead to a decrease in trust in online services and a decrease in the effectiveness of measures to prevent and respond to data breaches.



