Back to Feed
Threat IntelligenceJul 25, 2026

ShinyHunters data leaks fuel $2,000 sextortion email scam

Scammers use ShinyHunters data leaks to send $2,000 sextortion emails.

Summary

Threat actors are leveraging email addresses from data breaches previously leaked by the ShinyHunters extortion group to conduct a sextortion scam. These emails, falsely claiming to be from ShinyHunters, demand $2,000 in Bitcoin, threatening to release compromising information. While the emails use legitimate leaked data to appear more convincing, there is no evidence that the senders actually compromised the recipients' devices or activities.

Full text

ShinyHunters data leaks fuel $2,000 sextortion email scam By Lawrence Abrams July 25, 2026 10:16 AM 0 Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after obtaining their email addresses from breached company databases. However, the messages appear to be sent by someone who downloaded data previously leaked by ShinyHunters rather than by the extortion group itself, using the exposed email addresses to make the threats appear more legitimate. BleepingComputer has seen leaked data from the Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill breaches used in this sextortion email campaign. For some recipients, BleepingComputer confirmed that the email addresses targeted by the sextortion emails were actually included in the associated data previously leaked by ShinyHunters. Extortion gangs often warn victims that refusing to pay will expose their customers and employees to additional abuse once stolen data is published. While those claims are intended to pressure organizations into paying, this campaign illustrates how leaked data can later be repurposed by unrelated threat actors for malicious purposes. While the use of a recipient's leaked email address may make these emails appear more convincing, there is no indication that the sender compromised recipients' devices, installed malware, accessed their cameras, or monitored their activity on adult websites. BleepingComputer contacted the ShinyHunters extortion group, which denied any involvement in the sextortion email campaign. Fake ShinyHunters sextortion emails In the emails seen by BleepingComputer, they are sent from random email addresses using the names "ShinyHunters" or "You've Been HACKED" and have the subject "Information about your online security." The messages claim to be from the ShinyHunters hacking group and state that the attackers gained access to the recipient's devices several months earlier. The sender then names a company whose data was previously published by ShinyHunters, claiming that the breach allowed them to access the recipient's email account. We are the ShinyHunters hacking group. A few months ago, we gained access to your devices and started monitoring your online activities. What happened: We gained access to the Cargurus.com database where you have an account and easily accessed your email. You weren't very careful about the links you opened. A week later, we installed an exploit on your devices, including your phone, giving us access to your microphone, camera, keyboard, and all your data. We have your photos, browsing history, conversations, and contact list. Sextortion email claiming to be from the ShinyHunters extortion groupSource: BleepingComputer The email falsely claims that the attackers later "installed an exploit" on the victim's computers and phones, allowing them to access the microphone, camera, keyboard, photos, browsing history, conversations, and contact list. The sender then claims to have recorded the recipient visiting adult websites and threatens to share intimate videos with their friends, colleagues, and family. To prevent the alleged release of these compromising videos, the victim is told to send $2,000 in Bitcoin within 48 hours. The email also warns recipients not to contact police, reply to the message, or reset their devices, claiming that the stolen information is stored on remote servers. These types of emails are known as "sextortion" emails and are designed to frighten recipients into paying a demand out of worry that they will have their reputation hurt with friends, family, and work colleagues. However, there is nothing to indicate that the sender ever had access to the recipients' devices or personal activity. Instead, the attackers use details from published leaked data breaches, such as an email address and the name of the breached company, to make a sextortion scam appear targeted. While you may think that no one would fall for these scams, they were very profitable when they first appeared in 2018, generating over $50,000 in a week. Since then, scammers have created a wide variety of extortion email scams, including ones that pretend to be hitman contracts, information about cheating spouses, bomb threats, CIA investigations, and threats of installing ransomware. Campaign started in April The sextortion campaign appears to have started in April, with numerous people and organizations reporting similar messages or warning recipients to ignore them. One person who received an email referencing the Betterment breach posted about it on the Betterment Reddit. Betterment responded that it was aware some clients had received threatening emails claiming to come from a hacking group. "These messages are part of a common extortion scam designed to intimidate recipients," Betterment said. "Please note, knowing an email address does not provide the ability to install malware or access someone's device." The company advised recipients not to reply, send payment, click links, or open attachments and to delete the email. Betterment also asked customers who had interacted with the message to contact its fraud team. Although their email address may have appeared in one of the published data leaks referenced in the email, this does not mean the sender compromised their devices, recorded videos, or obtained any of the other information described in the message. Recipients of these messages should not pay the ransom or respond to the sender. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: NAIC says public data stolen in ShinyHunters' PeopleSoft breach7-Eleven confirms data breach claimed by the ShinyHunters gangAbbott probes two cyber incidents amid extortion claimsKodak confirms data breach claimed by ShinyHunters extortion gangNottingham University data breach affects over 450,000 students

Indicators of Compromise

  • malware — ShinyHunters

Entities

ShinyHunters (threat_actor)Bitcoin (product)