A new sextortion email campaign is targeting individuals whose email addresses were exposed in data breaches leaked by the ShinyHunters extortion group. The emails demand $2,000 in Bitcoin, falsely claiming that the recipients' devices were compromised after their email addresses were obtained from breached company databases.
The emails are sent from random addresses, often using names like "ShinyHunters" or "You've Been HACKED," and carry the subject "Information about your online security." While the messages claim to originate from the ShinyHunters hacking group, evidence suggests they are sent by unrelated actors who downloaded and repurposed the leaked data to make their threats seem more credible. The actual ShinyHunters group has denied involvement in this sextortion campaign.
BleepingComputer confirmed that email addresses targeted in this campaign were included in data previously leaked by ShinyHunters from companies such as Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill. The emails specifically name one of these companies, claiming that access to its database allowed the attackers to obtain the recipient's email account.
Despite the convincing appearance due to the use of leaked email addresses, there is no indication that the senders have compromised recipients' devices, installed malware, accessed cameras, or monitored online activity. The campaign illustrates how data leaked by one threat actor can be subsequently exploited by others for different malicious purposes, even if the initial claims of device compromise are false.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters group to send sextortion emails demanding $2,000 in Bitcoin. These emails falsely claim to be from ShinyHunters and allege device compromise, leveraging previously leaked data to appear legitimate.