← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

ShinyHunters data leaks exploited in $2,000 Bitcoin sextortion email scam

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Sextortion emails demand $2,000 in Bitcoin.
  • Emails use addresses from ShinyHunters data leaks.
  • Scammers impersonate ShinyHunters group.
  • No evidence of device compromise by scammers.

Sextortion Campaign Leverages Leaked Data

A new sextortion email campaign is targeting individuals whose email addresses were exposed in data breaches leaked by the ShinyHunters extortion group. The emails demand $2,000 in Bitcoin, falsely claiming that the recipients' devices were compromised after their email addresses were obtained from breached company databases.

Impersonation of ShinyHunters

The emails are sent from random addresses, often using names like "ShinyHunters" or "You've Been HACKED," and carry the subject "Information about your online security." While the messages claim to originate from the ShinyHunters hacking group, evidence suggests they are sent by unrelated actors who downloaded and repurposed the leaked data to make their threats seem more credible. The actual ShinyHunters group has denied involvement in this sextortion campaign.

Specific Breaches Cited

BleepingComputer confirmed that email addresses targeted in this campaign were included in data previously leaked by ShinyHunters from companies such as Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill. The emails specifically name one of these companies, claiming that access to its database allowed the attackers to obtain the recipient's email account.

Lack of Device Compromise

Despite the convincing appearance due to the use of leaked email addresses, there is no indication that the senders have compromised recipients' devices, installed malware, accessed cameras, or monitored online activity. The campaign illustrates how data leaked by one threat actor can be subsequently exploited by others for different malicious purposes, even if the initial claims of device compromise are false.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~12 min · 11 stories · Jul 25

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters group to send sextortion emails demanding $2,000 in Bitcoin. These emails falsely claim to be from ShinyHunters and allege device compromise, leveraging previously leaked data to appear legitimate.