A new ShinyHunters sextortion scam is using email addresses from previously leaked company databases to make false threats appear convincing. The emails demand $2,000 in Bitcoin and claim that hackers have recorded recipients through their devices.
However, there is no evidence that the scammers accessed victims’ phones, computers, cameras or personal accounts. Instead, they appear to be using exposed email addresses and breach details to create a more believable extortion attempt.
Scammers use data from published breaches
The campaign has targeted email addresses connected to data breaches involving Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread and McGraw Hill.
In some cases, the recipient’s email address was genuinely present in data previously published by ShinyHunters. That fact may make the threat seem more personal. However, it does not mean that the sender hacked the recipient’s device.
The group has denied taking part in the email campaign. This suggests that unrelated criminals downloaded leaked data and repurposed it for their own scam.
Fake ShinyHunters emails claim device access
The messages are sent from random email addresses. They may use names such as “ShinyHunters” or “You’ve Been HACKED” and often include a subject line about online security.
Each email names a company linked to a previous breach. The sender then claims that access to the company’s database gave them control over the recipient’s email account and devices.
The scammers falsely say they installed an exploit on the victim’s phone and computer. They claim to have access to the camera, microphone, keyboard, photos, browsing history, conversations and contact list.
Next, the email states that the recipient visited adult websites and was secretly recorded. It threatens to share supposed videos with family, friends and colleagues.
Victims are told to pay $2,000 in Bitcoin
To stop the alleged videos from being released, recipients are told to send $2,000 in Bitcoin within 48 hours.
The email also warns people not to contact the police, reply to the message or reset their devices. It claims that stolen information is already stored on remote servers.
These claims are designed to cause fear and force a quick payment. Yet the scammers provide no evidence that they have access to the recipient’s devices or private activity.
Why the ShinyHunters sextortion scam looks convincing
Sextortion emails often rely on alarming language rather than real proof. In this case, the use of an actual email address and a real breached company adds credibility to a fabricated story.
Data leaks can expose information that criminals later reuse in unrelated attacks. Extortion groups often warn organisations that published data could lead to more abuse for customers and employees. This campaign shows how that risk can become real, even when the original extortion group is not behind the follow-up scam.
Still, an exposed email address does not give anyone the ability to install malware, activate a camera or monitor online activity.
What to do if you receive the email
Do not pay the Bitcoin demand or contact the sender. Do not click links, download attachments or provide any personal information.
Mark the email as spam and delete it. If you use the same password on several websites, change it immediately and enable two-factor authentication wherever possible.
The ShinyHunters sextortion scam may use real breach information, but the threats of hacked devices and recorded videos are false.


0 responses to “ShinyHunters Sextortion Scam Uses Leaked Emails for Bitcoin Threats”