A sextortion email campaign is using real email addresses exposed in prior ShinyHunters-linked data breaches to make fraudulent threats appear credible and demand $2,000 in Bitcoin. The messages claim the sender compromised victims’ devices, installed malware, accessed cameras and microphones, and recorded visits to adult websites, then threaten to release supposed footage unless payment is made within 48 hours. Reporting found no evidence that the scammers had actual access to recipients’ devices or accounts.
The campaign appears to be run by actors impersonating ShinyHunters, not by the extortion group itself, and relies on previously leaked data from breaches affecting organizations including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill. Some targeted addresses were confirmed to match leaked datasets, reinforcing the scam’s plausibility, while affected organizations such as Betterment warned customers that the messages are a common extortion attempt and advised recipients not to pay or respond.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Organizations affected by the earlier data leaks, including Betterment, issued warnings about the emails and described them as a common extortion scam. The warnings followed use of leaked addresses from breaches affecting firms such as Amtrak, Hallmark, Substack, and Betterment.
ShinyHunters denied involvement in the sextortion campaign and suggested unrelated actors were reusing previously leaked breach data. Reporting found no evidence that the senders had actually installed malware or accessed victims' cameras or microphones.
A sextortion campaign began in April using email addresses exposed in prior ShinyHunters-linked breaches to make fraudulent threats appear credible and demand $2,000 in Bitcoin. The emails falsely claimed recipients' devices were compromised and that compromising recordings would be released unless payment was made.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.