A wave of threatening email campaigns is using intimidation and recycled data to pressure recipients into paying attackers. One campaign sent sextortion emails demanding $2,000 in Bitcoin, falsely claiming the sender had hacked victims’ devices, activated cameras and microphones, and recorded visits to adult websites. Reporting indicates the messages relied on email addresses exposed in earlier ShinyHunters-linked data leaks, with criminals referencing companies associated with the recipient’s address to make the threats appear credible. Betterment said some customers received the emails and emphasized that possession of an email address alone does not give an attacker access to a device.
A separate warning from CERT Bulgaria described a campaign of threatening emails about allegedly planted explosive devices, underscoring a broader pattern of coercive messaging designed to trigger fear rather than reflecting confirmed compromise. Together, the incidents show how threat actors are repurposing previously leaked personal data and high-pressure hoax narratives to drive extortion and social engineering, while security authorities and affected organizations stress that recipients should treat the claims as fraudulent unless independent evidence shows an actual intrusion.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
CERT Bulgaria published a warning about a campaign involving threatening email messages. The reference indicates official awareness and public warning activity around the scam campaign.
A sextortion scam campaign began using email addresses exposed in prior ShinyHunters-related data leaks to send threatening emails demanding $2,000 in Bitcoin. The messages falsely claimed victims' devices were compromised and that intimate recordings would be released unless payment was made.
Betterment acknowledged that some of its customers received the threatening emails and said the messages were a common extortion scam. The company stated that knowing an email address alone does not let criminals install malware or access a device.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcegovcert.bg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.