Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Malicious sites use JavaScript to build malware in browser memory

    July 25, 2026

    Ethereum ETFs End 5-Day Inflow Streak With $70.6M Outflows

    July 25, 2026

    A single dose reversed autism-like symptoms in adult mice within hours

    July 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Malicious sites use JavaScript to build malware in browser memory
    • Ethereum ETFs End 5-Day Inflow Streak With $70.6M Outflows
    • A single dose reversed autism-like symptoms in adult mice within hours
    • Trump takes swipes at press during White House Correspondents’ Dinner
    • They Gave MAGA a Safe Haven. Now They’re in Retreat.
    • Wealthy gen Xers stand in the way of a Burnham tax on the super-rich | Phillip Inman
    • From Celebration to Escalation: How Trump’s Iran Cease-Fire Collapsed
    • Cricut Explore 5 vs. Siser Romeo: Choosing the Right Smart Cutting Machine (2026)
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, July 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ShinyHunters data leaks fuel $2,000 sextortion email scam

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 25, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.

    The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after obtaining their email addresses from breached company databases.

    However, the messages appear to be sent by someone who downloaded data previously leaked by ShinyHunters rather than by the extortion group itself, using the exposed email addresses to make the threats appear more legitimate.

    image

    BleepingComputer has seen leaked data from the Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill breaches used in this sextortion email campaign.

    For some recipients, BleepingComputer confirmed that the email addresses targeted by the sextortion emails were actually included in the associated data previously leaked by ShinyHunters.

    Extortion gangs often warn victims that refusing to pay will expose their customers and employees to additional abuse once stolen data is published. While those claims are intended to pressure organizations into paying, this campaign illustrates how leaked data can later be repurposed by unrelated threat actors for malicious purposes.

    While the use of a recipient’s leaked email address may make these emails appear more convincing, there is no indication that the sender compromised recipients’ devices, installed malware, accessed their cameras, or monitored their activity on adult websites.

    BleepingComputer contacted the ShinyHunters extortion group, which denied any involvement in the sextortion email campaign.

    Fake ShinyHunters sextortion emails

    In the emails seen by BleepingComputer, they are sent from random email addresses using the names “ShinyHunters” or “You’ve Been HACKED” and have the subject “Information about your online security.”

    The messages claim to be from the ShinyHunters hacking group and state that the attackers gained access to the recipient’s devices several months earlier.

    The sender then names a company whose data was previously published by ShinyHunters, claiming that the breach allowed them to access the recipient’s email account.

    We are the ShinyHunters hacking group.

    A few months ago, we gained access to your devices and started monitoring your online activities.

    What happened:

    We gained access to the Cargurus.com database where you have an account and easily accessed your email.

    You weren’t very careful about the links you opened.

    A week later, we installed an exploit on your devices, including your phone, giving us access to your microphone, camera, keyboard, and all your data.

    We have your photos, browsing history, conversations, and contact list.

    Sextortion email claiming to be from the ShinyHunters extortion group
    Sextortion email claiming to be from the ShinyHunters extortion group
    Source: BleepingComputer

    The email falsely claims that the attackers later “installed an exploit” on the victim’s computers and phones, allowing them to access the microphone, camera, keyboard, photos, browsing history, conversations, and contact list.

    The sender then claims to have recorded the recipient visiting adult websites and threatens to share intimate videos with their friends, colleagues, and family.

    To prevent the alleged release of these compromising videos, the victim is told to send $2,000 in Bitcoin within 48 hours.

    The email also warns recipients not to contact police, reply to the message, or reset their devices, claiming that the stolen information is stored on remote servers.

    These types of emails are known as “sextortion” emails and are designed to frighten recipients into paying a demand out of worry that they will have their reputation hurt with friends, family, and work colleagues.

    However, there is nothing to indicate that the sender ever had access to the recipients’ devices or personal activity.

    Instead, the attackers use details from published leaked data breaches, such as an email address and the name of the breached company, to make a sextortion scam appear targeted.

    While you may think that no one would fall for these scams, they were very profitable when they first appeared in 2018, generating over $50,000 in a week.

    Since then, scammers have created a wide variety of extortion email scams, including ones that pretend to be hitman contracts, information about cheating spouses, bomb threats, CIA investigations, and threats of installing ransomware.

    Campaign started in April

    The sextortion campaign appears to have started in April, with numerous people and organizations reporting similar messages or warning recipients to ignore them.

    One person who received an email referencing the Betterment breach posted about it on the Betterment Reddit.

    Betterment responded that it was aware some clients had received threatening emails claiming to come from a hacking group.

    “These messages are part of a common extortion scam designed to intimidate recipients,” Betterment said.

    “Please note, knowing an email address does not provide the ability to install malware or access someone’s device.”

    The company advised recipients not to reply, send payment, click links, or open attachments and to delete the email. Betterment also asked customers who had interacted with the message to contact its fraud team.

    Although their email address may have appeared in one of the published data leaks referenced in the email, this does not mean the sender compromised their devices, recorded videos, or obtained any of the other information described in the message.

    Recipients of these messages should not pay the ransom or respond to the sender.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    data email fuel leaks scam sextortion ShinyHunters
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Malicious sites use JavaScript to build malware in browser memory

    Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

    One fallen power line exposed a growing AI data center problem. Here’s how to fix it.

    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

    CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

    Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Malicious sites use JavaScript to build malware in browser memory

    July 25, 2026

    Ethereum ETFs End 5-Day Inflow Streak With $70.6M Outflows

    July 25, 2026

    A single dose reversed autism-like symptoms in adult mice within hours

    July 25, 2026

    Trump takes swipes at press during White House Correspondents’ Dinner

    July 25, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Malicious sites use JavaScript to build malware in browser memory

    July 25, 2026

    Ethereum ETFs End 5-Day Inflow Streak With $70.6M Outflows

    July 25, 2026

    A single dose reversed autism-like symptoms in adult mice within hours

    July 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.