Skip to main content
Emerging ThreatsMalware & Ransomware

ShinyHunters data leaks fuel sextortion scam targeting breach victims

Person sits at dimly lit desk, looking concerned at laptop screen with blurred email inbox.
“We are the ShinyHunters hacking group,” a message seen by BleepingComputer declares — a line used to lend credibility to an extortion pitch that, in reality, appears to be the work of copycats mining previously leaked datasets.

ShinyHunters-branded sextortion emails

Since April, threat actors have circulated sextortion emails that claim to come from the ShinyHunters extortion group. The messages are sent from random email addresses but use display names such as "ShinyHunters" or "You've Been HACKED" and carry the subject line "Information about your online security."

Those emails allege the attackers gained long-standing access to recipients' devices, installed an “exploit” that granted use of microphones, cameras and keyboards, and recorded victims visiting adult websites. Recipients are threatened with exposure of alleged intimate videos unless they pay $2,000 in Bitcoin within 48 hours. The messages further warn recipients not to contact police, not to reply, and not to reset their devices, claiming the stolen data is stored on remote servers.

Leaked datasets repurposed: Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, McGraw Hill

BleepingComputer reviewed the campaign and found the attackers are reusing email addresses and breach details previously published by the ShinyHunters extortion group. Leaked data from Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill were used to craft the messages.

For some recipients, BleepingComputer confirmed the email addresses targeted by the sextortion emails were actually included in the associated ShinyHunters-published data. That connection is the likely source of the scammers' ability to make demands look targeted without having to compromise devices directly.

Tactics and the $2,000 Bitcoin demand

The campaign's core technique is social engineering built on plausibility: take an exposed email address and the name of a breached company, then allege a device compromise that permitted blackmail. There is no indication in BleepingComputer’s reporting that the senders installed malware, accessed cameras, or monitored activity on adult sites; the exposed email address is used to create urgency and fear.

These sextortion messages are part of a wider family of extortion scams that resurfaced in profitably in 2018 — generating over $50,000 in a single week at that time — and have since evolved into many variants, including fabricated hitman contracts, false bomb threats, and bogus intelligence-agency investigations. The present campaign demands $2,000 in Bitcoin and gives a 48-hour deadline to pressure victims into payment.

Betterment's guidance and ShinyHunters' denial

Individuals and organizations reported receiving the messages to multiple forums and vendors. One recipient who posted on the Betterment Reddit prompted a company response. Betterment told customers it was aware of threatening emails that claimed to come from a hacking group and advised recipients to ignore them. "These messages are part of a common extortion scam designed to intimidate recipients," Betterment said. "Please note, knowing an email address does not provide the ability to install malware or access someone's device."

BleepingComputer also contacted the ShinyHunters extortion group; the group denied any involvement in the sextortion email campaign, indicating the emails come from actors repurposing previously published breach data.

How technologists and security teams, affected enterprises, and end users are responding

  • Technologists and security teams: The campaign highlights how publicly leaked records can be repackaged into secondary scams. Teams should note that published email addresses may show up in fraud attempts long after a breach is disclosed, even when no additional technical compromise has occurred.
  • Affected enterprises and procurement leaders: Companies whose customer data was published — including those named in the campaign — face follow-on reputational risk as unrelated actors reuse leaked records to target customers. Betterment advised customers to delete the messages and asked anyone who interacted with the email to contact its fraud team.
  • End users and the general public: Recipients of these messages should not pay the ransom or respond to the sender. The campaign’s apparent reliance on leaked email addresses rather than device compromise means the most damaging element is fear; the messages are designed to intimidate and extract payment, not to support their technical claims.

This episode underlines a simple but consequential point: when data from a breach is published, it becomes raw material for many actors. Even if an extortion group publishes a trove of emails for leverage against a company, unrelated scammers can later repurpose that same data to conduct sextortion, phishing, or other fraud. The one confirmed thread running through BleepingComputer’s reporting is reuse — not fresh, remote device exploits — as the mechanism that makes these threats appear authentic.

Read the original BleepingComputer reporting: ShinyHunters data leaks fuel $2,000 sextortion email scam