ShinyHunters data leaks fuel $2,000 sextortion email scam

Threat Actors Repurpose Leaked Data for Sextortion Scams, Demanding $2,000 in Bitcoin

A malicious email campaign has been underway since April, with attackers using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. The messages claim to come from ShinyHunters and threaten to share intimate videos with recipients’ friends, family, and colleagues unless they pay up.

The scheme relies on a clever ruse: using details from published leaked data breaches to make the threats appear targeted. The attackers send emails from random email addresses, often using the names “ShinyHunters” or “You’ve Been HACKED”, with subjects like “Information about your online security”. These messages claim that ShinyHunters compromised the recipient’s devices after obtaining their email address from a breached company database.

However, a closer look reveals that these emails are not sent by ShinyHunters themselves. Rather, they’re using leaked data to make the threats appear legitimate. In some cases, BleepingComputer confirmed that the targeted email addresses were indeed included in the associated data previously leaked by ShinyHunters.

The use of repurposed data from previous breaches is a disturbing trend. Extortion gangs often claim that refusing to pay will expose victims’ customers and employees to additional abuse once stolen data is published. While these claims are intended to pressure organizations into paying, this campaign illustrates how leaked data can be used for malicious purposes by unrelated threat actors.

The emails themselves are designed to frighten recipients into paying a demand out of worry that their reputation will be hurt with friends, family, and work colleagues. However, there’s no indication that the sender ever had access to the recipient’s devices or personal activity. Instead, they’re simply using details from published leaks to make the scam appear targeted.

This campaign is not an isolated incident; it’s part of a wider trend of extortion email scams. Scammers have created various types of emails pretending to be everything from hitman contracts to CIA investigations, all designed to extort money from victims. These schemes may seem convincing, but they’re often based on empty threats and can be easily avoided.

So what can you do to protect yourself? First and foremost, remain vigilant when receiving unsolicited emails claiming to have compromising information about you. If an email demands payment in exchange for not releasing sensitive material, it’s likely a scam. Don’t fall for the threats; instead, report the email to your email provider or delete it altogether.

Furthermore, be cautious of emails that use sensational subject lines or claim to have accessed your devices in some way. These are often red flags for malicious activity. If you’re unsure about an email’s legitimacy, trust your instincts and take action.

In conclusion, this campaign highlights the importance of being aware of the risks associated with leaked data breaches. By staying informed and taking steps to protect yourself, you can avoid falling victim to these types of scams. Remember: if it seems too good (or bad) to be true, it probably is.


Source: Bleeping Computer — 2026-07-25