A New Wave of Sextortion Emails is Scamming Victims with Leaked Data Breaches
Cybersecurity experts are sounding the alarm about a growing trend of sextortion emails that are tricking victims into sending thousands of dollars in Bitcoin. These malicious messages are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to make threats appear more convincing.
Threat actors are exploiting these exposed email addresses to send targeted sextortion emails, demanding $2,000 from recipients under the guise that their devices have been compromised and intimate videos will be shared with friends, family, and colleagues unless they pay up. The twist? These emails often use legitimate data breaches leaked by ShinyHunters, making it seem like the attackers had access to the victims’ personal info.
In reality, these scammers are using publicly available information to craft convincing messages. They claim to have accessed devices through a compromised email account or installed malware on computers and phones, but there’s no evidence to support this. The goal is to create a sense of urgency and fear in recipients, who may be worried about their reputation being tarnished.
BleepingComputer has confirmed that the email addresses targeted by these sextortion emails were indeed included in the associated data previously leaked by ShinyHunters. This shows how vulnerable organizations can become when faced with large-scale data breaches. Even though the data is publicly available, it’s still a treasure trove for scammers looking to make a quick profit.
The use of email addresses exposed in data breaches has become a common tactic among sextortion scammers. In some cases, recipients have received emails that directly reference their involvement in previous data leaks. This can be distressing and may lead to further emotional manipulation by the attackers.
The ShinyHunters extortion group itself denied any involvement in this latest campaign, but it’s clear that unrelated threat actors are repurposing leaked data for malicious purposes.
For individuals and organizations affected by these breaches, it’s essential to remain vigilant. These types of emails can be distressing, but it’s crucial not to fall prey to the emotional manipulation tactics used by scammers. If you receive a sextortion email, don’t panic – report it to your IT department or cybersecurity team immediately.
To protect yourself from similar scams in the future:
* Be cautious when clicking on links or opening attachments from unknown senders
* Use strong passwords and enable two-factor authentication for all accounts
* Keep software up-to-date and regularly back up important data
* Educate your employees about cybersecurity best practices to prevent phishing and other social engineering attacks
By staying informed and taking proactive steps, you can reduce the risk of falling victim to these types of scams.
Source: Bleeping Computer — 2026-07-25