Skip to content
Tech News
← Back to articles

ShinyHunters data leaks fuel $2,000 sextortion email scam

read original more articles
Why This Matters

This article highlights how leaked data from breaches associated with ShinyHunters is being exploited by threat actors to conduct a $2,000 sextortion email scam, emphasizing the ongoing risks of data breaches and their misuse. It underscores the importance for consumers and organizations to monitor leaked information and remain vigilant against evolving cyber threats. The incident illustrates how stolen data can be repurposed for malicious activities, even when the original breach does not involve direct device compromise.

Key Takeaways

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.

The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after obtaining their email addresses from breached company databases.

However, the messages appear to be sent by someone who downloaded data previously leaked by ShinyHunters rather than by the extortion group itself, using the exposed email addresses to make the threats appear more legitimate.

BleepingComputer has seen leaked data from the Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill breaches used in this sextortion email campaign.

For some recipients, BleepingComputer confirmed that the email addresses targeted by the sextortion emails were actually included in the associated data previously leaked by ShinyHunters.

Extortion gangs often warn victims that refusing to pay will expose their customers and employees to additional abuse once stolen data is published. While those claims are intended to pressure organizations into paying, this campaign illustrates how leaked data can later be repurposed by unrelated threat actors for malicious purposes.

While the use of a recipient's leaked email address may make these emails appear more convincing, there is no indication that the sender compromised recipients' devices, installed malware, accessed their cameras, or monitored their activity on adult websites.

BleepingComputer contacted the ShinyHunters extortion group, which denied any involvement in the sextortion email campaign.

Fake ShinyHunters sextortion emails

In the emails seen by BleepingComputer, they are sent from random email addresses using the names "ShinyHunters" or "You've Been HACKED" and have the subject "Information about your online security."

... continue reading