Find notable cyber news and cases, enriched with sources, timelines, and signals.

ShinyHunters impersonation sextortion email campaign

Campaign
First reported
Last updated
Happening score
H score 17
1 unique sources, 1 articles

Summary

Hide ▲

A sextortion email campaign is using leaked email addresses and ShinyHunters impersonation to demand $2,000 in Bitcoin, broadening abuse of previously exposed breach data. The messages claim device compromise and threaten to release intimate videos, but there is no indication the sender accessed devices, installed malware, or monitored activity. The operation has reused addresses from published leaks tied to Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill. The campaign appears to have begun in April and has generated similar reports across multiple people and organizations.

Timeline

  1. 25.07.2026 17:16 2 articles · 2h ago

    ShinyHunters impersonation sextortion email campaign

    Initial Disclosure

    The first observed phase used leaked breach addresses to send ShinyHunters-branded sextortion emails demanding Bitcoin payments. Early messages referenced published company breaches and pretended the sender had accessed devices several months earlier.

    Show sources