ShinyHunters impersonation sextortion email campaign
Campaign
Summary
Hide ▲
Show ▼
A sextortion email campaign is using leaked email addresses and ShinyHunters impersonation to demand $2,000 in Bitcoin, broadening abuse of previously exposed breach data. The messages claim device compromise and threaten to release intimate videos, but there is no indication the sender accessed devices, installed malware, or monitored activity. The operation has reused addresses from published leaks tied to Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill. The campaign appears to have begun in April and has generated similar reports across multiple people and organizations.
Timeline
-
25.07.2026 17:16 2 articles · 2h ago
ShinyHunters impersonation sextortion email campaign
Initial DisclosureThe first observed phase used leaked breach addresses to send ShinyHunters-branded sextortion emails demanding Bitcoin payments. Early messages referenced published company breaches and pretended the sender had accessed devices several months earlier.
Show sources
- ShinyHunters data leaks fuel $2,000 sextortion email scam — www.bleepingcomputer.com — 25.07.2026 17:16
- ShinyHunters data leaks fuel $2,000 sextortion email scam — www.bleepingcomputer.com — 25.07.2026 17:16