410/69 Monday, July 27, 2026

Reports indicate that threat actors are using email addresses previously exposed in data breaches and published by the extortion group ShinyHunters to send sextortion scam emails demanding USD 2,000 in Bitcoin. The emails claim to be from ShinyHunters and state that the attackers have accessed the recipient’s device after obtaining the email address from a breached company database. However, based on initial analysis, these messages do not appear to have been sent directly by ShinyHunters. Instead, the attackers appear to be reusing data previously published by ShinyHunters to make the threats appear more credible.
BleepingComputer reported that leaked data from several incidents, including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill, has been used in this email scam campaign. In some cases, it was confirmed that the recipient’s email address had appeared in leaked datasets. The senders used display names such as “ShinyHunters” or “You’ve Been HACKED” with the subject line “Information about your online security.” The messages claimed that an exploit had been installed on the victim’s device and that the attackers had access to the camera, microphone, keyboard, photos, browsing history, and contact list. The emails then threatened to release private information unless payment was made within 48 hours. However, there is no evidence that the senders were able to access recipients’ devices, install malware, or record private activity.
This type of campaign shows that data leaked from breaches can later be reused by other threat actors for scams or extortion attempts. Although references to an email address or a company previously affected by a breach may make the message appear targeted, they do not mean that the recipient’s device has actually been compromised. Recipients of such emails should not pay, reply, click links, or open attachments. They should delete the email and report it to the security team or relevant internal team if it involves an organizational account. Betterment, whose customers were among those targeted by these emails, clarified that this is a common extortion scam and that knowing an email address alone does not allow attackers to install malware or access a user’s device.
