
Fake iPhone Crypto Wallet Stole $1.8M
Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…
A sextortion email campaign is using real leaked email addresses from ShinyHunters-related data dumps to make threats sound credible. The scammers impersonate the “ShinyHunters hacking group,” claim they recorded victims via webcam, and demand $2,000 in Bitcoin within 48 hours. Reporting indicates the emails are bluffs with no proof, but the leaked data helps them target and personalize messages at scale.
This campaign is a classic sextortion email dressed up with a topical twist. The messages claim to come from the “ShinyHunters hacking group” and assert that the sender has compromised the recipient's device, recorded them via webcam, and will release the footage unless $2,000 in Bitcoin is paid within 48 hours. What makes this version notable is not technical sophistication, it is the use of email addresses drawn from real leaked data, reportedly tied to breaches and leaks associated with services including Amtrak, Hallmark, ADT, Substack, Betterment, CarGurus, Panera Bread, McGraw Hill, and the Canvas data breach. Pulling from these leaks lets scammers target people at scale while making each message feel personally targeted.
The attack leans entirely on fear and shame rather than technical compromise. The combination of a named, semi-recognizable threat actor, a claim of webcam access, and a tight 48-hour deadline is designed to short-circuit careful thinking. Reporting indicates these are bluffs, a Bitcoin wallet checked in one example showed no activity, but the psychological pressure alone is often enough to prompt a hasty payment from someone who is embarrassed or scared and does not want to ask for help.
The most effective response to this kind of email is inaction paired with reporting: never reply, delete the message, and report it as spam. Slowing down matters more than anything else here, since these scams rely on panic to prevent people from thinking clearly or asking a colleague or helpdesk for a second opinion. Treat any password mentioned in the email as a signal to change that password everywhere it is reused and to enable two-factor authentication. Since these threats source real leaked credentials, awareness programs should also remind employees and students that leaked personal data is often used to add false credibility to unrelated scams, not proof of an actual compromise.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is an email extortion campaign where scammers impersonate the ShinyHunters hacking group, claim to have webcam recordings of the victim, and demand $2,000 in Bitcoin within 48 hours.
They use email addresses pulled from data leaks and breaches associated with services like Amtrak, Hallmark, ADT, Substack, and others to personalize the message and appear to have inside knowledge of the victim.
No. Reporting found the emails are typically bluffs, and a check of the Bitcoin wallet referenced in one example showed no activity.
Do not reply, do not treat any attachment as proof, delete the message and report it as spam, and if it includes a password you have used before, change it immediately and enable two-factor authentication.
You open an email: subject line says, “Information about your online security,” and it claims to be the ShinyHunters hacking group. It says they hacked your Amtrak or Panera or Substack account, recorded you through your webcam, and demands $2,000 in Bitcoin within 48 hours or they’ll expose everything. Here’s the twist: these ShinyHunters sextortion emails are mass-produced bluffs. They use leaked email lists from places like Hallmark, ADT, Betterment, and Canvas, but provide zero real proof, and their Bitcoin wallets often show no activity. If you get one of these, don’t reply, don’t pay, just mark it as spam, and if it shows a real password you’ve used, change that password everywhere and turn on 2FA.

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…

Researchers reported a real phishing campaign targeting Call of Duty Mobile players with a fake “free Call of Duty Points” giveaway site. Victims are tricked…

Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites…

A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to…