Fake ShinyHunters Sextortion Demands $2,000

Malwarebytes · Low sophistication
Last updated July 30, 2026

A sextortion email campaign is using real leaked email addresses from ShinyHunters-related data dumps to make threats sound credible. The scammers impersonate the “ShinyHunters hacking group,” claim they recorded victims via webcam, and demand $2,000 in Bitcoin within 48 hours. Reporting indicates the emails are bluffs with no proof, but the leaked data helps them target and personalize messages at scale.

How the attack worked

This campaign is a classic sextortion email dressed up with a topical twist. The messages claim to come from the “ShinyHunters hacking group” and assert that the sender has compromised the recipient's device, recorded them via webcam, and will release the footage unless $2,000 in Bitcoin is paid within 48 hours. What makes this version notable is not technical sophistication, it is the use of email addresses drawn from real leaked data, reportedly tied to breaches and leaks associated with services including Amtrak, Hallmark, ADT, Substack, Betterment, CarGurus, Panera Bread, McGraw Hill, and the Canvas data breach. Pulling from these leaks lets scammers target people at scale while making each message feel personally targeted.

Why it succeeded

The attack leans entirely on fear and shame rather than technical compromise. The combination of a named, semi-recognizable threat actor, a claim of webcam access, and a tight 48-hour deadline is designed to short-circuit careful thinking. Reporting indicates these are bluffs, a Bitcoin wallet checked in one example showed no activity, but the psychological pressure alone is often enough to prompt a hasty payment from someone who is embarrassed or scared and does not want to ask for help.

What to watch for

  • Emails that open with generic security language, such as a subject like "Information about your online security"
  • Claims of sweeping access to your device or webcam paired with vague promises like removing malware in exchange for payment
  • Urgent countdowns, such as a fixed 48-hour deadline, meant to prevent verification
  • Attachments presented as "proof," which may instead be used to deliver malware or simply make the threat look more convincing
  • Any mention of a password you recognize, which likely came from an old breach rather than active access to your accounts

How to build resistance

The most effective response to this kind of email is inaction paired with reporting: never reply, delete the message, and report it as spam. Slowing down matters more than anything else here, since these scams rely on panic to prevent people from thinking clearly or asking a colleague or helpdesk for a second opinion. Treat any password mentioned in the email as a signal to change that password everywhere it is reused and to enable two-factor authentication. Since these threats source real leaked credentials, awareness programs should also remind employees and students that leaked personal data is often used to add false credibility to unrelated scams, not proof of an actual compromise.

Key findings

  • Scammers are using email addresses found in data leaked by the ShinyHunters hacking group to target victims and add credibility to sextortion threats.
  • The emails impersonate “ShinyHunters,” claim access to victims’ devices and webcam recordings, and demand $2,000 in Bitcoin with a 48-hour deadline.
  • BleepingComputer reported targeted addresses came from breaches/leaks associated with services including Amtrak, Hallmark, ADT, Substack, Betterment, CarGurus, Panera Bread, and McGraw Hill, plus victims of the Canvas data breach.
  • The article notes these sextortion emails are typically bluffs and that a check of the Bitcoin address in the example showed “no activity.”

Who’s being targeted

  • Commonly targeted roles: All employees, Finance teams (payment/extortion escalation awareness), IT/Helpdesk (user reporting and guidance), Students/Faculty/Staff in education environments.
  • Affected industries: Transportation (rail), Retail/Consumer services, Security & alarm monitoring, Online publishing/newsletters, Finance/Investing, Automotive marketplaces, Food service/restaurants, Education (colleges/universities), Publishing/Education content.
  • Attack channels: email.
  • Impersonated: ShinyHunters hacking group.

Red flags to watch for

  • Uses fear and shame (porn/webcam recording) to pressure quick payment
  • Urgent deadline: “You have 48 hours”
  • Claims sweeping access and “we’ll remove the malware” but provides no real proof
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the fake ShinyHunters sextortion scam?

It is an email extortion campaign where scammers impersonate the ShinyHunters hacking group, claim to have webcam recordings of the victim, and demand $2,000 in Bitcoin within 48 hours.

How do the scammers make the threats seem credible?

They use email addresses pulled from data leaks and breaches associated with services like Amtrak, Hallmark, ADT, Substack, and others to personalize the message and appear to have inside knowledge of the victim.

Is there real proof behind these sextortion emails?

No. Reporting found the emails are typically bluffs, and a check of the Bitcoin wallet referenced in one example showed no activity.

What should someone do if they receive one of these emails?

Do not reply, do not treat any attachment as proof, delete the message and report it as spam, and if it includes a password you have used before, change it immediately and enable two-factor authentication.

Read the video transcript

You open an email: subject line says, “Information about your online security,” and it claims to be the ShinyHunters hacking group. It says they hacked your Amtrak or Panera or Substack account, recorded you through your webcam, and demands $2,000 in Bitcoin within 48 hours or they’ll expose everything. Here’s the twist: these ShinyHunters sextortion emails are mass-produced bluffs. They use leaked email lists from places like Hallmark, ADT, Betterment, and Canvas, but provide zero real proof, and their Bitcoin wallets often show no activity. If you get one of these, don’t reply, don’t pay, just mark it as spam, and if it shows a real password you’ve used, change that password everywhere and turn on 2FA.

Similar attacks

Fake iPhone Crypto Wallet Stole $1.8M

Fake iPhone Crypto Wallet Stole $1.8M

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…

July 29, 2026
QR-Code PDFs Steal Microsoft 365 Logins

QR-Code PDFs Steal Microsoft 365 Logins

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

July 28, 2026