Cybercriminals are exploiting email addresses exposed in data breaches linked to the ShinyHunters hacking group to make sextortion emails appear more credible.
The campaign uses stolen personal details and references to known breaches to pressure recipients into paying $2,000\$2{,}000$2,000 in Bitcoin.
Sextortion scams are not new. Attackers typically claim they hacked a victim’s device and recorded them through a webcam. At the same time, they claim the victim visited adult websites.
They will send the alleged footage to friends, family, or colleagues unless a ransom is paid. These messages are designed to trigger fear, shame, and urgency.
In the latest campaign, scammers identify themselves as ShinyHunters and tell recipients that they accessed their email address through a breached online service.

They then claim they installed malware on the victim’s devices and gained access to cameras, microphones, keyboards, photos, browsing history, messages, and contact lists.
However, there is no evidence that the attackers actually compromised recipients’ devices or recorded them. The claims are part of a long-running social-engineering tactic that relies on publicly leaked data to create a believable story.
Leak Data Fuels Blackmail
According to BleepingComputer, the sextortion emails have targeted people whose addresses appeared in datasets allegedly stolen from organizations including Amtrak, Hallmark, ADT, Substack, Betterment, CarGurus, Panera Bread, and McGraw Hill.
The emails frequently mention the specific company where the victim’s data was supposedly exposed.
For example, a recipient whose email address appeared in an Amtrak-related dataset may receive a message claiming that Amtrak’s database gave the threat actor initial access to their account and devices.
This personalization makes the campaign more convincing than generic spam. Victims may recognize the named organization, remember having an account there, and assume the rest of the email is true.
A California community college also warned users about similar messages targeting individuals affected by the Canvas data breach. The college confirmed that targeted email addresses had previously appeared in data leaked by ShinyHunters.
ShinyHunters reportedly denied involvement in the sextortion operation. This suggests that separate scammers are reusing data published or circulated after previous breaches.

Threat actors can download leaked datasets from forums, messaging channels, or file-sharing platforms and use them for phishing, credential attacks, identity fraud, and extortion scams.
The demand for $ 2,000$2 {,}000$2,000 is higher than many earlier sextortion campaigns, which often requested smaller Bitcoin payments.
The increase may be an attempt to extract more money from victims using breach-specific details.
A review of a Bitcoin wallet included in one reported message showed no transaction activity, indicating that recipients may be ignoring the demand, malwarebytes said.
Recipients should treat these emails as unverified extortion attempts, even if the message includes their name, an old password, or the name of a company they use.
A leaked email address does not mean a criminal has access to a device, webcam, or online accounts.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.