Scammers Recycle ShinyHunters Breach Data to Power $2,000 Sextortion Emails

A campaign running since April uses email addresses from old ShinyHunters leaks to make fake extortion threats look personal.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial aerial view of three illuminated server racks in a dark data center, each casting a different colored glow — amber, blue, red — on the
Share

Key points

  • Scammers are sending sextortion emails demanding $2,000 in Bitcoin, using email addresses pulled from data leaks published by the ShinyHunters extortion group.
  • Leaked records from Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread and McGraw Hill have been reused in the campaign.
  • The senders falsely claim to have hacked recipients' phones and cameras; there is no evidence any device was actually accessed.
  • ShinyHunters told BleepingComputer, which first reported the campaign, that it has no involvement.
  • The campaign began in April 2024 and Betterment has publicly warned customers to ignore and delete the emails.

Criminals are working through old breach data to run a fresh sextortion scam, sending emails that demand $2,000 in Bitcoin and claim to come from the well-known ShinyHunters extortion crew.

Sextortion is a scam where a stranger emails you claiming they have filmed you watching adult websites, and threatens to send the video to your friends and family unless you pay. The scam has been around for years. What makes this wave different is the personal touch: the sender addresses you at an email address that really did appear in a company data breach, and names the breached company by way of proof.

The emails arrive from random addresses under names like "ShinyHunters" or "You've Been HACKED" with the subject line "Information about your online security." Inside, the sender claims they broke into a specific company's database (CarGurus, for example), used that to get into the recipient's email, then installed spyware giving them access to the camera, microphone, keyboard, photos and contacts.

None of that is true. Knowing someone's email address does not let you install malware on their phone.

Where did the email addresses come from?

From real breaches, but not from fresh hacking. The senders appear to have simply downloaded data that ShinyHunters had already leaked publicly, then mail-merged the addresses into a threatening template.

BleepingComputer, which broke the story, has seen the campaign reference leaked data from Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread and McGraw Hill. In some cases, reporters confirmed the targeted email address really was in the associated leak.

ShinyHunters itself denies running the campaign. That fits the pattern: once stolen data is dumped online, anyone can pick it up and reuse it.

What the scam email actually says

The message follows a template. Below is how the key claims line up against reality.

Claim in the email Reality
"We are the ShinyHunters hacking group" ShinyHunters denies involvement
"We accessed your email via the [Company] breach" Only the email address was taken from the public leak
"We installed an exploit on your phone and computer" No evidence any device was accessed
"Pay $2,000 in Bitcoin within 48 hours" Paying funds the scam; there is nothing to release

The email also tells recipients not to contact police, not to reply, and not to reset their devices. That is a pressure tactic, not a technical constraint.

Should I be worried if I got one?

No, but do not pay. There is no evidence the sender has any access to your camera, microphone, browsing history or contacts. They have your email address because a company you used was breached, and that address was later dumped online.

Delete the message. Do not reply, do not click links, do not open attachments. If you reused the password from the breached account anywhere else, change it now, and turn on two-factor authentication where you can.

Betterment, one of the companies named in the emails, told affected customers plainly: "knowing an email address does not provide the ability to install malware or access someone's device." The firm advised recipients to delete the email and contact its fraud team if they had already engaged with it.

Sextortion scams have been profitable before. An early 2018 wave pulled in more than $50,000 in a single week. The formula keeps evolving, from fake hitman contracts to bomb threats to ransomware claims, but the underlying trick is the same: frighten you into paying for something that never happened.

Common questions

How did the scammers get my email address?

From a company data breach that was later published online. The sender did not hack you personally; they downloaded a public leak and used your address from it.

Should I pay the $2,000?

No. Paying confirms your address is active and marks you as a soft target for further scams. There are no compromising videos to release.

What if the email includes an old password of mine?

That password came from the same leaked data. Change it anywhere you still use it, and switch on two-factor authentication on those accounts.

© 2026 Threat Vectr