ShinyHunters data leak fuels $2,000 sextortion email scams

▼ Summary
– Threat actors are using email addresses from ShinyHunters’ data breaches to send sextortion emails demanding $2,000 in Bitcoin, but the emails are likely sent by unrelated scammers, not ShinyHunters itself.
– The emails falsely claim the sender compromised the recipient’s devices, accessed cameras and browsing history, and recorded them visiting adult websites, but there is no evidence of such access.
– BleepingComputer confirmed that email addresses in the campaign match leaked data from breaches including Amtrak, Hallmark, and Substack, which were previously published by ShinyHunters.
– The sextortion campaign began in April, with victims reporting emails referencing breaches like Betterment; Betterment advised customers not to pay or reply, noting that knowing an email address does not enable device access.
– ShinyHunters denied involvement in the campaign, and the emails are a common scam tactic using leaked data to appear targeted, despite lacking any actual compromise of recipients’ devices.
Threat actors are exploiting email addresses exposed in data breaches linked to the ShinyHunters extortion group, launching sextortion email scams that demand $2,000 in Bitcoin. These messages falsely claim to originate from ShinyHunters, warning recipients that hackers compromised their devices after obtaining their email addresses from breached company databases.
In reality, the emails appear to be sent by individuals who downloaded data previously leaked by ShinyHunters, rather than by the group itself. The attackers use these exposed email addresses to lend credibility to their threats. BleepingComputer has confirmed that leaked data from breaches involving Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill has been used in this campaign. For some recipients, verification showed their email addresses were indeed part of the associated ShinyHunters leaks.
Extortion groups typically threaten victims that refusing to pay will expose customers and employees to further abuse once stolen data is published. While these claims aim to pressure organizations into compliance, this campaign demonstrates how leaked data can be repurposed by unrelated threat actors for malicious ends. Despite the use of a recipient’s leaked email address to make the messages appear more convincing, there is no evidence that the sender compromised devices, installed malware, accessed cameras, or monitored activity on adult websites.
BleepingComputer reached out to the ShinyHunters extortion group, which denied any involvement in the sextortion email campaign.
The emails seen by BleepingComputer arrive from random addresses using sender names like “ShinyHunters” or “You’ve Been HACKED,” with the subject line “Information about your online security.” The messages claim the attackers gained access to recipients’ devices months earlier, naming a company whose data ShinyHunters previously published. They allege that the breach allowed them to access the recipient’s email account, stating: “We gained access to the Cargurus.com database where you have an account and easily accessed your email. You weren’t very careful about the links you opened.”
The email falsely asserts that the attackers later installed an exploit on victims’ computers and phones, enabling access to microphones, cameras, keyboards, photos, browsing history, conversations, and contact lists. It then claims the sender recorded the recipient visiting adult websites and threatens to share intimate videos with friends, colleagues, and family. To prevent this, victims are told to send $2,000 in Bitcoin within 48 hours. The email also warns against contacting police, replying, or resetting devices, claiming the stolen information is stored on remote servers.
These sextortion emails are designed to frighten recipients into paying out of fear of reputational damage. However, there is no indication that the sender ever accessed recipients’ devices or personal activity. Instead, attackers use details from published data breaches,such as an email address and the breached company name,to make the scam appear targeted.
While some might doubt anyone would fall for these scams, they were highly profitable when they first emerged in 2018, generating over $50,000 in a single week. Since then, scammers have diversified into various extortion email schemes, including fake hitman contracts, cheating spouse allegations, bomb threats, CIA investigations, and ransomware threats.
The current sextortion campaign appears to have started in April, with numerous individuals and organizations reporting similar messages or warning recipients to ignore them. One Reddit user who received an email referencing the Betterment breach posted about it on the Betterment subreddit. Betterment responded that it was aware some clients had received threatening emails claiming to come from a hacking group. “These messages are part of a common extortion scam designed to intimidate recipients,” Betterment stated. “Please note, knowing an email address does not provide the ability to install malware or access someone’s device.”
Betterment advised recipients not to reply, send payment, click links, or open attachments, and to delete the email. It also asked customers who had interacted with the message to contact its fraud team. Although a recipient’s email address may appear in one of the published data leaks referenced in the message, this does not mean the sender compromised their devices, recorded videos, or obtained any other information described. Recipients should not pay the ransom or respond to the sender.
(Source: BleepingComputer)




