Threat actors have been sending sextortion emails since April 2026 that draw on email addresses published in ShinyHunters data leaks, demanding $2,000 in Bitcoin while citing the specific company whose breach database the recipient’s address came from — a personalization technique designed to make fabricated surveillance threats feel targeted and credible.
How Attackers Use ShinyHunters Leak Data to Simulate Targeted Device Access
The campaign’s central deception relies on a single fact the attacker can actually verify: that the recipient’s email address appeared in a specific data breach. Each email opens by naming the breached company — “We gained access to the [Company] database where you have an account” — before escalating to false claims about malware installation, webcam and microphone access, and captured intimate video footage. The attacker does not have any of these things. The company-specific reference is the only accurate element in the message; everything that follows is fabricated.
Email addresses targeted in the campaign were verified to match those published in ShinyHunters’ leaked breach databases. The sextortion operators are not conducting new breaches — they are searching breach datasets already published by ShinyHunters and sending customized emails to each address, with the company name drawn from the dataset the address came from.
Amtrak, ADT, Betterment, and Five Other Breached Companies Named in the Fake Threats
The ShinyHunters breach databases being used in the campaign include records from Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill. Recipients whose email addresses appeared in these breach publications are receiving personalized emails that name the corresponding company, creating the impression that the sender has specific knowledge of the recipient’s device, online accounts, or browsing history. Betterment publicly acknowledged that its clients received threatening emails referencing the Betterment breach — the only company named in the campaign to issue a public statement confirming client reports.
The Fabricated Claims Behind Each $2,000 Bitcoin Demand
Beyond the company-specific breach reference, the emails make four categories of false claims: that malware was installed on the recipient’s device, that the malware provided webcam and microphone access, that intimate video footage of the recipient was captured, and that the sender holds the recipient’s complete contact list and will distribute the footage to those contacts if unpaid. None of these claims are true. The 48-hour payment deadline and the threat to distribute footage to contacts are pressure tactics designed to prevent recipients from pausing to verify the claims. Bitcoin wallet addresses are generated randomly per email, making the payment flow difficult to trace.
ShinyHunters Denies Direct Involvement as Reports Spread Across Multiple Platforms
ShinyHunters denied direct involvement in the sextortion campaign, claiming the operators were separately purchasing or scraping the breach data the group had published. Whether the sextortion operators are acquiring the breach data through purchase, direct scraping of ShinyHunters’ leak publications, or other channels, the practical outcome is the same: every future ShinyHunters data release expands the available targeting list for this campaign, and every subsequent breach publication by any extortion group using the same public leak format creates a fresh reservoir of personalized lure material for sextortion operators.
Reports of the campaign appeared across Reddit forums, Facebook groups, Better Business Bureau complaint filings, and local government fraud alerts from April 2026 onward, indicating the campaign reached a broad geographic distribution across the United States. The personalization of sextortion emails with breach-specific company references represents a material increase in perceived legitimacy compared to generic mass sextortion messages, which typically contain no accurate personal information. Campaigns that can credibly cite a real data breach the recipient is already aware of are more effective at generating fear responses that drive payment — a dynamic that gives sextortion operators direct financial incentive to monitor breach publications in real time.
