"We Are ShinyHunters": The Extortion Email Scam Using Real Breaches to Fool You

Scammers are mining real data breaches to make a sextortion email look personal. If you got one naming a company you use, here's what's really going on.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

An email lands in your inbox claiming a hacker recorded you through your webcam, and to make you believe it, the sender names a real company you actually have an account with. Pay $2,000 in Bitcoin within 48 hours, it says, or the video goes to your family, friends, and coworkers.

If you received a message like this recently, you are one of potentially millions of Americans caught up in a coordinated scam that recycles data stolen from breaches at major US brands. Security researchers say the sextortion email is almost certainly an empty threat. But the reason they feel so personal is worth understanding, because it points to a much longer-lasting risk than the fake video ever could.[1]

In this article
How the fake ShinyHunters sextortion email scam works
Why the sextortion email feels personal even though it's a bluff
What to do if you get a sextortion email demanding Bitcoin
The bottom line on the ShinyHunters sextortion email

How the fake ShinyHunters sextortion email scam works

Since around April 2026, scammers have been sending emails that claim to come from the ShinyHunters hacking group, according to BleepingComputer, which first reported the campaign. The messages arrive with a subject line like "Information about your online security" and are signed by "ShinyHunters" or "You've Been HACKED."

The pitch is always the same. The sender claims to have broken into a company's database where you have an account, used that access to get into your email, and then installed an exploit that gave them control of your microphone, camera, and files. They say they recorded you visiting adult websites and will release the footage unless you pay.

Here is the important part: ShinyHunters is a real group tied to hundreds of data breaches, but it says it has nothing to do with these emails. When BleepingComputer contacted the group, it denied any involvement. The messages appear to come from unrelated scammers who simply downloaded data ShinyHunters had already leaked and are now reusing it.

The real breaches being mined for this campaign include those at Amtrak, Panera Bread, ADT, CarGurus, Betterment, Substack, Hallmark, and McGraw Hill. If you have an account with one of those companies, your email address may sit in that leaked data, which is exactly how the scammer knew to name it.

ShinyHunters is a real hacking group behind breaches at dozens of major companies, including 7-Eleven. But researchers confirmed these sextortion emails are not coming from them. Scammers are borrowing the name to sound credible.

Why the sextortion email feels personal even though it's a bluff

The trick that makes this scam land is a real email address paired with the name of a company you recognize. That is the entire illusion. There is no evidence the sender ever gained access to your device, installed malware, or recorded anything, according to both BleepingComputer and Malwarebytes, which analyzed the campaign.

One of the affected companies said as much to its own customers. After clients reported the emails, Betterment warned that "knowing an email address does not provide the ability to install malware or access someone's device," and advised recipients not to reply, pay, or click anything.

The scammers are also getting better at looking legitimate. Malwarebytes notes that while some of these emails are sloppy, many have been polished with AI and read convincingly. Regardless of how professional one looks, the underlying threat is the same empty bluff. As of late July, the Bitcoin wallet in at least one version of the email showed no payments at all, a sign that recipients are ignoring it.

Still, the fact that your email surfaced in a leak is a real signal worth taking seriously. Data breaches are the leading cause of identity theft, according to an identity theft survey by All About Cookies. The sextortion video is fake. The exposure that made you a target is not.

What to do if you get a sextortion email demanding Bitcoin

Knowing how to tell if a sextortion email is real comes down to this: these threats are essentially never backed by an actual recording. Once you accept that, the response is straightforward. Here is what to do after a data breach turns your inbox into a target.

  1. Do not reply and do not pay. Replying confirms your address is active and can invite more attempts. Paying signals you are an easy mark. Delete the message and report it as spam.
  2. Do not panic over the company name. It came from a public data leak, not from someone watching you. Naming it is the scam, not proof of a hack.
  3. Change the password on the named account, and anywhere you reused it. If the email quotes an old password of yours, change it everywhere it still appears. A password manager makes it easy to use a unique password for every account.
  4. Turn on two-factor authentication for your email and any financial or sensitive accounts, so a leaked password alone cannot get anyone in.
  5. Shrink your exposure. The less of your data is floating around, the fewer scams like this can reach you. A data removal service can pull your information from data broker sites that make it easy to find.

If your email has turned up in more than one breach, it may be worth setting up identity theft monitoring so you are alerted the moment your information is actually misused. When you are choosing a service, the features that matter most for a situation like this are dark web and breach monitoring that scans for your email address, passwords, and Social Security number, plus real-time alerts and recovery support if something does go wrong. A tool that covers those bases turns a scary email into a manageable heads-up.

The bottom line on the ShinyHunters sextortion email

A sextortion email that names a real company and demands Bitcoin is designed to scare you into acting before you think. It is built on real but limited leaked data, not on any actual access to your device. Ignore the threat, delete the message, and use the moment to lock down the accounts and reduce the exposure that put you on the list in the first place. That is the response that actually protects you.

4.8
Editorial Rating
Get Deal
On Aura Identity Theft's website
2026 Editors’ Choice
Best Overall Identity Theft Protection Service
Identity Protection
Aura Identity Theft
PROMOTION: Save Up to 68%
  • ID theft protection that monitors your SSN, bank accounts, credit cards, and brokerage and retirement accounts for suspicious activity
  • Every plan includes the full feature set, so no additional cost to unlock monitoring, insurance, or restoration
  • Bundles data removal with identity theft protection, antivirus, VPN, and a password manager in one subscription

Author Details
Kalleigh Lane is the Managing Editor at All About Cookies, where she helped develop the site's star rating system for product reviews and specializes in testing VPNs, ad blockers, and parental controls on Android and PC. She brings more than five years of experience editing and writing across cybersecurity, tech, and finance. Before joining AAC, she worked as a journalist and editor at CTV News and the Globe and Mail, and she holds a Master of Arts in English Literature from the University of Toronto.

Citations

[1] ShinyHunters data leaks fuel $2,000 sextortion email scam