All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
An email lands in your inbox claiming a hacker recorded you through your webcam, and to make you believe it, the sender names a real company you actually have an account with. Pay $2,000 in Bitcoin within 48 hours, it says, or the video goes to your family, friends, and coworkers.
If you received a message like this recently, you are one of potentially millions of Americans caught up in a coordinated scam that recycles data stolen from breaches at major US brands. Security researchers say the sextortion email is almost certainly an empty threat. But the reason they feel so personal is worth understanding, because it points to a much longer-lasting risk than the fake video ever could.[1]
Why the sextortion email feels personal even though it's a bluff
What to do if you get a sextortion email demanding Bitcoin
The bottom line on the ShinyHunters sextortion email
How the fake ShinyHunters sextortion email scam works
Since around April 2026, scammers have been sending emails that claim to come from the ShinyHunters hacking group, according to BleepingComputer, which first reported the campaign. The messages arrive with a subject line like "Information about your online security" and are signed by "ShinyHunters" or "You've Been HACKED."
The pitch is always the same. The sender claims to have broken into a company's database where you have an account, used that access to get into your email, and then installed an exploit that gave them control of your microphone, camera, and files. They say they recorded you visiting adult websites and will release the footage unless you pay.
Here is the important part: ShinyHunters is a real group tied to hundreds of data breaches, but it says it has nothing to do with these emails. When BleepingComputer contacted the group, it denied any involvement. The messages appear to come from unrelated scammers who simply downloaded data ShinyHunters had already leaked and are now reusing it.
The real breaches being mined for this campaign include those at Amtrak, Panera Bread, ADT, CarGurus, Betterment, Substack, Hallmark, and McGraw Hill. If you have an account with one of those companies, your email address may sit in that leaked data, which is exactly how the scammer knew to name it.
Why the sextortion email feels personal even though it's a bluff
The trick that makes this scam land is a real email address paired with the name of a company you recognize. That is the entire illusion. There is no evidence the sender ever gained access to your device, installed malware, or recorded anything, according to both BleepingComputer and Malwarebytes, which analyzed the campaign.
One of the affected companies said as much to its own customers. After clients reported the emails, Betterment warned that "knowing an email address does not provide the ability to install malware or access someone's device," and advised recipients not to reply, pay, or click anything.
The scammers are also getting better at looking legitimate. Malwarebytes notes that while some of these emails are sloppy, many have been polished with AI and read convincingly. Regardless of how professional one looks, the underlying threat is the same empty bluff. As of late July, the Bitcoin wallet in at least one version of the email showed no payments at all, a sign that recipients are ignoring it.
Still, the fact that your email surfaced in a leak is a real signal worth taking seriously. Data breaches are the leading cause of identity theft, according to an identity theft survey by All About Cookies. The sextortion video is fake. The exposure that made you a target is not.
What to do if you get a sextortion email demanding Bitcoin
Knowing how to tell if a sextortion email is real comes down to this: these threats are essentially never backed by an actual recording. Once you accept that, the response is straightforward. Here is what to do after a data breach turns your inbox into a target.
- Do not reply and do not pay. Replying confirms your address is active and can invite more attempts. Paying signals you are an easy mark. Delete the message and report it as spam.
- Do not panic over the company name. It came from a public data leak, not from someone watching you. Naming it is the scam, not proof of a hack.
- Change the password on the named account, and anywhere you reused it. If the email quotes an old password of yours, change it everywhere it still appears. A password manager makes it easy to use a unique password for every account.
- Turn on two-factor authentication for your email and any financial or sensitive accounts, so a leaked password alone cannot get anyone in.
- Shrink your exposure. The less of your data is floating around, the fewer scams like this can reach you. A data removal service can pull your information from data broker sites that make it easy to find.
If your email has turned up in more than one breach, it may be worth setting up identity theft monitoring so you are alerted the moment your information is actually misused. When you are choosing a service, the features that matter most for a situation like this are dark web and breach monitoring that scans for your email address, passwords, and Social Security number, plus real-time alerts and recovery support if something does go wrong. A tool that covers those bases turns a scary email into a manageable heads-up.
The bottom line on the ShinyHunters sextortion email
A sextortion email that names a real company and demands Bitcoin is designed to scare you into acting before you think. It is built on real but limited leaked data, not on any actual access to your device. Ignore the threat, delete the message, and use the moment to lock down the accounts and reduce the exposure that put you on the list in the first place. That is the response that actually protects you.