ShinyHunters’ Name Gets Hijacked for a New $2,000 Sextortion Scam

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Ransom demand: Scammers use ShinyHunters-leaked email addresses from breaches at Hallmark, Betterment, and more to demand $2,000 in Bitcoin.
  • Group denial: ShinyHunters denied any involvement in the sextortion email campaign.
  • Campaign details: The campaign appears to have started in April 2026 and the scammers allege they stole photos, browsing history, conversations, and contact list.

Threat actors are reportedly exploiting email addresses exposed in data breaches leaked by the ShinyHunters group to send sextortion emails demanding $2,000 in Bitcoin. The emails claim to come from the infamous threat actor and tell recipients that attackers compromised their devices after pulling their email addresses from breached company databases. 

Fake ShinyHunters Identity Used for Scam

The messages actually appear to be sent by someone who simply downloaded data ShinyHunters had already leaked, then borrowed the group's name to make the threat feel more credible. The emails allegedly arrive from random addresses using names like "ShinyHunters" or "You've Been HACKED," carrying the subject line "Information about your online security."

We gained access to the Cargurus.com database where you have an account and easily accessed your email,” the analyzed example said. The message reportedly claims an exploit was installed on the recipient’s devices a week later, granting access to the microphone, camera, keyboard, photos, browsing history, conversations, and contact list.

Fake ShinyHunters email | Source: BleepingComputer
Fake ShinyHunters email | Source: BleepingComputer

Then threatens to release intimate videos unless $2,000 in Bitcoin lands in a wallet within 48 hours. There's no proof any of that actually happened. BleepingComputer has traced leaked data used in the campaign back to these breaches:

For some recipients, the report says their targeted email address genuinely did appear in that previously leaked data. When contacted, the real ShinyHunters extortion group allegedly denied any involvement.

Betterment Responds, Urges No Payment

After a recipient posted about receiving one of these emails referencing the Betterment breach on Reddit, the firm confirmed it was aware of the campaign, noting plainly that "knowing an email address does not provide the ability to install malware or access someone's device." 

Best practice suggests you don't pay, don't reply, don't click anything, and don't open attachments.

February reports said 1.4 million Betterment email addresses were exposed following a “third-party” social engineering data breach, and a March 2026 Hallmark data breach exposed 1.7 million customers via Salesforce compromise.

Earlier this month, Medtronic notified customers of a data breach claimed by ShinyHunters.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: