Risk actors are sending sextortion emails demanding $2,000 in Bitcoin utilizing e-mail addresses uncovered in a knowledge breach leaked by extortion group ShinyHunters.
The e-mail claims to be from ShinyHunters and tells the recipient that their machine has been compromised after the hacker retrieves the e-mail tackle from a compromised company database.
Nonetheless, the message seems to have been despatched by somebody who downloaded knowledge beforehand leaked by ShinyHunters, quite than the extortion group itself, utilizing a broadcast e-mail tackle to make the risk appear extra official.
BleepingComputer has recognized leaked knowledge from Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill breaches used on this sextortion e-mail marketing campaign.
For some recipients, BleepingComputer has confirmed that the e-mail addresses focused by the sextortion emails had been certainly included in associated knowledge beforehand leaked by ShinyHunters.
Extortion gangs typically warn victims that refusing to pay will expose prospects and workers to additional abuse after stolen knowledge is made public. Whereas these claims are geared toward forcing organizations to pay up, this marketing campaign exhibits how leaked knowledge can later be reused for malicious functions by unrelated risk actors.
Though the recipient’s leaked e-mail tackle might make these emails seem extra convincing, there is no such thing as a indication that the sender has compromised the recipient’s machine, put in malware, accessed their digital camera, or monitored their exercise on grownup web sites.
BleepingComputer contacted the ShinyHunters extortion group, which denied any involvement within the sextortion e-mail marketing campaign.
ShinyHunters pretend sextortion e-mail
The emails seen by BleepingComputer had been despatched from random e-mail addresses utilizing the names “ShinyHunters” or “You’ve got Been HACKED” and the topic line was “Details about on-line safety.”
The message claims to be from the ShinyHunters hacking group and states that the attackers gained entry to the recipient’s machine a number of months in the past.
The sender then named the businesses whose knowledge had beforehand been uncovered by ShinyHunters and claimed that the breach gave them entry to the recipients’ e-mail accounts.
We’re the ShinyHunters hacking group.
A couple of months in the past, we gained entry to your machine and began monitoring your on-line actions.
what occurred:
We have now accessed the Cargurus.com database the place you’ve an account and have made it simple so that you can entry your e-mail.
I wasn’t paying a lot consideration to the hyperlinks I opened.
After every week, the exploit was put in on the client’s machine, together with their cell phone, permitting entry to the microphone, digital camera, keyboard, and all knowledge.
We have now your photographs, shopping historical past, conversations, and call record.

Supply: BleepingComputer
The e-mail falsely claims that the attackers later “put in an exploit” on the victims’ computer systems and cellphones, giving them entry to their microphones, cameras, keyboards, photographs, shopping historical past, conversations, and call lists.
The sender then claimed to have recorded the recipient visiting an grownup web site and threatened to share the intimate video with pals, colleagues, and household.
To forestall these compromised movies from being printed, victims are requested to switch $2,000 in Bitcoin inside 48 hours.
The e-mail warns recipients to not contact regulation enforcement, reply to messages, or reset their units as a result of the stolen data is saved on a distant server.
The sort of e-mail is called a “sextortion” e-mail and is designed to scare the recipient into paying their calls for out of concern of damaging their fame with pals, household, or work colleagues.
Nonetheless, there is no such thing as a indication that the sender has accessed the recipient’s machine or private actions.
As an alternative, attackers use publicly accessible particulars of the info breach, equivalent to e-mail addresses and the identify of the compromised firm, to make it seem {that a} sextortion rip-off is being focused.
You would possibly suppose that nobody would fall for these scams, however they had been very profitable after they first appeared in 2018, producing over $50,000 in every week.
Since then, scammers have created a wide range of extortion e-mail scams posing as contracts for hit males, details about dishonest spouses, bomb threats, CIA investigations, threats to put in ransomware, and extra.
Marketing campaign began in April
The sextortion marketing campaign seems to have began in April, with many people and organizations reporting related messages or warning recipients to disregard them.
A person who obtained an e-mail concerning the Betterment breach posted about it on the Betterment Reddit.
Betterment responded that it’s conscious that some prospects have obtained threatening emails claiming to return from a hacking group.
“These messages are a part of a standard extortion rip-off geared toward blackmailing the recipient,” Betterment mentioned.
“Please be aware that understanding an e-mail tackle doesn’t imply you’ll be able to set up malware or acquire entry to another person’s machine.”
The corporate suggested recipients to not reply, ship cash, click on on hyperlinks or open attachments, and to delete the e-mail. Betterment additionally requested prospects whose messages had been manipulated to contact its fraud crew.
Though your e-mail tackle could also be listed in one of many public knowledge breaches referenced within the e-mail, this doesn’t imply that the sender has compromised your machine, recorded the video, or obtained another data talked about within the message.
Recipients of those messages should not pay the ransom or reply to the sender.
Safety groups doc 54% of profitable assaults and problem a warning on solely 14%. The remaining strikes invisibly by way of the atmosphere.
Picus’ whitepaper exhibits how one can take a look at your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
