Security News

Cybersecurity news aggregator

MEDIUM Attacks SC Media

Scammers impersonate ShinyHunters in new sextortion email campaign

  • What: Scammers impersonate ShinyHunters in new sextortion email campaign
  • Impact: Users may receive fraudulent emails demanding Bitcoin payments
Read Full Article →

Identity , Email security Scammers impersonate ShinyHunters in new sextortion email campaign July 27, 2026 Share By SC Staff Following insights from Bleeping Computer, threat actors are leveraging email addresses exposed in data breaches, previously leaked by the ShinyHunters extortion group, to perpetrate a new sextortion email campaign demanding $2,000 in Bitcoin. These fraudulent emails falsely claim to originate from ShinyHunters, asserting that the attackers compromised recipients' devices after obtaining their email addresses from breached company databases. However, investigations suggest these messages are sent by unrelated threat actors who have repurposed data leaked by ShinyHunters. The campaign has been observed using email addresses from breaches affecting companies such as Amtrak, Hallmark, Substack, and Betterment. While the use of a known leaked email address lends a false sense of legitimacy, there is no evidence that the senders have actually compromised recipients' devices, installed malware, accessed cameras, or monitored online activity. The ShinyHunters group itself has denied any involvement in this sextortion scheme. The emails typically claim to have gained access to devices, recorded visits to adult websites, and threaten to release compromising material to friends and family unless a Bitcoin ransom is paid within 48 hours. Security experts emphasize that these are common extortion tactics and recipients should not pay or respond to the sender, as the claims of device compromise are unsubstantiated. Source: Bleeping Computer SC Staff Related Data Security Pope’s prayer app leaks 700,000 user emails SC Staff July 27, 2026 The Click To Pray app, endorsed by the Pope and used by hundreds of thousands worldwide, was leaking user names and email addresses for months. Data Security OnTrac parcel delivery company reports customer data breach SC Staff July 27, 2026 Bleeping Computer reports that the parcel delivery company OnTrac has experienced a data breach, potentially exposing customer personal details following a cyberattack on its corporate network. AI/ML Phishing the agent: Why identity controls are essential to secure and manage AIs Paul Wagenseil July 27, 2026 Guardrails cannot serve as the primary security boundary for AI agents. Identity controls impose firmer limits. Related Events Cybercast The identity evolution that enables AI confidence Tue Aug 11 Cybercast IAM for MSSPs: Real-World Deployments On-Demand Event Cybercast Privilege risk is in the lifecycle: A CISO discussion on modernizing identity control On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Biometrics Bring Your Own Device (BYOD) Certificate-Based Authentication Challenge-Handshake Authentication Protocol (CHAP) Digital Certificate Discretionary Access Control (DAC) Post Office Protocol, Version 3 (POP3) Spam Store-and-Forward You can skip this ad in 5 seconds

Share this article