Threat actors are sending sextortion emails that use email addresses exposed in past ShinyHunters-linked data breaches to demand $2,000 in Bitcoin. The messages falsely claim device compromise, but evidence suggests the sender is repurposing leaked breach data rather than acting as ShinyHunters itself. #ShinyHunters #Amtrak #Hallmark #Substack #Betterment #CarGurus #ADT #PaneraBread #McGrawHill
Keypoints
- Attackers are using leaked email addresses from prior breaches in sextortion scams.
- The emails impersonate ShinyHunters and demand $2,000 in Bitcoin.
- The claims of device compromise, malware, and webcam access are false.
- Leaked data from Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill was seen in the campaign.
- Betterment and ShinyHunters both denied the senderβs claims, and recipients are advised not to pay or reply.