False Sextortion ShinyHunters: Emails Arrive in Italy for the First Time

False Sextortion ShinyHunters: Emails Arrive in Italy for the First Time
CERT-AGID identified a new sextortion campaign circulating internationally since April 2026 and observed for the first time in Italy, with scammers impersonating ShinyHunters. The emails claim to have compromising material and demand $2,000 in Bitcoin within 48 hours, but ShinyHunters denied any involvement. #ShinyHunters #CERTAGID

Keypoints

  • CERT-AGID detected a new sextortion campaign pretending to be distributed by ShinyHunters.
  • The emails had been circulating internationally since April 2026 and were seen in Italy for the first time.
  • The attackers claim to possess compromising material allegedly obtained through malware on the victim’s device.
  • The message threatens to leak intimate videos to family, colleagues, and friends unless $2,000 in Bitcoin is paid within 48 hours.
  • ShinyHunters, active since 2019, is known for data breaches, unauthorized access, zero-day exploits, supply chain attacks, and social engineering.
  • ShinyHunters told BleepingComputer that the emails are not attributable to them and denied involvement.
  • Recipients are advised to ignore or delete the email, avoid interacting with the sender, and make no payment.

MITRE Techniques

  • [T1566 ] Phishing – The campaign uses deceptive emails to lure victims into believing the extortion claim (’email circolanti già da aprile 2026′ / ’emails circulating since April 2026′).
  • [T1589 ] Gather Victim Identity Information – The attackers rely on harvested recipient email addresses, possibly from leaked data lists (‘non è noto dove siano stati reperiti gli indirizzi email italiani coinvolti’).
  • [T1566.001 ] Spearphishing Attachment – The email is framed as an extortion message delivered directly to the victim, though no attachment is described (‘campione della email di sextortion con richiesta di pagamento’).
  • [T1485 ] Data Destruction – The threat to expose or publish sensitive content is used as coercion (‘minacciano la diffusione di presunti video intimi’).
  • [T1657 ] Financial Theft – The attackers demand payment in Bitcoin as the objective of the sextortion attempt (‘pagamento di 2.000 dollari in Bitcoin entro 48 ore’).
  • [T1587.001 ] Develop Capabilities: Malware – The scammers claim access to victim devices via malware to obtain sensitive data (‘grazie a un malware installato sui dispositivi della vittima’).

Indicators of Compromise

  • [Email addresses ] Targeted recipients in the sextortion campaign – Italian victim addresses and other leaked recipient lists
  • [Threat actor name ] Impersonated sender identity used in the emails – ShinyHunters
  • [Monetary demand ] Extortion amount and payment channel – 2,000 USD, Bitcoin
  • [Time constraint ] Deadline included in the threat email – 48 hours
  • [Organizations mentioned ] Reporting and attribution context – CERT-AGID, BleepingComputer


Read more: https://cert-agid.gov.it/news/falsa-sextortion-shinyhunters-le-email-arrivano-per-la-prima-volta-in-italia/