CERT-AGID identified a new sextortion campaign circulating internationally since April 2026 and observed for the first time in Italy, with scammers impersonating ShinyHunters. The emails claim to have compromising material and demand $2,000 in Bitcoin within 48 hours, but ShinyHunters denied any involvement. #ShinyHunters #CERTAGID
Keypoints
- CERT-AGID detected a new sextortion campaign pretending to be distributed by ShinyHunters.
- The emails had been circulating internationally since April 2026 and were seen in Italy for the first time.
- The attackers claim to possess compromising material allegedly obtained through malware on the victim’s device.
- The message threatens to leak intimate videos to family, colleagues, and friends unless $2,000 in Bitcoin is paid within 48 hours.
- ShinyHunters, active since 2019, is known for data breaches, unauthorized access, zero-day exploits, supply chain attacks, and social engineering.
- ShinyHunters told BleepingComputer that the emails are not attributable to them and denied involvement.
- Recipients are advised to ignore or delete the email, avoid interacting with the sender, and make no payment.
MITRE Techniques
- [T1566 ] Phishing – The campaign uses deceptive emails to lure victims into believing the extortion claim (’email circolanti già da aprile 2026′ / ’emails circulating since April 2026′).
- [T1589 ] Gather Victim Identity Information – The attackers rely on harvested recipient email addresses, possibly from leaked data lists (‘non è noto dove siano stati reperiti gli indirizzi email italiani coinvolti’).
- [T1566.001 ] Spearphishing Attachment – The email is framed as an extortion message delivered directly to the victim, though no attachment is described (‘campione della email di sextortion con richiesta di pagamento’).
- [T1485 ] Data Destruction – The threat to expose or publish sensitive content is used as coercion (‘minacciano la diffusione di presunti video intimi’).
- [T1657 ] Financial Theft – The attackers demand payment in Bitcoin as the objective of the sextortion attempt (‘pagamento di 2.000 dollari in Bitcoin entro 48 ore’).
- [T1587.001 ] Develop Capabilities: Malware – The scammers claim access to victim devices via malware to obtain sensitive data (‘grazie a un malware installato sui dispositivi della vittima’).
Indicators of Compromise
- [Email addresses ] Targeted recipients in the sextortion campaign – Italian victim addresses and other leaked recipient lists
- [Threat actor name ] Impersonated sender identity used in the emails – ShinyHunters
- [Monetary demand ] Extortion amount and payment channel – 2,000 USD, Bitcoin
- [Time constraint ] Deadline included in the threat email – 48 hours
- [Organizations mentioned ] Reporting and attribution context – CERT-AGID, BleepingComputer