Skip to content
feed: live
>_ 0dayNews
ransomware
● Breaking

ShinyHunters Breach Data Now Fueling Sextortion Emails

Threat actors are targeting email addresses from ShinyHunters data leaks with $2,000 Bitcoin sextortion demands. What the campaign looks like and what to do.

ShinyHunters Breach Data Now Fueling Sextortion Emails
Photo: Optima D / Wikimedia Commons · CC BY-SA 4.0
airgap airgap · Published · 1 min read

Breach data from ShinyHunters leaks is now the source list for a $2,000 Bitcoin sextortion campaign. BleepingComputer confirmed today. Confidence: confirmed reporting.

What’s known

  • Email addresses were sourced from ShinyHunters-linked data leaks. Confirmed.
  • Threat actors are using those addresses to send sextortion demands at $2,000 per email. Confirmed.
  • Whether ShinyHunters operators are running the campaign directly or the data moved through secondary channels: unconfirmed — treat attribution separately until established.

ShinyHunters has fed the breach ecosystem repeatedly over the past several weeks — the Abbott / Exact Sciences vishing intrusion, Salesforce OAuth abuse documented by Microsoft, the Odido exposure. Each event deposited real names, real email addresses, and in some cases phone numbers into the downstream market. That inventory is now being monetized.

What to do if you receive one

Do not pay. Do not reply. Confidence: confirmed — both actions mark you as responsive and escalate targeting.

Report it: FBI IC3 in the U.S.; Action Fraud in the UK.

Rotate any passwords tied to the compromised email address. Breach-sourced campaign lists often carry password data alongside the email. Reuse is the real secondary risk. Credential reuse — not the sextortion threat itself — is what causes downstream account compromise.

Mass campaign vs. targeted

Mass sextortion at this price point is almost entirely bluff. Real individual extortion comes with proof and does not arrive as a form letter. If the message includes accurate personal detail beyond your email address, actual proof of material, or reads as individually crafted: that is a separate, higher-severity situation. Contact law enforcement directly.

The longer arc

ShinyHunters breach data now has confirmed downstream use in two distinct campaign types: corporate vishing chains (Entra SSO, OAuth abuse) and mass consumer sextortion. The data lifecycle runs past the notification window. Assume any address that appeared in a ShinyHunters-linked breach is a durable exposure.

Have I Been Pwned — baseline check for known breach membership. Not exhaustive. A starting point.


Source: ShinyHunters data leaks fuel $2,000 sextortion email scam — BleepingComputer, July 25, 2026.

Found this useful? Share it.