ShinyHunters Leaks Fuel $2000 Sextortion Scam
Cybercriminals are using the ShinyHunters name in a new sextortion campaign, demanding $2,000 in Bitcoin by leveraging email addresses from past data breaches. Here are the details of this bluff-based scam and how to protect yourself.
What Happened
The cybersecurity world is buzzing with a new scam campaign that exploits the name of the notorious group ShinyHunters, known for its large-scale data breaches. Threat actors are sending mass sextortion emails to individuals whose email addresses were exposed in company databases previously leaked by ShinyHunters. In this scheme, known as "sextortion," victims are demanded to pay $2,000 worth of Bitcoin. The most striking aspect of the campaign is how the scammers try to make their threats more credible by mentioning the specific data breach from which the victim's email address was obtained.
In the emails, the attackers, posing as the "ShinyHunters hacking group," claim to have gained access to the victim's devices several months ago and have been monitoring all their online activities. However, these claims are nothing more than a bluff based on social engineering tactics. Investigations by BleepingComputer and direct inquiries to the ShinyHunters group have revealed that the group itself is not behind this campaign. The real ShinyHunters group has flatly denied any involvement in these sextortion emails. This situation once again highlights how leaked data can be repurposed by different criminal groups and poses a continuous threat to innocent users. By hiding behind a big name and presenting information that seems specific to the victim, the attackers aim to create panic and achieve financial gain through this panic.
What Data Was Exposed
This scam campaign does not involve a new data breach. The attackers are repurposing information obtained from data breaches previously carried out and publicly leaked by ShinyHunters. The primary type of data being targeted is users' email addresses. It has been determined that the attackers use these emails to personalize their threats and create a perception of legitimacy. Knowing which company's breach the victim's email came from strengthens the impression that the threat is real.
According to BleepingComputer's analysis, the known data breaches from which the email addresses used in this campaign originate are:
- Amtrak
- Hallmark
- Substack
- Betterment
- CarGurus
- ADT
- Panera Bread
- McGraw Hill
In their emails, the attackers explicitly mention one of these companies, using phrases like, "We gained access to the Cargurus.com database where you have an account and easily accessed your email." If the victim has indeed had a relationship with one of these companies in the past, this increases the likelihood of the threat being taken seriously. However, it is understood that the compromised data is limited to email addresses and potentially the name of the associated company, while claims of device access are entirely false.
How Did the Attack Happen
This campaign is a social engineering attack based on psychological manipulation rather than a technical hack. The steps followed by the attackers are quite simple but are built on an effective fear mechanism.
1. Data Collection: The attackers first download the massive datasets previously leaked by ShinyHunters, which are often shared on various forums or the dark web. These datasets contain personal information like email addresses of millions of users.
2. Targeting: The email addresses in these datasets form the list of potential victims for the campaign. The attackers prepare for a mass email dispatch using these lists.
3. Crafting the Threat Email: To increase credibility, the scammers create an email template where they introduce themselves as ShinyHunters. The content of the email is designed to shock the victim and prevent rational thinking. The claims include:
- Access to the victim's devices (phone and computer) was gained several months ago.
- This access was made possible through the database breach of a named company (e.g., CarGurus) where the victim had an account.
- An "exploit" was installed on the devices, giving them access to the microphone, camera, keyboard, and all data.
- The victim's photos, browsing history, conversations, and contact list have been compromised.
- Most importantly, the threat that the victim was secretly recorded via their camera while visiting adult websites, and these videos will be shared with all their contacts.
4. Personalization and Dispatch: The email is personalized to include the name of the specific company from which the victim's email address was leaked. This small detail makes the victim think the email is not just another spam message, causing them to panic. The emails are sent with deceptive sender names like "ShinyHunters" or "You've Been HACKED" and generic subject lines such as "Information about your online security."
However, it must be reiterated that there is no evidence to support these claims. There are no indications that the victims' devices were compromised, that malware was installed, or that their cameras were monitored. This is an extortion attempt based entirely on a bluff.
Who Is Affected
The direct targets of this extortion campaign are individual users whose email addresses were exposed in past data breaches of the companies listed above, such as Amtrak, Hallmark, and Panera Bread. Therefore, former or current customers of these companies are at risk of receiving these fraudulent emails. The attack targets end-users whose data is already exposed due to leaks, not the companies' current systems. If a user had an account with any of these companies in the past and their account information was part of a breach, they become a potential victim. BleepingComputer has confirmed that some of the targeted email addresses were indeed present in the respective ShinyHunters leaks, which shows that the attackers are not targeting randomly but are proceeding with specific datasets.
What You Can Do
If you receive such an email, it is crucial to remain calm and take the right steps. Here is what you should do:
- Do Not Pay the Ransom: This is the most important rule. The attackers do not have any video or data as they claim. It is a bluff. Paying them will only show that their demands work and make you a more attractive target for future scams.
- Do Not Reply to the Email: Do not engage in any communication with the attackers. Replying confirms that your email address is active and can lead to further harassment.
- Mark as Spam and Delete: Immediately mark the email as spam or junk. This helps your email service provider filter similar emails in the future. Then, permanently delete the message.
- Review Your Account Security: This incident is another reminder of the importance of digital hygiene. You can use trusted services like "Have I Been Pwned" to check if your email address has been part of past breaches. Use strong, unique passwords for all your important accounts. Enable two-factor authentication (2FA) wherever possible.
- Don't Panic: Remember, these types of scams are built on exploiting feelings of fear and shame. The attackers' goal is to force you into making an irrational decision. Manage the situation knowing that the claims are false.
What Is the Company's Statement
There have been no statements yet from the companies whose data was leaked and whose names are being used in the campaign (such as Amtrak, CarGurus, etc.). However, a clear response has come from the ShinyHunters group, whose name is being exploited. Representatives of ShinyHunters, who were contacted directly by BleepingComputer, stated that they have no involvement in this sextortion campaign. They implied that such individual and small-scale scams are not their style of operation. This denial confirms that the incident is being carried out by third-party criminals who are using the notoriety created by ShinyHunters for their own benefit. It was already an unexpected scenario for a group known for large-scale actions like corporate extortion and data sales to be involved in this type of mass email scam.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.