Scam watch · 5 min read

Sextortion Scammers Are Recycling the ShinyHunters Leaks

Old breach data is fuelling a new wave of "we have your photos" emails. Here is how the scam actually works, why the personal details in it are real, and why an alias user just deletes the address.

YeyMail Team ·

A wave of extortion emails is landing in inboxes with an unsettling opener: your real name, an address you have used, sometimes a password you recognise. The sender claims to have recorded you through your webcam and demands payment. Malwarebytes reports the current wave is built on data from breaches attributed to the ShinyHunters group — and that the group itself has denied sending the emails.

The demand in the campaign Malwarebytes examined is $2,000 in Bitcoin, with a 48-hour deadline. The researchers checked the Bitcoin address given in the emails and found no activity on it at all, which tells you something useful: nobody had paid.

The threat is empty. The data is not.

There is no footage. Malwarebytes describes the threats as unsubstantiated, and the absence of any payment to the wallet supports that. What is real is the personal information — it came out of breaches affecting a long list of well-known companies.

  • Amtrak
  • Hallmark
  • ADT
  • Substack
  • Betterment
  • CarGurus
  • Panera Bread
  • McGraw Hill
  • Canvas, the education platform

That is the whole trick. When a stranger quotes something true back at you — your name, an old password — your mind fills in the rest of the story and assumes the scary part is true as well. It is not evidence of a hacked device. It is evidence of a purchased spreadsheet.

Why the same leak works for years

Sextortion is cheap to run and close to risk-free. One database funds campaigns for years, because most people keep the same email address for a decade or more. The address is the join key: every breach it has ever appeared in stays attached to it, and the targeting list never goes stale.

Your email address is the one credential you never rotate. Leaked once, it stays a valid target for as long as you keep it.

Spam filters catch a share of these. But the wording changes constantly while the psychological hook — genuine personal data — survives every filter update.

What to do if one arrives

The advice in the Malwarebytes write-up is worth repeating, because it is short and it works.

  • Do not reply, and do not pay. Replying confirms the address is live.
  • Do not act in a hurry — the deadline exists to stop you thinking.
  • Change the password if you recognise it, anywhere you still use it.
  • Delete the message and report it as spam.
  • Use a password manager and turn on two-factor authentication.
The YeyMail takeaway
A scammer cannot extort an address that no longer exists.

If every signup gets its own alias, an extortion email tells you where it came from before you finish reading it — the address it arrived on names the breach. Deleting that one alias cuts the thread. Your real inbox and every other signup carry on untouched, and the list the scammer bought now points at nothing.

Start free — one alias per signup7-day trial · No credit card

Sources

Common questions

Do sextortion scammers really have video of me?

In this campaign, no. Malwarebytes describes the threats as unsubstantiated, and the Bitcoin address used in the emails showed no activity. The personal details in the message come from old data breaches, not from your device.

Why does the email know my real password?

Because it appeared in a data breach. Passwords and email addresses from breaches are traded and reused for years. Knowing one is evidence a company you used was breached, not evidence your computer was.

Should I pay a sextortion demand?

No. There is nothing to release, paying marks you as someone who pays, and replying at all confirms your address is live. Delete the email and report it as spam.

How do email aliases help against sextortion scams?

A unique alias per signup tells you which breach exposed you, because the scam arrives on that specific address. You can then delete that one alias, which stops that list from reaching you, without changing your real email address.

Keep reading

Breach analysis
Even Celebrities Get Leaked: Lessons From the Tribeca Contact Dump
Third-party risk
The Missouri Voucher Leak: You Are Only as Safe as the Weakest Contractor