A wave of extortion emails is landing in inboxes with an unsettling opener: your real name, an address you have used, sometimes a password you recognise. The sender claims to have recorded you through your webcam and demands payment. Malwarebytes reports the current wave is built on data from breaches attributed to the ShinyHunters group — and that the group itself has denied sending the emails.
The demand in the campaign Malwarebytes examined is $2,000 in Bitcoin, with a 48-hour deadline. The researchers checked the Bitcoin address given in the emails and found no activity on it at all, which tells you something useful: nobody had paid.
The threat is empty. The data is not.
There is no footage. Malwarebytes describes the threats as unsubstantiated, and the absence of any payment to the wallet supports that. What is real is the personal information — it came out of breaches affecting a long list of well-known companies.
- Amtrak
- Hallmark
- ADT
- Substack
- Betterment
- CarGurus
- Panera Bread
- McGraw Hill
- Canvas, the education platform
That is the whole trick. When a stranger quotes something true back at you — your name, an old password — your mind fills in the rest of the story and assumes the scary part is true as well. It is not evidence of a hacked device. It is evidence of a purchased spreadsheet.
Why the same leak works for years
Sextortion is cheap to run and close to risk-free. One database funds campaigns for years, because most people keep the same email address for a decade or more. The address is the join key: every breach it has ever appeared in stays attached to it, and the targeting list never goes stale.
Your email address is the one credential you never rotate. Leaked once, it stays a valid target for as long as you keep it.
Spam filters catch a share of these. But the wording changes constantly while the psychological hook — genuine personal data — survives every filter update.
What to do if one arrives
The advice in the Malwarebytes write-up is worth repeating, because it is short and it works.
- Do not reply, and do not pay. Replying confirms the address is live.
- Do not act in a hurry — the deadline exists to stop you thinking.
- Change the password if you recognise it, anywhere you still use it.
- Delete the message and report it as spam.
- Use a password manager and turn on two-factor authentication.