Cybercriminals are leveraging stolen email addresses from data breaches linked to the ShinyHunters hacking group to create more believable sextortion emails This article explores cybercriminals leveraging stolen. . The campaign uses fake personal information and references to known breaches to pressure recipients into paying $2,000 in Bitcoin.
Sextortion scams have been around for a while; attackers typically claim they hacked a victim's device and recorded them through a webcam or that the user visited adult websites. They claim that malware was installed on the victim’s devices, allowing them to access cameras, microphones, keyboards, photos, browsing history, messages, and contact lists.
Leak Data Fuels Blackmail According to BleepingComputer, sextortion emails have targeted individuals whose email addresses were found in datasets allegedly stolen from organizations such as Amtrak, Hallmark, ADT, Substack, Betterment, CarGurus, Panera Bread, and McGraw Hill. For example, a recipient whose email address appeared in an Amtrak-related dataset may receive a message claiming that Amtrak’s database gave the threat actor initial access to their account and devices. Threat actors can download leaked datasets from forums, messaging channels, or file-sharing platforms and exploit them for phishing, credential attacks, identity fraud, and extortion scams.
Utilize ANY.RUN's advanced SOC tools to identify vulnerabilities and mitigate risks proactively, thereby minimizing response costs and disruptions while ensuring a swift containment of threats.












