The Truth Behind the Latest $2,000 Sextortion Scam

If you opened your inbox today to find a terrifying email claiming a hacker group has taken over your phone, recorded your private moments, and demands $2,000 in Bitcoin to keep quiet, take a deep breath. You have not been hacked, and your camera was not compromised.

A widespread extortion campaign is currently targeting everyday web users, posing as the well-known threat group ShinyHunters. While the email might look scary because it names a specific service you use, the entire threat is a complete bluff.

Here is what is actually happening, why these emails sound so convincing, and what you should do next.

How the Scam Works

In a typical email from this campaign, scammers claim they accessed your device months ago through a corporate security breach. They might list a real company where you have an account—such as Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, or McGraw Hill—to make the threat feel personal and real.

The scammer then claims they installed spyware on your phone or computer, logged your keystrokes, and recorded embarrassing footage of you while visiting adult websites. They threaten to send these alleged videos to your friends, family, and co-workers within 48 hours unless you pay $2,000 in Bitcoin.

The Twist: It’s Just Recycled Data

While the email address and company name they mention might be real, the threat is completely fake.

Scammers didn’t hack your personal device or install malware. Instead, they simply downloaded publicly leaked customer data from past corporate data breaches involving ShinyHunters. By cross-referencing your email address with the company name from those old leaks, they create a personalized script designed to spark panic.

Even ShinyHunters itself has denied involvement; this is just an opportunistic scammer using recycled breach records to scare people into sending money.

3 Things You Should Do Right Now

  1. Do NOT Pay or Reply: Paying or replying confirms to the scammer that your email address is active, which can make you a target for even more spam and extortion attempts.
  2. Delete the Email: Once you’ve read it, flag it as spam or phishing in your email provider and delete it.
  3. Secure Your Accounts for Peace of Mind:
    • Change Passwords: If you reuse the password associated with the breached service named in the email, change it immediately on all accounts where it’s used.
    • Enable 2FA: Turn on Two-Factor Authentication (2FA) across your primary email and financial accounts to add an extra layer of security.

The Bottom Line

Receiving an email that knows your name or where you shop can be unsettling, but knowing how these scams operate takes away their power. Scammers rely on fear and urgency to force quick decisions.

If you receive one of these extortion emails, remember: it’s just spam fueled by old breach data. Delete the message, secure your passwords, and enjoy your day.

Stop Responding to Threats.
Prevent Them.

Want to get monthly tips & tricks?

Subscribe to our newsletter to get cybersecurity tips & tricks and stay up to date with the constantly evolving world of cybersecurity.

Related Articles