Jul 26, 2026 · 7 min read
Leaked Emails Now Fuel a $2,000 Sextortion Scam
Scammers are pulling addresses out of the breach dumps ShinyHunters published from Amtrak, Panera Bread, Substack, ADT and five other companies, then emailing those people a fabricated claim of camera access and a 48 hour deadline to send $2,000 in Bitcoin. ShinyHunters says it isn't them.
The message opens with a line built to make your stomach drop. "We are the ShinyHunters hacking group. A few months ago, we gained access to your devices and started monitoring your online activities." Then it names the company your address was taken from. That one detail is the hook, because unlike everything else in the email, it happens to be true.
BleepingComputer reported on July 25, 2026 that a sextortion campaign running since April has been targeting people whose addresses appear in ShinyHunters leak data, demanding $2,000 in Bitcoin within 48 hours. The publication confirmed that recipients' addresses matched leaked data from eight separate breaches. When it contacted ShinyHunters, the group denied any involvement, which means somebody else downloaded the group's published dumps and is now monetizing them a second time.
Key Takeaways
- The emails demand $2,000 in Bitcoin within 48 hours and arrive under the subject line "Information about your online security" with sender names such as "ShinyHunters" or "You've Been HACKED," according to BleepingComputer.
- Addresses used in the campaign trace to leaked data from Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread and McGraw Hill.
- ShinyHunters told BleepingComputer it had nothing to do with the campaign, so unrelated actors are recycling lists the group published months earlier.
- Have I Been Pwned puts Amtrak's April 2026 leak at 2.1 million unique addresses and Panera Bread's at 5.1 million, meaning two of the eight named lists alone supply roughly 7.2 million targets.
- The FBI's Internet Crime Complaint Center logged more than 75,000 sextortion submissions in 2025, and the device access these particular emails describe does not exist.
What Do These Sextortion Emails Actually Claim?
They claim the sender broke into your computer and phone months ago and has been watching ever since. The email asserts that an exploit was installed on your devices, granting access to the camera and microphone, and that the sender now holds your photos, browsing history, conversations and contact list. It then claims to have recorded you visiting adult websites and threatens to send an intimate video to your friends, colleagues and family unless $2,000 in Bitcoin arrives inside 48 hours.
None of the device compromise is real. This is the same template the FTC warned about back in 2020, when the credibility prop was an old password lifted from a breach dump rather than a company name. The FTC's guidance then still holds now: the threats are false, and the correct response is to not pay.
Why Does Naming the Breach Make It Land?
Because it supplies the one checkable fact in an otherwise fabricated email, and it checks out. A recipient who reads "we obtained your data from Amtrak" can search their inbox, find the Amtrak breach notification they received in April, and conclude the rest of the message deserves the same benefit of the doubt. The scam borrows the trust of a real incident that a real company already confirmed.
Most coverage of this campaign leads with the ShinyHunters denial, which is the least interesting part of it. The shift worth noticing is where the proof of life moved. Old sextortion mail pasted your password into the subject line, a trick that decayed as password managers and forced resets spread. Naming the source breach does the same psychological work while requiring nothing but the leak's provenance, which never expires and never needs to be reset. It is a cheaper credibility token that ages better.
Which ShinyHunters Leaks Are Feeding This?
Eight are confirmed so far, and they span roughly a year of the group's extortion output. ShinyHunters spent 2025 running one of the broadest corporate data theft sprees on record, documented in detail by Krebs on Security. The largest single wave abused OAuth tokens stolen from the Salesloft Drift integration to reach roughly 760 Salesforce customer organizations in a ten day window in August 2025, an operation the FBI and CISA covered in a joint cybersecurity advisory tracking the actors as UNC6040 and UNC6395.
The individual dumps kept landing through 2026. Panera Bread's breach, which The Register covered in January 2026, put 5.1 million unique addresses into circulation alongside names, physical addresses and phone numbers. Amtrak followed in April with 2.1 million addresses plus customer support tickets. Gblock has tracked the same pattern through other victims, including the Sysco leak that added 2.7 million addresses to Have I Been Pwned and the Kodak breach covering 2.2 million records. Every one of those dumps is now permanent inventory for whoever wants it.
Why Is an Email Address the Hardest Thing to Rotate?
Because unlike a password or a payment card, it is wired into everything else you own. A leaked password takes 30 seconds to change. A compromised card gets reissued in a week and the old number dies. Your address is the login on dozens of services, the recovery anchor for your bank and your Google account, the string on your business cards, and the thing every contact you have already has saved.
That asymmetry is why breach dumps stay commercially useful long after the passwords in them are worthless. The Amtrak list will still be a valid targeting file in 2031. This is also why the same address keeps showing up across unrelated campaigns: infostealer collections, credential stuffing runs and scam mail all draw from overlapping pools, a dynamic visible in the 24 billion credential records dumped from infostealer logs. Each new leak doesn't replace the last one. It joins it.
Why Email Users Should Care
A leaked address is raw material. An address confirmed to belong to a person who actually reads their mail is a finished product, and it sells for considerably more. That gap is exactly what a tracking pixel closes. When your client renders a remote image in a message, it fetches that image from the sender's server, and the request itself reports back that the address is live, roughly when it was read and what device read it. The sender never needed you to click anything.
BleepingComputer's report doesn't say whether these particular sextortion messages carry open confirmation pixels, so treat that as unconfirmed for this campaign specifically. What is well established is the economics underneath it: bulk mail operators routinely embed pixels precisely to separate dead addresses from monitored ones before deciding who gets a follow up. If you open a scam email with remote images enabled, the worst realistic outcome isn't the fictional webcam video. It's your address getting promoted from a stale 2026 leak file to a verified, actively read inbox on a fresher list.
Gmail proxies remote images through Google's servers, which hides your raw IP address but still fires the fetch that confirms the open. Gblock blocks those pixels outright in Gmail so the fetch never happens and the sender learns nothing. If you want to see what one looks like before trusting a tool to handle it, Gblock's guide to detecting email tracking pixels in Gmail walks through finding one by hand.
What Should You Do If One Arrives?
Nothing the email asks for, and a handful of things it doesn't. The demand is automated and the deadline is theater, so the pressure to act inside 48 hours is the only real weapon it has.
- Do not pay. There is no video, the Bitcoin is unrecoverable, and payment marks your address as one that responds to extortion, which guarantees more of it.
- Do not reply, click links or open attachments. Any interaction is a signal, and a reply is the strongest one you can send.
- Turn off automatic loading of remote images, or block pixels entirely, so simply reading the message doesn't verify your address for the next list.
- Check Have I Been Pwned to see which of these breaches actually included you. It converts a vague threat into a known, bounded fact.
- Turn on two factor authentication or a passkey on your email account. The address itself is the recovery anchor for everything else, so it is the account worth hardening first.
- Use per service aliases for new signups. You cannot rotate your primary address, but you can stop giving it to every retailer that will eventually be breached.
- Report it to the FBI's IC3 or the FTC. Volume is what turns an annoyance into a documented pattern.
This will keep happening, and not because ShinyHunters is behind it. The group already got paid, or didn't, and moved on. What it left is eight or more public address lists that cost nothing to download and can be re monetized by anyone with a mail server and a Bitcoin wallet. The breach was the event. The lists are the aftermath, and the aftermath does not have an end date.
Sources: BleepingComputer, Have I Been Pwned, FTC Consumer Advice, FBI and CISA joint advisory on UNC6040 and UNC6395, 2025 IC3 Annual Report, Krebs on Security, and The Register.