ShinyHunters-Impersonation Sextortion Scam Abuses Emails From 8 Prior Data Leaks, Demands $2,000 — Threadlinqs Intelligence
As of 2026-07-25, ShinyHunters-Impersonation Sextortion Scam Abuses Emails From 8 Prior Data Leaks, Demands $2,000 is a low-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1685 · Severity: LOW · Status: ACTIVE · Category: PHISHING
An unidentified threat actor is running a mass sextortion email campaign, active since April 2026, that falsely claims affiliation with the ShinyHunters extortion brand (which publicly denies
Since April 2026, victims whose email addresses appear in prior breach dumps have received unsolicited extortion emails with the subject line "Information about your online security," sent from spoofed sender display names reading "ShinyHunters" or "You've Been HACKED." The message falsely claims the sender gained device access "a few months ago" via an exploit reaching the victim's microphone, camera, keyboard, browsing history, photos, conversations, and contact list, and that the victim was recorded visiting adult websites. It demands $2,000 in cryptocurrency (BleepingComputer's sampled emails cite Bitcoin; a separately sampled message analyzed by MyAntiSpyware.com cites Litecoin, wallet ltc1qfpjl5999jwpjq7kvyjld9akaspx69qaxvxrf20) within 48 hours, threatening to send the alleged footage to the victim's contacts, and instructs the victim not to contact police or reset devices -- a classic isolation tactic. No independent technical evidence of device or account compromise has been identified in any reporting; the scam's sole leverage is that the target's real email address and the name of a company that previously suffered a breach appear together, lending superficial plausibility.
All eight named prior breaches occurred within the broader 2025-2026 ShinyHunters/Scattered-LAPSUS$-Hunters (SLSH) extortion wave, which primarily abused Salesforce CRM and Salesforce Experience Cloud environments plus stolen Salesloft Drift OAuth/refresh tokens to exfiltrate customer PII at scale: Betterment (breached 2026-01-09 via vishing/social-engineering against a third-party Salesforce vendor, ~1.4M customer records, no passwords exposed), Substack (unauthorized access window opened ~October 2025, detected 2026-02-03, ~700K records -- reporting on this breach does not explicitly attribute it to ShinyHunters, unlike the other seven), Hallmark Cards/Hallmark Plus (claimed by ShinyHunters 2026-03-31, ~7.9M Salesforce records, leak deadline set for 2026-04-02), Amtrak (claimed by ShinyHunters ~2026-04-11/12 via compromised Salesforce, ~2.1M confirmed accounts added to Have I Been Pwned 2026-04-17, ShinyHunters alleged up to 9.4M records), ADT (Salesforce breached "days after" Amtrak per Techlicious, ~5.5M records via Salesforce Experience Cloud misconfiguration), Panera Bread (~5.1M accounts via Salesforce Experience Cloud misconfiguration), CarGurus (named victim, Salesforce-linked), and McGraw Hill (publicly confirmed 2026-04-14 following a ShinyHunters extortion threat; McGraw Hill characterized exposed data as "limited and non-sensitive" while ShinyHunters claimed 45M PII records, a claim not independently verified).
ShinyHunters (aliases/overlapping clusters tracked as UNC6240, UNC6395, UNC6661, UNC6671, UNC6040, and converging with Scattered Spider/Lapsus$ under the "ShinySp1d3r"/SLSH umbrella) publicly denied any role in the sextortion emails when contacted by BleepingComputer. Betterment separately confirmed awareness of the scam, called it "a common extortion scam," and advised customers not to pay. Victim reports have surfaced on Reddit, Facebook groups, and the Better Business Bureau. The pattern matches the long-running, low-technical-sophistication "automated sextortion" scam family (e.g., the 2018 "I know your password" wave and the pattern documented nationally by New York State Police), refreshed here with a topical, credible-sounding brand name and genuinely leaked email/company pairings to raise conversion rates. Severity is assessed LOW because no technical intrusion, malware, or account takeover is confirmed -- the risk is financial/psychological (fear-driven cryptocurrency payment) rather than system compromise -- but the campaign is tracked for SOC awareness/notification purposes and for correlation against the eight source breaches and the wider ShinyHunters activity cluster.
Target sectors: financial-services, transport, retail, home-security, food-service, publishing, education, consumer
Target regions: united states of america
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, LOW, threat intelligence, cybersecurity, T1589, T1597, T1585, T1588, T1583, T1566, T1190, T1078, T1598, T1528