Skip to content
Data Breach

Scammers Pose as ShinyHunters to Blackmail Data-Breach Victims With Fake Webcam Videos

Victims of recent data breaches are receiving alarming emails that claim hackers recorded them through their webcams. The messages borrow the ShinyHunters name and cite a recipient’s real email address, turning a familiar sextortion script into a more personal and intimidating fraud. The goal is sim...

· Jul 28, 2026 · 4 min read · 👁 1 views

Victims of recent data breaches are receiving alarming emails that claim hackers recorded them through their webcams.

The messages borrow the ShinyHunters name and cite a recipient’s real email address, turning a familiar sextortion script into a more personal and intimidating fraud.

The goal is simple: pressure recipients into sending Bitcoin before they have time to assess the claim.

Rather than relying on malware, the campaign abuses information already exposed in breaches. Scammers use leaked email addresses to make their claims appear credible, then allege they installed spyware after a victim opened a harmful link.

The emails falsely state that the attackers gained access to webcams, microphones, messages, contact lists, and browsing activity.

Analysts at Malwarebytes noted that the emails are a bluff, with no malware, recording, or credible proof supplied to support the claims.

Malwarebytes said in a report shared with Cyber Security News (CSN) that scammers are exploiting leaked contact data to strengthen their social-engineering pressure.

The scam illustrates how breach fallout can continue long after stolen information is published or traded.

A leaked address does not prove that a criminal controls a victim’s device, but it can create enough doubt to make a threatening email feel authentic.

Readers tracking the group’s recent activity can also review the reported EY breach claimed by ShinyHunters for broader context.

Scammers Pose as ShinyHunters

The emails typically introduce the sender as ShinyHunters and say the group accessed the victim’s account through a breached organization. One example referenced an Amtrak account, then claimed an exploit was installed across the recipient’s phone and other devices.

It threatened to send supposed explicit videos to family, friends, and colleagues unless a $2,000 Bitcoin payment was made within 48 hours.

Researchers reported that addresses linked to breaches involving Amtrak, Hallmark, ADT, Substack, Betterment, CarGurus, Panera Bread, and McGraw Hill have been used in the campaign.

A California community college also warned people affected by a Canvas-related incident, where targeted addresses had previously appeared in data attributed to ShinyHunters.

The reported Canvas LMS data breach shows why exposed contact details remain valuable to fraudsters. The real ShinyHunters group denied involvement when contacted about the sextortion operation, according to the report.

No activity on their Bitcoin address (Source - Malwarebytes)
No activity on their Bitcoin address (Source – Malwarebytes)

That denial does not reduce the danger of the emails themselves, because impersonation lets unrelated criminals exploit an established threat actor’s reputation.

The apparent payment address in the sample showed no activity, further suggesting that the campaign relies on panic and volume rather than proven device compromise.

How Recipients Should Respond

Recipients should not reply, negotiate, or send money. A response tells the sender that the email account is actively monitored and may lead to more harassment.

Victims should slow down, discuss the message with someone they trust if needed, and remember that professional-looking wording, including text polished with AI tools, is not evidence that the allegation is real.

Attachments should also be treated carefully. Sextortion emails often contain no proof, and an attachment may be used to deliver malware or make an empty threat look more convincing.

Email scam (Source - Malwarebytes)
Email scam (Source – Malwarebytes)

Anyone who sees an old or current password in a message should immediately change it everywhere it remains in use and enable two-factor authentication, as explained in coverage of the Astaroth 2FA phishing kit.

The safest response is to delete the email, report it as spam, and avoid clicking links or opening attached files.

Concerned users can independently check whether their information appeared in known breaches, but they should not engage with the blackmailer to seek confirmation.

Digital sextortion remains part of a wider fraud problem, alongside phishing and business email compromise, highlighted in reporting on the sharp rise in cyber attacks.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you