Threat actors are impersonating the ShinyHunters hacking group to send fraudulent sextortion emails demanding $2,000 in Bitcoin by leveraging personal email addresses obtained from previous corporate data breaches.
Key Points
- Scammers are using data from breaches at companies including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill.
- The emails falsely claim that attackers have compromised the recipient's devices, cameras, and microphones to record intimate activity.
- Despite the threats, there is no evidence that the senders have actually accessed any devices or installed malware on victims' systems.
- The ShinyHunters group has officially denied any involvement in this ongoing extortion campaign, which reportedly began in April.
- Security experts and affected companies advise recipients to delete the messages immediately and avoid paying any ransom demands.