Scammers are using ShinyHunters' data leaks to send sextortion emails demanding $2,000 in Bitcoin. Learn how the scam works and what to do if you get one.
If you've received an alarming email demanding $2,000 in Bitcoin or else your private browsing history gets exposed, you're not alone. A new wave of sextortion scams is hitting inboxes across the United States, and it's all thanks to data leaked by the notorious ShinyHunters extortion group.
These scammers are getting smarter. They're using email addresses and old passwords stolen from major data breaches to make their threats feel personal. The goal? To scare you into paying up before you have a chance to think.
### How the Scam Works
The email usually lands in your inbox with a subject line like "I know what you did" or "You've been hacked." Inside, the scammer claims they have access to your webcam and know the sites you visit. They demand $2,000 in Bitcoin sent to a specific wallet address, often with a deadline of 24 to 48 hours.
Here's the kicker: they include one of your old passwords to prove they're legit. That password came from a data breach, not from hacking your computer. But it's enough to make most people panic.
- The email address used to contact you was exposed in a breach.
- The password shown is from an old account, not your current one.
- The threat is empty, but the fear is real.
### Why ShinyHunters Is Involved
ShinyHunters is a group known for stealing and leaking massive databases from companies like Microsoft, Tokopedia, and Wattpad. They've dumped millions of records online, including email addresses, usernames, and passwords. Other threat actors grab these leaks and use them to launch targeted scams.
This isn't a new technique, but it's becoming more common as data breaches pile up. The more breaches happen, the more ammunition scammers have.
### What You Should Do If You Get One
First, don't pay. Sending Bitcoin only confirms your email is active and makes you a target for future scams. Instead, follow these steps:
- Check the password they included. If it's old and reused, change it immediately across all accounts.
- Enable two-factor authentication on your email and financial accounts.
- Report the email to the Federal Trade Commission (FTC) at ReportFraud.ftc.gov.
- Delete the email without replying.
### Protecting Yourself Going Forward
The best defense is prevention. Use a password manager to generate unique, strong passwords for every account. Regularly check your email address on sites like Have I Been Pwned to see if it's been compromised.
Also, consider using an antidetect browser for sensitive online activities. These tools mask your digital fingerprint, making it harder for scammers to link your data across platforms. While antidetect browsers won't stop sextortion emails, they reduce the amount of personal info exposed in breaches.
### The Bottom Line
Sextortion scams are scary, but they're mostly bluff. The scammers rely on shame and urgency to get you to act without thinking. Take a breath, verify the facts, and never send money to someone who threatens you.
Stay informed, stay skeptical, and keep your passwords unique. That's the best way to shut down these scams before they start.