What Are the Fake ShinyHunters Sextortion Emails?

A wave of sextortion emails has been circulating in 2026 claiming to be from 'ShinyHunters,' a real hacking group known for major data breaches. The emails claim the sender has access to your devices, has recorded compromising video through your webcam, and has stolen your contacts. They demand a Bitcoin ransom — typically $500 to $2,000 — to prevent the footage from being shared with your contacts.

The threats are almost entirely fabricated. But the use of a real hacking group's name, combined with real breach data, makes these emails terrifyingly convincing — and that's exactly the point. The scammer doesn't need to actually have anything on you. They just need you to believe they do.

These emails are sent in mass batches to millions of addresses at once. The scammer's entire strategy is volume: send enough emails, reference enough old passwords, and a small percentage of recipients will panic and pay.

How the Scam Works

The scammer obtains email addresses and associated personal data from previous data breaches — names, passwords, phone numbers, and sometimes partial account details. This data is widely available on the dark web from hundreds of breaches over the past decade.

They send a mass email claiming to be from ShinyHunters. The email references a real password the victim has used in the past — obtained from a breach — as 'proof' that the sender has access to your device. This is the most effective psychological trick in the scam: seeing a password you recognize makes the threat feel real.

The email claims that malware was installed on your device, that webcam footage was captured, and that the footage will be sent to all your email and social media contacts unless a Bitcoin ransom is paid within 24 to 48 hours. The email includes a Bitcoin wallet address and sometimes a QR code for easy payment.

In reality, the scammer has no malware on your device, no webcam footage, and no access to your contacts. They have an email address and an old password from a breach — nothing more.

Why the Threats Are Almost Always Empty

The core claim — that the scammer has webcam footage and control of your device — is almost always false. Here's how to reason through it:

If a hacker had real malware on your device, they wouldn't need to email you and ask for Bitcoin. They could simply drain your bank account, steal your crypto, or sell your data directly. The fact that they're asking for a ransom is itself evidence that they don't have the access they claim.

The 'proof' password is from an old data breach, not evidence of current device access. If you've ever used that password on a website that was breached — and most people have — it's available in breach databases that anyone can access. The scammer simply matched your email to an old password from a breach database.

The ShinyHunters name is used for credibility, not because the real group is involved. The actual ShinyHunters group is known for stealing and selling corporate data, not sending individual sextortion emails demanding Bitcoin. Using a famous hacking group's name is a scare tactic, nothing more.

What to Do If You Receive One

Do not pay the ransom. Paying confirms two things to the scammer: that your email address is active, and that you're someone who will pay when threatened. This marks you as a target for future scams — once you pay, the demands often escalate.

Do not reply to the email. Do not click any links or download any attachments — some versions include malware payloads alongside the sextortion threat. Change the password that was referenced in the email — if you still use it anywhere, it's compromised from the original breach.

Run a malware scan on your devices for peace of mind, though actual infection is extremely unlikely from this type of scam. Cover your webcam if it makes you feel safer, but understand that the footage claim is almost certainly fabricated.

Report the email to the FTC at reportfraud.ftc.gov and to the FBI's IC3 at ic3.gov. You can also report it to your email provider — most providers have a 'report phishing' button that helps filter future copies.

How to Protect Yourself Going Forward

The best defense against sextortion emails is understanding how they work — and now you do. Here are additional steps to protect yourself:

1. Use unique, strong passwords for every account. A password manager makes this practical. If every account has a different password, a breach on one site doesn't give scammers a 'proof' password to use against you on another.

2. Enable two-factor authentication on all important accounts. Even if a scammer has your password, they can't access your account without the second factor.

3. Check haveibeenpwned.com to see which data breaches have exposed your email and passwords. Knowing what's out there helps you understand what scammers might reference.

4. Treat any email that references an old password as a scare tactic, not proof of current access. The password is from a breach, not from your device.

5. If the email includes a link claiming to show 'your compromised data' or 'evidence,' do not click it. Run it through Scam Detective first — a $1 URL check can confirm whether the link leads to a phishing page or malware download. For more on email-based scams, read our guide on fake purchase alert scams.