One of your employees gets an email. It contains their real home address, their real phone number, and a claim that the sender has recorded them watching explicit content. The email demands $2,000 in Bitcoin. Delete it and move on? Maybe. But what happens when the next one lands in your inbox, and it feels just as real?
According to BleepingComputer, this is exactly what is happening right now. Attackers are using data stolen in ShinyHunters breaches to fuel a large-scale sextortion campaign targeting real people with verified personal details. The $2,000 demand is not random. It is calculated to feel like a painful but payable amount, one that many people would quietly hand over rather than explain the situation to a spouse or employer.
Who Is ShinyHunters and Why Does It Matter Here
ShinyHunters is a well-known threat group responsible for some of the largest data breaches of the past few years. Their targets have included Ticketmaster, Santander Bank, and hundreds of other organizations. The stolen records include names, email addresses, phone numbers, physical addresses, and in many cases partial financial data.
That data does not disappear after a breach. It gets sold, resold, and eventually ends up in the hands of criminal groups running exactly this kind of campaign. The ShinyHunters leaks have put hundreds of millions of personal records into circulation. Some of your employees are almost certainly in those databases.
Why This Wave Is Different From Old Sextortion Spam
Older sextortion emails were easy to spot. They were vague, badly written, and contained no personal details. Your spam filter caught most of them.
This round is different. Because the attackers are pulling from real breach data, the emails arrive with accurate information. A message that includes your employee's actual street address and their current phone number does not feel like a generic scam. It feels like a credible threat. That psychological shift is the whole point.
The emails also tend to reference a real password the target used at some point, sourced from older credential leaks. That detail alone has caused thousands of people to pay up, assuming the claim must be true.
What the Risk Looks Like for a Canadian SMB
Your business faces two distinct problems here.
First, your employees are targets as individuals. If someone on your team pays $2,000 quietly, that is their personal loss. But if they engage with the attacker, respond from a work device, or click anything in the email, they can expose your network. Sextortion emails are increasingly used as a delivery mechanism for credential harvesting and malware.
Second, if any of your staff used a work email address when they signed up for a breached service, their corporate credentials may be in the same leaked datasets. Attackers can use that to attempt account takeovers on your Microsoft 365 environment, your VPN, or your line-of-business applications.
What We Recommend
The most useful thing you can do right now is tell your team this is happening. Many people who receive these emails feel too embarrassed to report them. Making it normal to flag suspicious email is the fastest way to catch a real threat before it escalates.
- Brief your staff this week. Let them know sextortion emails using real personal data are circulating. Explain that paying accomplishes nothing and that receiving one does not mean anything was actually recorded. Encourage anyone who gets one to report it immediately without fear of judgment.
- Check your domains against breach databases. Tools like Have I Been Pwned (haveibeenpwned.com) let you check whether email addresses from your domain have appeared in known data breaches. If you find hits, those accounts need password resets and MFA enabled immediately.
- Enable MFA on everything that touches your business. Microsoft 365, your VPN, your banking portal, your cloud storage. If an attacker has a real email and a recycled password, MFA is what stops them from getting in.
- Review your email filtering rules. Make sure your Microsoft 365 or Google Workspace environment is flagging external emails that contain Bitcoin wallet addresses or payment demands. These are signals a modern spam filter should catch.
- Do not pay and do not respond. Engaging with the sender confirms your address is active and often triggers a second, more aggressive demand.
The Bigger Pattern Worth Watching
This campaign is a reminder of something we tell our clients regularly. A data breach at a company you have never heard of, affecting a service your employee signed up for years ago, can land in your inbox as a direct threat today. Breach data has a long shelf life. The ShinyHunters leaks are years in the making and the damage is still accumulating.
The practical answer is to treat credential hygiene as an ongoing habit rather than a one-time project. Unique passwords for every service, a password manager, and MFA across the board closes most of the attack surface these campaigns rely on.
If you want us to run a breach exposure check on your domain or review your current email filtering setup, reach out to our team. It is a straightforward process and it gives you a clear picture of what is actually out there with your name on it.
Soft Computers