Share
CONSUMER ALERT - EMAIL EXTORTION

No, they do not have a video of you. The $2,000 Bitcoin sextortion email is a bluff

If you are reading this at two in the morning with that email open in another tab, here is the answer first: it is mass-mailed, it went to a very large list of addresses, and the sender has no footage of anything. You do not have to pay. You do not have to reply. BleepingComputer documented the current wave on July 25, 2026, and it is being sent to addresses lifted out of recent corporate breaches.

SafeBrowz Threat Research Security ResearchJuly 26, 20269 min read

The Brief

The email demanding $2,000 in Bitcoin over supposed webcam footage is a scam, and paying is the only move that can actually hurt you. No device of yours was accessed. The sender knows one thing about you, your email address, and they know it because a company you once signed up with was breached and the list was traded. Everything after that is a script sent to thousands of people at once. Do not reply, do not pay, do not click anything in the message. Delete it, then spend ten minutes on the thing that is genuinely worth doing: find out which breach exposed you, and change any password you reused.

Not sure about a link? SafeBrowz checks it before the page can load. Add to Chrome, free Get the free Android app or scan a URL now →

What the email says, and where the address came from

The wave running now arrives from a sender display name of either "ShinyHunters" or "You've Been HACKED", under the subject line "Information about your online security". Lawrence Abrams reported it for BleepingComputer on July 25, 2026. The body opens with a line designed to make your stomach drop: "We are the ShinyHunters hacking group. A few months ago, we gained access to your devices and started monitoring your online activities." Then the demand. $2,000 in Bitcoin, 48 hours.

According to that reporting, the address lists were drawn from breaches ShinyHunters had previously leaked, covering names including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread and McGraw Hill. Checked against Have I Been Pwned, those eight incidents are dated between October 2025 and April 2026, so the data is recent enough to feel current. Some copies of the email name the specific company whose breach your address came out of, which is the entire trick. It reads like inside knowledge. It is a mail-merge field.

One detail is worth sitting with. BleepingComputer contacted the ShinyHunters group directly, and the group denied any involvement. So the name at the top, the part meant to make it credible, is itself borrowed. Somebody holding leaked contact lists is wearing a notorious brand because a scary name raises the payment rate. That is the whole operation.

How they know your email, and nothing else

Here is the mechanism, in the order it happens. A company you gave an address to gets breached. The stolen records, usually addresses and sometimes old password hashes, are sold, traded, then dumped where anyone can pick them up. Somebody takes the list, writes one message, and sends it to every address on it. That is the sum total of the "hack" described in the email.

Nothing in that chain involves your computer, your phone, your camera or your browsing. They do not know whether you own a webcam, whether you have ever visited an adult site, or whether you are eighteen or eighty. They are betting that across a very large list, some fraction of recipients will read a generic accusation and fill in the specifics from their own memory.

The FBI documented this pattern a decade ago. IC3 alert I-060116-PSA, Extortion E-mail Schemes Tied to Recent High-Profile Data Breaches, notes that "fraudsters quickly use the news release of a high-profile data breach to initiate an extortion campaign", with victims "typically given a short deadline" and asked to pay in Bitcoin. That was 2016. The machine is unchanged, because it never needed to change.

The tell that closes the case: the email never describes anything. Someone holding real footage would name a date, a site, a device. This one gestures at "your online activities" and lets your imagination do the work. Vagueness is not caution on the sender's part. It is the absence of anything to be specific about, and it is the same hollowness that gives away any email pretending to be something it is not.

The old password in the email is not evidence of a hack

A long-running variant puts a real password of yours in the subject line or the first sentence. It is the most convincing thing these emails ever do, and it proves nothing about your devices.

Breached datasets frequently contain passwords, in the clear or in weak hashes that get cracked later. If your address appeared in one of those, so did whatever password you were using on that site at the time. It gets pasted in because it feels impossible to fake. It is not impossible. It is just old.

The FTC said the same thing plainly in its consumer alert "Scam emails demand Bitcoin, threaten blackmail" (April 29, 2020): the scammers "may say they have access to your computer or webcam, or installed clever software to defeat you. That's all talk." What they may genuinely have, the FTC goes on, is one of your old or recent passwords, included in the message to prove a point it does not actually prove. The FTC's advice on the demand itself is four words long. "Stop. Don't pay anything."

What that password does mean is a real, fixable problem: if you are still using it anywhere, that account is exposed to credential stuffing, which has nothing to do with sextortion and everything to do with someone quietly logging into your email. Change it. That is the useful signal buried in a worthless threat.

Check the link, for the versions of this that carry one

Many of these emails contain no link at all, and for those a URL scanner is honestly useless, so we will not pretend otherwise. The variants that do carry one are a different matter: a "view your recording" page that wants a login before it shows you anything, or a crypto payment portal built to walk you through sending the money. SafeBrowz is a free browser extension for Chrome, Firefox and Edge, with Safari pending, plus an Android app, and its job is to flag those pages the moment they open, before you type or send anything. The free tier runs all three detection layers, with the AI deep scan limited to one scan a day; Premium lifts that for $14.99 a year.

Chrome Add to Chrome Firefox Add to Firefox Edge Add to Edge Google Play Get it on Google Play

Find out what actually leaked, in about five minutes

This is the part that repays the anxiety. The email is worthless, but the exposure behind it is real and checkable.

Go to haveibeenpwned.com, type your address, and read the list of breaches it appears in. Each entry names the company, the date and the categories of data taken, so you can usually see which breach the sender's list came from. Do the same for every address you use, including the old one you forgot about.

Two cautions. An address showing up in ten breaches is normal in 2026 and is not a sign that you personally were targeted. More importantly, scammers noticed how many people go looking after a breach headline, and they run fake "check if you were affected" pages to harvest exactly those searches. We took one apart in our write-up of the 24-billion-record breach "check if affected" lure. Type the address of a checker you trust yourself. Never arrive at one from a link in an email about a breach.

The next ten minutes, in order

Do not reply, and do not pay. A reply confirms a live human reads that mailbox, which is worth money on its own. Payment marks you as someone who pays, and Bitcoin does not come back.

Do not click anything inside the message, including an unsubscribe link. In a message like this the only purpose of a link is to load a page or confirm you opened it.

Change any password you have reused, starting with the mailbox that received the email. Your email account is the master key to every password reset you own, so it goes first.

Turn on two-factor authentication on that mailbox and on anything financial. Use an authenticator app rather than SMS where you have the choice, for the interception reasons we covered in the SMS-to-TOTP upgrade guide.

Report it, then let it go. In the United States, file at ic3.gov with the keyword "Extortion E-mail Scheme" in the complaint, as the FBI's own alert asks, and at reportfraud.ftc.gov. Elsewhere, use your national fraud reporting body. Reporting will not get anyone arrested this week, but it is how campaigns like this one get counted at all.

Then delete the email and stop rereading it. Nothing happens when the deadline passes, because there was never anything to release. If you did send money, the sequence for clawing it back is in our step-by-step recovery guide.

Why paying is the one thing that makes it worse

The numbers here are unusually clear, and they come from the FBI's own annual accounting. In the 2025 IC3 Annual Report, extortion was the most-reported cyber-enabled fraud type in IC3's 2025 data, with 89,129 complaints, ahead of investment fraud at 72,984. Yet reported losses to extortion came to $122,499,133. Against total reported losses of $20.877 billion across 1,008,597 complaints, extortion accounts for well under one percent of the money.

That shape is the statistical signature of a bluff. Enormous volume, trivial takings. Investment fraud produced fewer complaints and $8.6 billion in losses, because those victims were worked individually. Extortion tops the cyber-enabled fraud complaint table and collects almost nothing, because it is one script sent to an enormous list and almost nobody pays. You would be joining a very small minority and funding the next send. The operators are not solving a puzzle about you. They are running a spreadsheet.

One more assumption worth deleting. The same report's sextortion breakdown for 2025 shows the largest age bracket by complaint count is 20 to 29, with 22,061 submissions, ahead of 30 to 39 at 11,855 and under-20s at 11,316, out of more than 75,000 sextortion submissions in total. This is not a thing that only happens to teenagers. If you are an adult who got one today, you are in the biggest group in the data.

The rarer case: when an extortion message is real

Honesty matters more than reassurance here, so: a small number of extortion cases are genuine, targeted and serious. The distinction is not subtle once you know where to look.

A real case is specific and current. It references material that actually exists, because you sent it, usually to someone you were talking to. It names the conversation, the platform, the day, and it usually continues on the app where the contact started rather than arriving cold by email. The FBI's guidance on financially motivated sextortion, which describes the interaction-based crime aimed largely at children and teenagers, is the version to read for that, and it is an emergency rather than an annoyance.

A mass-mailed case is generic and backdated. It never names anything checkable. Its only real information about you leaked from a company, not from you. It arrives at an address rather than at a person, and it always carries a countdown.

One question separates them: has anything actually been exchanged between you and another human being? If the answer is no, and the message can only cite a company breach, you are holding the mass-mailed version. If the answer is yes, stop negotiating, preserve the messages, and report it at ic3.gov or to your local police. For a minor, contact the FBI immediately. Paying is the wrong move in both cases. The FBI's own guidance on the targeted version notes that predators sometimes distribute the images even when the victim pays, and that cooperating rarely stops the blackmail.

How SafeBrowz reads the pages this scam sends people to

SafeBrowz runs a 3-layer detection architecture: Local + APIs + AI. Scope first, because it is unusually narrow on this one.

The honest limit: when the extortion email carries no link at all, and many do not, SafeBrowz does nothing for you and no browser tool can. It does not sit in your inbox. What it covers is the second step, for the variants that have one.

  • Layer 1 - Local detection: 60+ URL patterns and a 550+ brand database run inside the extension before the page paints. The link variants here point at a fake "view the recording" viewer wearing a mail or storage provider's branding, or a payment page borrowing an exchange logo. A tracked brand name in a hostname that brand does not own trips the impersonation signal locally, no network call needed.
  • Layer 2 - API checks: the domain is cross-referenced server-side against Google Safe Browsing, PhishTank, URLhaus, ScamAdviser feeds and a 30+ scam TLD watchlist. Extortion infrastructure is disposable by design, registered in batches on cheap TLDs and burned within days, and that churn is a weighted signal in itself.
  • Layer 3 - AI deep scan (Premium): AI content analysis via our proxy reads the page as an investigator would. A countdown, a fixed crypto sum, a wallet address, threat language and a login form on a domain registered last week is a combination that earns a danger verdict in seconds, including on pages too new for any blocklist to have seen.

It cannot unsend a payment and it cannot stop the email arriving. It can put a hard warning between you and a payment portal at the second the fear is doing the deciding.

Detection signatures are derived from threat-intelligence research and our internal brand database, not from user browsing data. SafeBrowz does not store per-user browsing history.

🛡 LIVE CHECK

Check a link from an extortion email, without opening it

If the message you received contains a link, copy it and paste it here rather than clicking. Our 3-layer engine (Local + APIs + AI) returns a verdict in about three seconds. Free, no signup. If there is no link in your email, there is nothing to check, and that is good news.

Full scan with deep AI analysis → · No URL is logged to your identity.

Frequently asked questions

Does the sextortion email mean my computer or webcam was hacked?

No. The sender obtained your email address from a breached company's data, not from your device. BleepingComputer reported on July 25, 2026 that the current wave, sent under the display names "ShinyHunters" and "You've Been HACKED" with the subject "Information about your online security", uses address lists drawn from breaches ShinyHunters had previously leaked, including Amtrak, Substack, ADT and Panera Bread. There is no recording, no monitoring software and no access to your camera. The proof of that is in the email itself: it never describes a single specific thing about you.

Should I pay the $2,000 Bitcoin demand?

No. The FTC's guidance on these emails is "Stop. Don't pay anything. Delete the message. It's a scam." Bitcoin payments cannot be reversed, and paying marks your address as belonging to someone who pays, which usually brings more demands rather than fewer. The FBI's 2025 IC3 Annual Report puts reported extortion losses at $122.5 million across 89,129 complaints, well under one percent of the year's $20.877 billion in total reported losses, which is what it looks like when almost nobody pays a mass-mailed threat.

The email had one of my real passwords in it. How did they get it?

From a data breach, not from your machine. Breached datasets often include passwords, and those lists circulate for years. The FTC noted in April 2020 that scammers may genuinely know one of your old or recent passwords and include it to look credible, while claims of webcam access are "all talk". Treat it as a reminder rather than a threat: if you still use that password anywhere, change it now, starting with your email account, and turn on two-factor authentication.

Is this really the ShinyHunters hacking group?

Apparently not. BleepingComputer contacted the ShinyHunters extortion group about this campaign and the group denied any involvement. The name is being borrowed by whoever bought or downloaded the leaked address lists, because a recognisable name raises the payment rate. It is the same reasoning behind every scam email that wears a familiar brand, and it means the signature at the top tells you nothing about who actually sent it.

I already replied or paid. What should I do now?

Stop all contact and do not send a second payment, whatever the follow-up says. Report it at ic3.gov with the keyword "Extortion E-mail Scheme" and at reportfraud.ftc.gov, keeping the original email with its headers and any wallet address. If you paid from an exchange account rather than a private wallet, contact that exchange's fraud team. Then secure the mailbox that received the email with a new password and two-factor authentication, and expect contact from people offering to recover your funds for a fee, which is its own scam.

Last updated 2026-07-26

Related SafeBrowz coverage