July 28, 2026
That Email Has Your Real Password. You Weren’t Hacked.
A blackmail wave is quoting genuine passwords pulled from the ShinyHunters breach dumps and demanding $2,000 in Bitcoin, and the…
By S6 Tech
4 min read
A blackmail wave is quoting genuine passwords pulled from the ShinyHunters breach dumps and demanding $2,000 in Bitcoin, and the fifteen-minute fix that takes the whole bluff off the table costs nothing.
The bookkeeper at a nine-person insurance agency opened an email before her second cup of coffee. The subject line was her own password.
Not a password. Her password. The one she reused on a few sites, including one she could not quite remember signing up for. It was sitting in the subject line of an email from a stranger.
She opened it. The tone was calm, almost polite. The sender said he had slipped something onto her laptop months ago, that it had been quietly watching her through the webcam, and that he now held footage she would not want her contacts to see. Pay $2,000 in Bitcoin inside 48 hours and it disappears. Ignore him and everyone in her address book gets a copy.
She looked at the small camera dot above her screen. She thought about the fact that a stranger had her password.
Then she picked up her phone to work out how to buy Bitcoin.
What just happened
She had walked into a sextortion scam, the kind of email that threatens to leak an embarrassing video unless you pay. Researchers at Malwarebytes documented the current wave this week. The emails demand around $2,000 in Bitcoin, give you 48 hours, and claim to hold webcam footage. The detail that makes people pay is a real password, and researchers confirmed the addresses being hit had turned up in data stolen by ShinyHunters, the crew whose breaches filled leak sites through the spring.
The footage does not exist. The password is the whole trick.
Here is the mechanic in plain English. When a website you used gets breached, the attackers walk off with a list of email addresses and their passwords. Those lists get traded in bulk for years. A breach dump is one of them. A scammer loads it into a script, emails every address, and drops that address's own password into the message so it reads like proof of a hack.
It is like a stranger reciting your old street address off a mailing list, then claiming he is standing in your kitchen. The address is real. The kitchen is a lie.
Nobody should pay. Nobody should reply. But the leaked passwords that make this email land are also the fuel for something that is not a bluff, and that is the part that deserves your attention.
Why it feels like proof
The email is built to walk your fear up a ladder. Climb it one rung at a time and it falls apart.
They have your password. True. That rung is real. It came out of a website breach, though, not off your computer, and it is often years old. A password in a scam email proves a site you used was compromised at some point. It proves nothing about your laptop.
They are inside your email. Almost always false. Seeing your own address in the "from" line feels damning, but that field is trivial to forge. Check your sent folder: the message is not there, because it was never sent from your account. The one exception is if you reused that password on your work email and left an old door open, which the next section closes.
They have webcam footage. False. There is no malware, no recording, no camera access. That line is generated text, dropped into every email on the list.
So the ladder has one real rung, at the very bottom. The only question that matters is whether that leaked password is still in use anywhere. If it is, that is your actual risk, and it takes minutes to fix. If it is retired, the email is noise.
Most owners were never taught the difference that matters. A data leak and a break-in are not the same event. One means a password of yours is loose in the world. The other means someone is on your systems right now. This email is the first, working hard to feel like the second.
What you can actually do this week
- Send your team the script before the email does. Cost: $0. Time: 5 minutes. Message them today: "If you get an email that quotes one of your passwords and threatens to release a video, it is a scam built from an old website breach. Do not pay. Do not reply. Forward it to me. If that password is still used anywhere, change it there right now." An employee who reads this a week early deletes the email in five seconds. One who does not might wire $2,000.
- Block legacy authentication and change any reused password. Cost: $0. Time: 15 minutes. Legacy authentication is an old sign-in path that checks a password and never asks for a second step, the code or phone prompt that multi-factor authentication (MFA) adds. So a stolen password by itself opens the mailbox. Criminals fire leaked and common passwords at logins until one lands, and Microsoft's own analysis finds more than 97 percent of those attacks ride this exact path. In Microsoft 365, open the admin center, go to Conditional Access, and create a policy to block legacy authentication (Microsoft's step-by-step guide is here). In Google Workspace, disable access to less secure apps for everyone. Then change any password that showed up in one of these emails, everywhere it lives.
- Check your exposure and lock down your own domain. Cost: $0. Time: 30 to 60 minutes. Run your work email addresses through Have I Been Pwned to see which breaches you already sit in. Then confirm your domain has SPF, DKIM, and DMARC in place, three small settings that tell the rest of the internet which servers may send mail in your name, with DMARC set to quarantine or reject rather than monitor. Those records stop a scammer from sending email that wears your company's name to your own staff and customers. Many small businesses run only the weakest of the three.
If this was useful
I write S6 Ransomware Signal, a free weekly newsletter for small and mid-size businesses without a dedicated security team. Every Monday it takes the week's actual ransomware activity, strips out the jargon, and tells you what to do about it.
This week's full issue also covers the malware that builds itself inside your browser on fake crypto and trading pages, so nothing is ever saved to disk for antivirus to catch. It breaks down the regional health system across South Carolina and Georgia that a live attack knocked offline mid-week, and why a clinic that cannot pause to recover gets priced as one that will pay. And it gets into The Gentlemen crew now using AI to build their own ransomware, plus the one thing worth testing next month: a restore, not just a backup.
Subscribe here. It is free.
The passwords are leaking faster than the advice is updating. This is the update.