In my spam mailbox today -
Note: It is actually true that Shiny Hunters (the real ones) gained access to the parent company (Carnival) of the Holland America cruise I went on eleven years ago (and I have had an increase in spam since then) but the rest of the email follows the exact same pattern as other spam emails that try to extract bitcoin from people. It just comes from some random having a go.
If you get one of these you can delete it / ignore it and report the bitcoin wallet to Chain Abuse. In the UK you can send it to Action Fraud.
- - - - -
From: You've been HACKED <fxuzn@na.commufa.jp> <-- note it's possible that this is an entirely innocent email address that has been exploited, but I've included it for completeness.
Subject: Information about your online security
Hello,
We are the ShinyHunters hacking group.
A few months ago, we gained access to your devices and started monitoring your online activities.
What happened:
We gained access to the Carnivalcorp.com database where you have an account and easily accessed your email.
You weren't very careful about the links you opened.
A week later, we installed an exploit on your devices, including your phone, giving us access to your microphone,
camera, keyboard, and all your data.
We have your photos, browsing history, conversations, and contact list.
Among other things, we discovered that you frequently visit adult websites and watch explicit videos.
We managed to record you and created videos of you pleasuring yourself.
With a few clicks, we can share these videos with your friends,
colleagues, and family or even make them public.
Proposal:
Send us $2000 in Bitcoin to the following wallet:
bc1qzuk2m6hvt7cnu49mhwxhcx26d4gz0vsak6vdva
You have 48 hours from the moment you open this email.
Once the payment is received, we'll remove the malware from your devices.
What you should NOT do:
Do not reply (email was sent from a hacked account).
Do not contact the police or anyone else—we'll release the videos along with other stuff all over the internet.
Do not try to reset your devices—everything is stored on remote servers.
What you don’t need to worry about:
We will see your payment immediately—the wallet is generated specifically for you.
We will not share your videos or other things after payment—there is no reason to continue causing problems.
Don't play with us!
REF# : 89949