Millions of accounts hit in huge sextortion email campaign

email security
(Image credit: Shutterstock.com / Nicescene)

A malicious email campaign looking to blackmail victims has affected millions of innocent users around the world, a new report has found.

Researchers from Cofense Labs have published a database of over 200 million compromised accounts hit by a wide-ranging campaign that is looking to spread malware and rake in ransoms from innoncent victims.

The campaign used a “for rent” botnet was used primarily to send sextortion emails, which look to extort money from the victims by threatening to release sexually-explicit content reportedly accessed on their device.

'Spray and pray'

Cofense Labs analysed over seven million email addresses impacted by sextortion in the first half of 2019 alone, finding that more than $1.5M in payments had been made to bitcoin wallets associated with sextortion campaigns this year. Many of these accounts were included in recent data breaches, but some were as much as ten years old.

The company says that poor password hygiene, including infrequent changes and reuse across multiple sites, is worsening the issue. Cofense is advising that anyone with emails included in the database should immediately change the passwords for any accounts linked to that address - and if a sextortion email is received, to not respond to the email or pay the ransom.

“This botnet is not infecting computers to acquire new data sets – it is a true “spray and pray” attack reusing credentials culled from past data breaches to fuel legitimacy and panic through sextortion scams,” said Aaron Higbee, Cofense Co-Founder and CTO. 

“If your email address is found in a target list used by the botnet, it’s highly likely you will receive a sextortion email – if you haven’t already. We felt it was critical to get this information out. We hope that victims receiving a sextortion email will find our resource center so they can avoid the anxiety and stress of trying to figure out whether to pay a bitcoin ransom.”

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection