FBI: Hackers target online accounts to steal nude photos

FBI

The FBI warns that cybercriminals are targeting adults’ and children’s social media and other online accounts to steal sexually explicit images or videos.

As the law enforcement agency explained in a public service announcement published this week, the attackers may use the stolen content to blackmail the victims or try to sell it on criminal marketplaces.

They may also share the victims’ personal information (including names, dates of birth, emails, phone numbers, and social media usernames) with other criminals, who can use it to pressure them into providing additional private images and videos through sextortion.

image

Sextortion is a form of online blackmail in which cybercriminals threaten victims with publicly leaking nude images and videos they stole (through hacking) or obtained (through coercion). In some cases, they may also demand payment not to leak the explicit content online or share it with the targets’ family and friends.

“Once the sexually explicit content is stolen, SE actors post or sell it to criminal marketplaces, which often includes personal information about the victim and typically without their knowledge,” the FBI warned.

“As a result, victims often face re-victimization through harassment, sextortion, stalking or other targeted attacks, such as advertising stolen content on a victim’s own social media page.”

Student-athletes also targeted by sexual exploitation schemes 

The same day, the FBI and the National Collegiate Athletic Association (NCAA) have also warned that cybercriminals are targeting student-athletes’ online accounts in similar sexual exploitation schemes and asked coaches, compliance staff, and athletic department leadership to raise awareness within their schools and communities.

It also told potential victims not to reply to text messages or emails asking them to provide verification codes or click password reset links and advised against storing explicit photos or videos on social media accounts or Internet-accessible sites. Additionally, it recommended using complex passwords and enabling multi-factor authentication whenever possible.

“The FBI has identified several indicators associated with these schemes, including, unsolicited text messages claiming an account will be disabled absent a verification code and unsolicited emails referencing a new login with an embedded link to reset a password,” it said.

“The FBI advises that a legitimate platform or service will not request a verification code, temporary password, or PIN reset code from an account holder. Utilizing passwords and PINs that do not include personal information, such as names, dates or birth and other easily accessible information, can also help lower the risk of victimization.”

While the FBI hasn’t shared what prompted this alert, the bureau often issues public service announcements after noticing an increase in the incidents they address.

Almost five years ago, in September 2021, it also warned of a massive increase in sextortion complaints and advised those receiving threats to stop all interaction with the criminals immediately and contact law enforcement as soon as possible.

Sextortionists face dozens of years in prison if caught and sentenced. For instance, in May, a Canadian man was sentenced to 33 years in prison for targeting more than 145 children across the United States, some as young as 6 years old, in an eight-year-long sextortion scheme.

article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report