The FBI is warning social media users about criminals who break into personal accounts in search of intimate photos and videos, which can later be distributed online or offered for sale. The attacks rely on several methods, including phishing messages, fake customer support interactions, and attempts to take over accounts using previously exposed passwords.
According to a public service announcement from the FBI’s Internet Crime Complaint Center (IC3), attackers may target particular individuals or cast a wider net in search of accounts containing private material. After obtaining intimate content, criminals have been observed sharing it through online communities or attempting to sell it on illicit marketplaces.
The consequences can extend beyond the initial theft. The FBI says stolen images may be published alongside identifying information about the person involved, including names, dates of birth, email addresses, telephone numbers and social media usernames. Combining intimate material with this information can expose victims to further harassment and repeated targeting.
One method described by the FBI begins with criminals pretending to represent a social media company’s support team. Attackers can create convincing email addresses or websites and contact users with a fabricated warning that somebody has attempted to access their account.
The message then directs the recipient to a malicious link. A victim who follows the instructions may unknowingly provide information that allows the attacker to enter the real social media account.
Another variation focuses on account verification codes. Criminals impersonating customer support may tell users that their account is about to be suspended or deleted and claim that a verification code is required to prevent this from happening. Behind the scenes, the attacker initiates a genuine password reset, causing the platform to send an authentication code to the account owner.
If that code is handed over, the criminal can use it to complete the reset and take control of the account. The legitimate owner may then find that the password has been changed and access has been lost.
Not every account compromise requires direct interaction with the victim. The FBI also warns about password attacks in which criminals try combinations of usernames and passwords until they find credentials that work. Login information exposed through previous data breaches or obtained from criminal marketplaces can be used for these attempts.
The FBI recommends avoiding the storage of sexually explicit photos and videos on social media accounts or other internet-accessible services when possible. Users are also advised to protect accounts with strong, unique passphrases and enable multi-factor authentication where available.
Passwords and PINs should not be based on easily discovered personal details such as birthdays or the names of relatives. Reusing passwords is also risky because credentials exposed through a breach involving one service can potentially be tested against accounts elsewhere.
Unexpected password-reset notifications, account warnings and messages containing login links should be treated cautiously. Rather than following a link supplied in an email or text message, users can open the platform’s official application or manually visit its website to check their account.
The FBI also stresses that authentication codes and login credentials should not be provided to someone claiming to work for a social media company. A request for this information can itself be an indication that somebody is attempting to take control of the account.
