Los Angeles, CA
The LA Globe
Security

FBI Warns Hackers Are Taking Over Accounts to Steal Intimate Photos — Here Are the Four Methods the Alert Names

The bureau says student-athletes are frequently targeted because of their public profiles. Three of the four intrusion techniques in the advisory never break a password at all — they ask for it.

A teenager's hands holding a smartphone in a dimly lit room, face out of frame, screen glow lighting the fingers — illustrating FBI warnings about account takeover and sextortion
The FBI advisory says attackers rely largely on social engineering, including impersonating social media customer service staff. (Photo illustration: The LA Globe)

The FBI has issued a public warning that cybercriminals are breaking into the social media accounts of adults and children in order to steal intimate explicit images and videos, then extorting the account holders or publishing the stolen material, according to TechCrunch, which reviewed the alert and contacted the bureau.

The advisory describes a crime that does not end when the images are taken. “Victims often face re-victimization through harassment, sextortion, stalking or other targeted attacks, such as advertising stolen content on a victim’s own social media page,” the FBI wrote, in language quoted by TechCrunch. The bureau declined to comment to TechCrunch and instead pointed to a press release, in which it said it “has determined that student-athletes are frequently targeted due to their public profiles.”

The four ways in

The mechanics matter here, because they explain why the standard advice is what it is. Per the advisory as reported by TechCrunch, attackers:

  • brute-force accounts using leaked or previously used passwords;
  • impersonate customer service representatives, claiming to work for Instagram and other social media companies;
  • contact targets directly, saying the target needs to recover an account;
  • send phishing emails using fake domains built to look like legitimate social media login pages.

Read side by side, three of those four never defeat a password. They ask for it — through an impersonated support agent, a manufactured account-recovery emergency, or a login page that is a copy of the real one. Only the first technique attacks the credential itself, and it works by reuse: a password exposed in some unrelated breach, tried again where the victim used it a second time. The FBI’s advisory characterizes the perpetrators as relying largely on social engineering, which is consistent with that split.

What the bureau tells people to do

The FBI’s guidance, as summarized by TechCrunch, maps onto those methods one for one: use unique passwords stored in a password manager, which removes the reuse that makes credential-stuffing work; turn on multi-factor authentication; and treat any unprompted contact from someone claiming to work for a social media company as suspect, since tech companies generally do not reach out to their customers. The bureau also urges people not to store intimate pictures in online accounts at all.

Why an alert now

Crimes of this kind have been known for years. Rachel Tobac, chief executive of the security awareness training firm SocialProof Security, told TechCrunch that the FBI issuing a public alert could indicate the incidents are now rising. Tobac said the attacks especially target young boys and called them “a big public health issue,” given that victims are sometimes driven to self-harm in response.

That framing — public health rather than pure computer crime — sits alongside the bureau’s observation about student-athletes. The common thread in both is exposure: a public profile gives an attacker a name, a face, a school affiliation and an audience to threaten the victim with. The extortion leverage is not the file. It is the list of people who could be shown it.

The advisory does not include case counts, and the FBI did not provide TechCrunch with figures or additional comment beyond the press release.

Comments