FBI: Fake “Account Locked” Alerts Steal Intimate Media

Malwarebytes · Medium sophistication
Last updated August 11, 2026

The FBI warned that criminals are breaking into personal and social media accounts to steal and share intimate images and videos without consent. The campaign uses social engineering like fake customer-service texts and phishing “new login” emails to trick victims into handing over verification codes or passwords, enabling account takeover and further harassment or sextortion.

Key findings

  • Attackers are stealing and distributing non-consensual intimate images (NCII) after breaking into personal and social media accounts.
  • A common workflow is to trigger a real password reset and then trick the victim into sharing the verification code via fake “customer service” texts.
  • Phishing emails use lookalike support domains and “new login” warnings to send victims to fake password-change pages that steal credentials.
  • Stolen media may be posted or sold with personal identifiers (name, phone, email, handles), increasing risk of harassment, stalking, and sextortion.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Anyone managing social media accounts, Security awareness / IT helpdesk (for user guidance).
  • Affected industries: General public / consumers, Any organization with employees using personal or social media accounts.
  • Attack channels: sms, email, website.
  • Impersonated: Social media platform customer support, Account/security support team (lookalike support domain).

Awareness takeaways

  • Never share verification codes (even if the request seems tied to a real password reset).
  • Treat unexpected account-warning texts/emails as suspicious and navigate using the official app or a known URL you type yourself.
  • Use unique, long passwords (and avoid predictable PINs based on public personal details) to reduce account-takeover risk.
  • Enable MFA, but don’t approve unexpected prompts or share one-time codes.

Red flags to watch for

  • Unsolicited account-lock warning sent by text
  • Pressure/urgency to act immediately
  • Request to share a verification code (codes should never be shared)
  • Lookalike support domain/email address
  • Link leads to a password change page that isn’t the real service
  • Unexpected “new login” alert prompting immediate action
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a text: “Your social media account will be locked or disabled. Reply with the verification code we just sent.” Here’s the trick: they trigger a real password reset on your account, then pretend to be customer support so you hand over that real verification code. Once they’re in, they can steal and share intimate photos and videos from your personal and social media accounts, tied to your name, phone, and email. Your move: if any text or email asks for a verification code, stop. Don’t share it, open the real app or site yourself and check there.

Similar attacks

How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay codes in real time, SIM swapping, and stealing session cookies so MFA isn’t needed again. It also cites known incidents (e.g., Uber 2022 MFA…

July 29, 2026
FBI Warns of Social Media Reset-Code Scams

FBI Warns of Social Media Reset-Code Scams

The FBI says criminals are using social engineering to take over social media accounts, steal explicit content, and sell or post it online along with victims’ personal information. Reported tactics include pretending to be a social media company representative, spamming victims with password-reset…

August 12, 2026
FBI: Sextortion Hackers Steal Photos via Fake Support

FBI: Sextortion Hackers Steal Photos via Fake Support

The FBI warns that criminals are breaking into social media and personal accounts to steal explicit images and sell them online, often bundled with personal details. The advisory describes common social-engineering lures, like fake customer-service texts and phishing emails, that trick people into…

August 12, 2026
FBI: Fake Support Codes Used to Steal Nudes

FBI: Fake Support Codes Used to Steal Nudes

The FBI warns that criminals are breaking into social media and personal accounts to steal explicit images and sell or share them online, often with the victim’s personal details attached. The warning highlights specific tactics such as password guessing from breached data, fake “account will be…

August 12, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Fake Free COD Points Scam Steals Logins and 2FA

Fake Free COD Points Scam Steals Logins and 2FA

A real phishing campaign targeted Call of Duty Mobile players by promising free in-game currency. Victims were tricked into entering their email and password, then providing a 2FA code on a follow-up page, enabling attackers to take over accounts.

August 2, 2026