FBI: Fake Support Codes Used to Steal Nudes

TechSpot · Medium sophistication
Last updated August 12, 2026

The FBI warns that criminals are breaking into social media and personal accounts to steal explicit images and sell or share them online, often with the victim’s personal details attached. The warning highlights specific tactics such as password guessing from breached data, fake “account will be locked” texts that trick victims into sharing verification codes, and phishing emails posing as platform support.

Key findings

  • Attackers compromise social media/personal accounts to search for and steal explicit photos/videos, then sell/share them on criminal marketplaces.
  • Stolen content is often packaged with personally identifiable information (name, DOB, email, phone, usernames), increasing risk of harassment, stalking, and sextortion.
  • Access methods described include password/PIN guessing using breached and public info, smishing that tricks victims into sharing real password-reset verification codes, and phishing emails from look-alike domains.
  • A cited real case involved fake Snapchat support texts sent to over 1,500 women, resulting in hundreds of compromised accounts and stolen images.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Communications/Marketing, HR.
  • Affected industries: Individuals/Consumers, Social media users.
  • Attack channels: smishing, email, website.
  • Impersonated: Social media support/security team, Social media support (look-alike domain), Snapchat Support.

Awareness takeaways

  • Never share verification codes (especially codes sent during password resets), even with someone claiming to be support.
  • Treat “new login” alerts and password-change links with suspicion; navigate to the platform directly instead of clicking links in messages.
  • Use unique, strong passphrases/PINs to reduce the impact of breached-password guessing.
  • Enable multi-factor authentication and reduce online storage of sensitive images to limit damage if an account is compromised.

Red flags to watch for

  • Urgent threat that your account will be locked/disabled
  • Request to share a verification code (codes should never be shared)
  • Message arrives while you didn’t request a password reset
  • Sender domain is a look-alike (not the real platform domain)
  • Unexpected 'new login' warning pushing you to click a link
  • Link leads to a site asking for credentials
  • Unsolicited support text claiming an account problem
  • Push to 'verify' quickly via text rather than through the app/official site
  • High-pressure language implying immediate loss of access
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

The FBI says criminals are hijacking Snapchat and other accounts just to steal private photos and sell them with your name and phone number attached. Here’s the trick: you get a text saying, 'Your Snapchat account will be locked unless you supply a verification code.' At the same time, Snapchat sends you a real password‑reset code. If you reply with that code, they reset your password and walk right into your account. Same play with email: 'Security alert: new login detected. Change your password using the link below.' The sender is a look‑alike domain, and the link opens a fake login page asking for your username and password. Your move: if any text or email asks for a verification code or wants you to click a password link, stop. Don’t reply, don’t click, go straight to the app or website yourself and check from there.

Similar attacks

FBI Warns of Social Media Reset-Code Scams

FBI Warns of Social Media Reset-Code Scams

The FBI says criminals are using social engineering to take over social media accounts, steal explicit content, and sell or post it online along with victims’ personal information. Reported tactics include pretending to be a social media company representative, spamming victims with password-reset…

August 12, 2026
FBI: Sextortion Hackers Steal Photos via Fake Support

FBI: Sextortion Hackers Steal Photos via Fake Support

The FBI warns that criminals are breaking into social media and personal accounts to steal explicit images and sell them online, often bundled with personal details. The advisory describes common social-engineering lures, like fake customer-service texts and phishing emails, that trick people into…

August 12, 2026
FBI: Fake “Account Locked” Alerts Steal Intimate Media

FBI: Fake “Account Locked” Alerts Steal Intimate Media

The FBI warned that criminals are breaking into personal and social media accounts to steal and share intimate images and videos without consent. The campaign uses social engineering like fake customer-service texts and phishing “new login” emails to trick victims into handing over verification…

August 11, 2026
How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay codes in real time, SIM swapping, and stealing session cookies so MFA isn’t needed again. It also cites known incidents (e.g., Uber 2022 MFA…

July 29, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026