FBI: Sextortion Hackers Steal Photos via Fake Support

ZDNet Security · Medium sophistication
Last updated August 12, 2026

The FBI warns that criminals are breaking into social media and personal accounts to steal explicit images and sell them online, often bundled with personal details. The advisory describes common social-engineering lures, like fake customer-service texts and phishing emails, that trick people into sharing password reset codes or clicking malicious links, leading to account takeover and potential sextortion.

Key findings

  • FBI warns criminals are stealing explicit images by hacking social media and personal accounts, then selling them on the dark web with identifying details.
  • The advisory highlights three access methods: password/PIN attacks using leaked data, customer-service impersonation via text to steal reset codes, and phishing emails with fake support domains and malicious password-reset links.
  • Stolen images and personal details can be used for sextortion, re-victimizing targets through blackmail.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, HR, Finance, Customer-facing teams, Anyone with company-linked social media accounts.
  • Affected industries: Consumers/individual account holders, Social media platforms, Online services with user accounts.
  • Attack channels: smishing, email, website.
  • Impersonated: Social media company customer service, Social media company customer service support.

Awareness takeaways

  • Never share password reset codes or temporary access codes, treat them like your password.
  • Avoid clicking links in unexpected messages; go directly to the official site/app to sign in or change your password.
  • Use unique, complex passwords/PINs and enable multi-factor authentication where available.
  • Reduce risk by not storing sensitive/explicit images on social media or public internet sites.

Red flags to watch for

  • Unsolicited text claiming your account will be disabled/locked
  • You receive a reset code you did not request
  • Request to share a one-time code (legitimate support will not ask)
  • Email comes from a lookalike domain impersonating support
  • Unexpected 'new login' alert urging immediate action
  • Embedded link to change password instead of using the official app/site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

The FBI says criminals are breaking into social accounts, stealing explicit photos, and selling them with your name attached. One way in: a text pretending to be social media support. It says your account is being locked and asks you to reply with the password reset code just sent to your phone. Here’s the trick: once you give up that code or click a fake “new login” email link from a lookalike support address, they reset your password, grab your photos, and can use them for sextortion. Aha moment: that reset code is your password. If you get a code you didn’t request, or anyone asks for it, stop and go straight into the official app or website to check your account.

Similar attacks

FBI Warns of Social Media Reset-Code Scams

FBI Warns of Social Media Reset-Code Scams

The FBI says criminals are using social engineering to take over social media accounts, steal explicit content, and sell or post it online along with victims’ personal information. Reported tactics include pretending to be a social media company representative, spamming victims with password-reset…

August 12, 2026
FBI: Fake Support Codes Used to Steal Nudes

FBI: Fake Support Codes Used to Steal Nudes

The FBI warns that criminals are breaking into social media and personal accounts to steal explicit images and sell or share them online, often with the victim’s personal details attached. The warning highlights specific tactics such as password guessing from breached data, fake “account will be…

August 12, 2026
FBI Warns: Athletes Hit With Fake Support Phishing

FBI Warns: Athletes Hit With Fake Support Phishing

The FBI and NCAA warned that criminals are breaking into college athletes’ online accounts to steal intimate photos and then use them for sextortion, harassment, or selling online. The article describes common entry methods like fake “customer support” password-reset requests and credential abuse,…

August 12, 2026
How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay codes in real time, SIM swapping, and stealing session cookies so MFA isn’t needed again. It also cites known incidents (e.g., Uber 2022 MFA…

July 29, 2026
FBI: Fake “Account Locked” Alerts Steal Intimate Media

FBI: Fake “Account Locked” Alerts Steal Intimate Media

The FBI warned that criminals are breaking into personal and social media accounts to steal and share intimate images and videos without consent. The campaign uses social engineering like fake customer-service texts and phishing “new login” emails to trick victims into handing over verification…

August 11, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026