FBI Warns: Athletes Hit With Fake Support Phishing

TechRepublic Security · Medium sophistication
Last updated August 12, 2026

The FBI and NCAA warned that criminals are breaking into college athletes’ online accounts to steal intimate photos and then use them for sextortion, harassment, or selling online. The article describes common entry methods like fake “customer support” password-reset requests and credential abuse, and highlights steps athletes and campus teams can take to reduce risk and respond safely.

Key findings

  • The FBI and NCAA warned of “cyber-enabled sexual exploitation targeting college athletes” where criminals steal intimate images for sextortion, harassment, stalking, or resale.
  • Attackers commonly gain access through “phishing, password and PIN targeting, and fake social-media customer-service requests.”
  • A reported tactic is impersonating platform support and creating urgency about a password reset to capture credentials.
  • Password reuse increases impact because one leaked password can be reused across multiple services (credential stuffing).
  • The article recommends strong unique passwords, password managers, MFA, and verifying account-recovery messages through official channels.

Who’s being targeted

  • Commonly targeted roles: College athletes, Athletics departments, Campus IT teams, Students with high-profile social media accounts.
  • Affected industries: Higher education (colleges and universities), Athletics programs, Students/individual consumers.
  • Attack channels: email, website.
  • Impersonated: Social-media platform support team, Legitimate login page (attacker uses stolen/reused credentials rather than impersonation in the message).

Awareness takeaways

  • Treat unsolicited password-reset or account-recovery messages as suspicious and verify through the official app/website, don’t respond to the message itself.
  • Never share passwords, PINs, or authentication codes with anyone who contacts you unexpectedly, even if they claim to be ‘support.’
  • Use strong, unique passwords and enable MFA to reduce the impact of stolen or reused credentials.
  • If targeted for sextortion, preserve evidence, block/report the account, and seek help rather than complying with threats.

Red flags to watch for

  • Unsolicited account-recovery message creating urgency
  • Support request not initiated by the user
  • Request for passwords, PINs, or authentication codes
  • Unexpected login alerts or new device/session notifications
  • Password works across multiple services (sign of reuse)
  • Account recovery settings changed without the user’s knowledge
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

FBI and NCAA are warning: college athletes are getting phished, then blackmailed with stolen private photos. One move they use: an email that looks like platform support. Subject line: 'Urgent: Password reset requested, verify now to prevent lockout.' You click, log in, and they quietly walk into your account and grab every intimate photo. Here’s the nasty part: if you reuse that password, one leak can unlock your cloud backup, DMs, everything. Attackers use automated logins, then download private photos for sextortion, harassment, or resale. Your move: if you get an unsolicited password-reset or 'support' message, don’t click it. Open the official app or website yourself and check there instead.

Similar attacks

Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
FBI: Sextortion Hackers Steal Photos via Fake Support

FBI: Sextortion Hackers Steal Photos via Fake Support

The FBI warns that criminals are breaking into social media and personal accounts to steal explicit images and sell them online, often bundled with personal details. The advisory describes common social-engineering lures, like fake customer-service texts and phishing emails, that trick people into…

August 12, 2026
AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026
“Half-Click” Zimbra Email Attack Steals 90 Days

“Half-Click” Zimbra Email Attack Steals 90 Days

CISA warns a Russian state-sponsored group (“Laundry Bear,” tracked by Microsoft as “Void Blizzard”) is compromising some unpatched Zimbra email accounts when users merely open or preview a specially crafted email. The hidden code can steal passwords, MFA-related tokens, and up to 90 days of…

August 14, 2026