FBI Warns: Athletes Hit With Fake Support Phishing

TechRepublic Security · Medium sophistication
Last updated August 12, 2026

The FBI and NCAA warned that criminals are breaking into college athletes’ online accounts to steal intimate photos and then use them for sextortion, harassment, or selling online. The article describes common entry methods like fake “customer support” password-reset requests and credential abuse, and highlights steps athletes and campus teams can take to reduce risk and respond safely.

Key findings

  • The FBI and NCAA warned of “cyber-enabled sexual exploitation targeting college athletes” where criminals steal intimate images for sextortion, harassment, stalking, or resale.
  • Attackers commonly gain access through “phishing, password and PIN targeting, and fake social-media customer-service requests.”
  • A reported tactic is impersonating platform support and creating urgency about a password reset to capture credentials.
  • Password reuse increases impact because one leaked password can be reused across multiple services (credential stuffing).
  • The article recommends strong unique passwords, password managers, MFA, and verifying account-recovery messages through official channels.

Who’s being targeted

  • Commonly targeted roles: College athletes, Athletics departments, Campus IT teams, Students with high-profile social media accounts.
  • Affected industries: Higher education (colleges and universities), Athletics programs, Students/individual consumers.
  • Attack channels: email, website.
  • Impersonated: Social-media platform support team, Legitimate login page (attacker uses stolen/reused credentials rather than impersonation in the message).

Awareness takeaways

  • Treat unsolicited password-reset or account-recovery messages as suspicious and verify through the official app/website, don’t respond to the message itself.
  • Never share passwords, PINs, or authentication codes with anyone who contacts you unexpectedly, even if they claim to be ‘support.’
  • Use strong, unique passwords and enable MFA to reduce the impact of stolen or reused credentials.
  • If targeted for sextortion, preserve evidence, block/report the account, and seek help rather than complying with threats.

Red flags to watch for

  • Unsolicited account-recovery message creating urgency
  • Support request not initiated by the user
  • Request for passwords, PINs, or authentication codes
  • Unexpected login alerts or new device/session notifications
  • Password works across multiple services (sign of reuse)
  • Account recovery settings changed without the user’s knowledge
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

FBI and NCAA are warning: college athletes are getting phished, then blackmailed with stolen private photos. One move they use: an email that looks like platform support. Subject line: 'Urgent: Password reset requested, verify now to prevent lockout.' You click, log in, and they quietly walk into your account and grab every intimate photo. Here’s the nasty part: if you reuse that password, one leak can unlock your cloud backup, DMs, everything. Attackers use automated logins, then download private photos for sextortion, harassment, or resale. Your move: if you get an unsolicited password-reset or 'support' message, don’t click it. Open the official app or website yourself and check there instead.

Similar attacks

Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
FBI: Sextortion Hackers Steal Photos via Fake Support

FBI: Sextortion Hackers Steal Photos via Fake Support

The FBI warns that criminals are breaking into social media and personal accounts to steal explicit images and sell them online, often bundled with personal details. The advisory describes common social-engineering lures, like fake customer-service texts and phishing emails, that trick people into…

August 12, 2026
FBI Warns of Social Media Reset-Code Scams

FBI Warns of Social Media Reset-Code Scams

The FBI says criminals are using social engineering to take over social media accounts, steal explicit content, and sell or post it online along with victims’ personal information. Reported tactics include pretending to be a social media company representative, spamming victims with password-reset…

August 12, 2026
BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
Defense Supplier Tricked by Fake M365 Share Link

Defense Supplier Tricked by Fake M365 Share Link

IEH Corporation disclosed that an attacker got into its Microsoft 365 email environment after an employee clicked what looked like a legitimate Microsoft file-sharing link from a supposed new business contact. The fake link led to a phony login page that captured the employee’s credentials, letting…

August 7, 2026
Voicemail Phish Steals Microsoft 365 Sessions

Voicemail Phish Steals Microsoft 365 Sessions

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in…

August 7, 2026