The FBI and NCAA warned that criminals are breaking into college athletes’ online accounts to steal intimate photos and then use them for sextortion, harassment, or selling online. The article describes common entry methods like fake “customer support” password-reset requests and credential abuse, and highlights steps athletes and campus teams can take to reduce risk and respond safely.
Key findings
- The FBI and NCAA warned of “cyber-enabled sexual exploitation targeting college athletes” where criminals steal intimate images for sextortion, harassment, stalking, or resale.
- Attackers commonly gain access through “phishing, password and PIN targeting, and fake social-media customer-service requests.”
- A reported tactic is impersonating platform support and creating urgency about a password reset to capture credentials.
- Password reuse increases impact because one leaked password can be reused across multiple services (credential stuffing).
- The article recommends strong unique passwords, password managers, MFA, and verifying account-recovery messages through official channels.
Who’s being targeted
- Commonly targeted roles: College athletes, Athletics departments, Campus IT teams, Students with high-profile social media accounts.
- Affected industries: Higher education (colleges and universities), Athletics programs, Students/individual consumers.
- Attack channels: email, website.
- Impersonated: Social-media platform support team, Legitimate login page (attacker uses stolen/reused credentials rather than impersonation in the message).
Awareness takeaways
- Treat unsolicited password-reset or account-recovery messages as suspicious and verify through the official app/website, don’t respond to the message itself.
- Never share passwords, PINs, or authentication codes with anyone who contacts you unexpectedly, even if they claim to be ‘support.’
- Use strong, unique passwords and enable MFA to reduce the impact of stolen or reused credentials.
- If targeted for sextortion, preserve evidence, block/report the account, and seek help rather than complying with threats.
Red flags to watch for
- Unsolicited account-recovery message creating urgency
- Support request not initiated by the user
- Request for passwords, PINs, or authentication codes
- Unexpected login alerts or new device/session notifications
- Password works across multiple services (sign of reuse)
- Account recovery settings changed without the user’s knowledge
Read the video transcript
FBI and NCAA are warning: college athletes are getting phished, then blackmailed with stolen private photos. One move they use: an email that looks like platform support. Subject line: 'Urgent: Password reset requested, verify now to prevent lockout.' You click, log in, and they quietly walk into your account and grab every intimate photo. Here’s the nasty part: if you reuse that password, one leak can unlock your cloud backup, DMs, everything. Attackers use automated logins, then download private photos for sextortion, harassment, or resale. Your move: if you get an unsolicited password-reset or 'support' message, don’t click it. Open the official app or website yourself and check there instead.