Hackers target social media accounts to steal intimate images, FBI says
They’re using phishing and other social engineering techniques to steal victims’ intimate images.

Hackers. By Shutterstock/Cybernews
- The FBI warns hackers are targeting social media accounts to steal and share intimate images.
- Attackers use fake support messages, phishing links, verification-code scams, and brute-force attacks to access accounts.
- Stolen images may be posted with personal details, increasing harassment, extortion, and repeated victimization risks.
- The FBI advises avoiding online storage of explicit content and using strong passwords and multi-factor authentication.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
You shouldn’t store any sexually explicit photos or videos on social media accounts or other platforms that are accessible via the internet. Doing so makes you a target for hackers.
According to the FBI, threat actors are actively scouring the internet to hack social media platforms in an attempt to gain access to personal accounts and steal naked pictures and nude videos.
Once the attackers get hold of these intimate images, they share or post the content within community forums, or try to sell these pictures and videos on criminal marketplaces.
Personally identifiable information, such as name, date of birth, email, phone number, and social media username, is often posted along with the victim’s explicit content, exposing them to continued re-victimization,the FBI’s Internet Crime Complaint Center (IC3) says in a public service announcement (PSA) that was published on Monday.
The announcement states that attackers use a variety of social engineering and intrusion tactics to target both specific individuals and general targets.
For example, hackers create fake domains and email accounts, pretending to be a social media customer support desk worker. In this role, they contact the target by falsely claiming there’s been a fraudulent login attempt into their account. By clicking the malicious URL in the email, the attackers gain access to their account.
There have also been phishing attempts in which the hackers impersonate a social media customer service and falsely claim the victim’s social media account will be disabled or deleted unless this person responds with a verification code. The actors then request a password reset, which in turn generates an access code that is sent to the victim. Once the victim shares this code, the scammers access the victim’s account and change the password.
Lastly, there have been reports of brute-force attacks, in which attackers use software to enter an unlimited number of username-password combinations until a match is found. Threat actors have often obtained this data through prior data breaches at companies and organizations or by purchasing it on the dark web.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The public service announcement mentions several recommendations. The FBI advises against storing nude material on social media platforms and other online accessible sites.
In addition, the use of complex passphrases, PINs, or multi-factor authentication (MFA) is recommended. The use of traceable personal information for a password, such as the name of someone you love or your date of birth, is discouraged.
Lastly, people are advised to be cautious with links in emails and text messages, as well as messages regarding password resets.
“Do not share login information with anyone, even if the requester claims to be associated with a platform or service with which you have an account. Go directly to the service’s website or official app to change your password or PIN, if necessary,” the PSA concludes.