
FBI Warns of Account Hacks Used to Steal Intimate Images
The FBI says criminals are taking over social-media and cloud accounts to steal and distribute private images, using password attacks, phishing and fake customer-support messages.
The short version
What you need to know
- The FBI says criminals target adults and minors by breaking into social-media, cloud-storage and other accounts, then distributing or selling stolen intimate material.
- Common tactics include password guessing with leaked or personal information, phishing links, and impersonating platform support to obtain genuine reset codes.
- Unique passwords, multi-factor authentication and never sharing an unsolicited verification code matter here. A VPN does not stop account takeover or remove leaked content.
What did the FBI warn about?
In an Internet Crime Complaint Center alert dated 10 August, the FBI said sexual-exploitation actors are illegally accessing social-media, cloud-storage and other personal accounts belonging to adults and minors. They steal intimate images or videos and may publish or sell them alongside identifying information.
The FBI and NCAA also announced an education initiative for student-athletes, whom they say are frequently targeted because public profiles can provide personal details and create perceived reputational leverage. The warning is about criminal account access and abuse—not consent to share material that was privately stored.
How the account takeovers work
Attackers may make high-volume password and PIN attempts using credentials from data leaks or details collected from social media. Reused passwords and PINs based on names or birth dates make that approach more likely to succeed.
Another method starts with a genuine password-reset request. The platform sends the victim a real code, then a criminal posing as customer support asks the victim to forward it. Phishing emails and look-alike domains can similarly claim there was a new login and direct the target to a fake password page.
What you can do now
Use a different long password for every important account and store it in a reputable password manager. Turn on multi-factor authentication, preferably a passkey or security key where offered, and review recovery email addresses, phone numbers and signed-in sessions. Do not use publicly discoverable identity details as a PIN or password.
Never share an unexpected reset code, temporary password or PIN with somebody who contacts you. Open the service's official app or type its address yourself to investigate an alert. Consider whether highly sensitive files need to be stored in an internet-accessible account at all, and review the account's encryption and sharing settings.
If private content is stolen or used for extortion
The FBI advises victims to stop contact with the offender, avoid paying or providing proof of identity, preserve messages and images as evidence, and report promptly. Paying does not reliably prevent distribution and can lead to further demands.
The US reporting route in the alert is the FBI's non-consensual intimate image portal at ncii.ic3.gov. People elsewhere should use their local police and specialist victim-support or image-removal services. If a child is involved or anyone faces immediate danger or self-harm risk, contact emergency services and an appropriate child-protection organisation without delay.
Where a VPN helps — and where it does not
A VPN can encrypt network traffic on an untrusted local connection and reduce exposure of your usual public IP address. That is useful general privacy when accessing accounts on public Wi-Fi.
It cannot make a reused password unique, block every phishing page, prevent you sharing a genuine reset code, restore a stolen account or remove copied images. The most relevant controls are unique credentials, strong MFA, careful recovery settings, secure storage and rapid reporting—not a change of IP address.
VPN Rocks view
A convincing support message may contain a real code because the criminal triggered the platform to send it. That is exactly why users should treat unsolicited requests for codes as hostile, even when other parts of the message seem authentic.
Victims deserve practical help without blame. Account-security advice should focus on limiting further access, preserving evidence and connecting people with reporting and removal support.
Primary reading
Sources and further reading
We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.


