Published Security3 min read
The FBI's Explicit-Content Alert Is an Account Takeover Bulletin in Different Clothing
Credential spraying from leak sites, help-desk impersonation over SMS, reset-code relay and look-alike login pages.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- The FBI published a public service announcement this week warning that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos.
- The FBI notice was issued on Monday and said threat actors are using a variety of social engineering and cyber intrusion tactics to target specific individuals of interest, who may or may not be known to the actor, or general targets of opportunity.
- The stolen material, known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge.
- In password/PIN targeting, actors use high-volume password and PIN attempts against social media and personal accounts, using information from data leak sites, social media and open-source information.
- When victims are known to the actors, curated lists may include personal details such as names, date of birth or variations of those details.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The FBI published a public service announcement this week warning that criminals are breaking into the social media and personal accounts of adults and children to steal sexually explicit images and video, then posting or selling the material, known as non-consensual intimate images, on criminal marketplaces [1][2][3]. Read as a tradecraft document rather than a child-safety document, the notice describes four unremarkable account-takeover techniques, which is precisely why it belongs in general security awareness material and not only in a parents-and-coaches briefing.
The first technique is high-volume password and PIN guessing, with candidate values drawn from data leak sites, social media and other open-source information [4]. Where the target is personally known to the attacker, the bureau says the lists are curated with names, dates of birth and variations on both [5]. That is credential stuffing plus a hand-built dictionary, and it works for the same reason it works against corporate SaaS logins.
The second is help-desk impersonation over SMS. According to the FBI, victims receive texts claiming their account will be disabled or locked unless they supply a verification code [6]. The attacker then triggers a password reset, which sends a legitimate code to the victim, and if the victim relays it, the attacker completes the reset and owns the account [7]. The bureau lists unsolicited texts demanding a verification code, and unsolicited emails referencing a new login with an embedded reset link, as indicators [8], and states flatly that a legitimate platform or service will not ask an account holder for a verification code, temporary password or PIN reset code [9].
The third and fourth are phishing email from look-alike domains posing as platform customer support [10] and cloned social media login pages that forward entered credentials to the operator [11]. None of the four routes requires a software vulnerability [12]. Every one targets a person or a reset flow.
Note the tension inside the guidance. The FBI recommends complex passphrases, PINs that avoid names and birthdays, and multi-factor authentication where available [13][14]. It also documents that the primary hands-on technique is persuading the victim to read out the second factor [15]. Enabling SMS-delivered MFA does not close the hole described in the same document, and defenders who treat "MFA enabled" as a completed control are measuring the wrong thing.
The consequence side is where this stops resembling a routine bulletin. The stolen material is published with the victim's name, date of birth, email address, phone number and social media username [16], and the FBI says victims then face harassment, sextortion, stalking and other targeted attacks, including having the stolen content advertised on their own social media page [17]. Prior prosecutions show the scale one operator can reach: a 27-year-old Illinois man pleaded guilty in February over a campaign against roughly 600 women's Snapchat accounts [18], and a former University of Michigan assistant football coach was indicted last year for breaching student athlete databases at more than 100 colleges and universities, accessing medical data on about 150,000 people and using it to break into the accounts of female student athletes [19]. The FBI and the NCAA issued a parallel warning the same day asking coaches, compliance staff and athletic department leadership to push awareness through their schools [20].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The FBI published a public service announcement this week warning that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos.
- [2]
The FBI notice was issued on Monday and said threat actors are using a variety of social engineering and cyber intrusion tactics to target specific individuals of interest, who may or may not be known to the actor, or general targets of opportunity.
- [3]
The stolen material, known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge.
- [4]
In password/PIN targeting, actors use high-volume password and PIN attempts against social media and personal accounts, using information from data leak sites, social media and open-source information.
- [5]
When victims are known to the actors, curated lists may include personal details such as names, date of birth or variations of those details.
- [6]
In social media customer service impersonation, victims receive text messages claiming their account is being disabled or locked unless they provide a verification code.
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comSergiu GatlanAug 12FBI: Hackers target online accounts to steal nude photos
- therecord.mediaAug 12FBI: Hackers using social engineering to breach accounts and steal explicit content
- thecyberexpress.comSamiksha JainAug 12



