VYPR
advisoryPublished Aug 11, 2026· 1 source

FBI Warns of Rising Trend in Sexual Predators Targeting Online Accounts for Intimate Images

The FBI has issued a public warning about an escalating threat where sexual predators are compromising online accounts to steal and distribute non-consensual intimate images (NCII) for harassment, stalking, and sextortion.

The FBI has issued a Public Service Announcement (PSA) highlighting a disturbing trend where cybercriminals are actively targeting social media and personal online accounts with the primary goal of stealing and distributing intimate images and videos without consent. This illicit material, referred to by the FBI as non-consensual intimate images (NCII), is increasingly being posted or sold on criminal marketplaces. These marketplaces often include victims' personal identifying information such as names, phone numbers, email addresses, and social media handles, thereby amplifying the potential for severe harassment, stalking, and sextortion.

Attackers are employing a sophisticated combination of account takeover techniques and social engineering tactics to achieve their objectives. One prevalent method involves high-volume password and PIN guessing, leveraging data previously exposed in data breaches, scraped from public social media profiles, and sourced from various leak sites. Criminals often target known victims by using variations of their names, birth dates, and other predictable personal details that are readily available.

Another common tactic involves deceptive "fake customer service" text messages. Victims may receive a message falsely claiming their social media account is about to be locked or disabled. The attacker then initiates a legitimate password reset process for the victim's account and subsequently persuades the victim to divulge the one-time verification code sent to their device. This social engineering trick allows the attacker to gain unauthorized access to the account.

Phishing emails are also a significant vector in these attacks. Threat actors create emails that mimic legitimate communications from service providers, often using lookalike support domains and email addresses. These emails typically warn of a "new login" or suspicious activity, directing the victim to a fake password change page. This meticulously crafted page is designed to steal the victim's credentials when they attempt to "secure" their account.

These methods differ from more common "I recorded you" sextortion scams, which typically rely on intimidation rather than actual account compromise. However, the FBI advises that if such an email includes a password that is still in use across multiple accounts, it should be changed immediately on all affected platforms.

To mitigate the risk of becoming a victim, the FBI recommends several security best practices. It is crucial to avoid storing sensitive images on social media platforms or other internet-connected services whenever possible, as breaches and leaks can lead to this content falling into the wrong hands. Utilizing a password manager to generate unique, strong passwords for every account is essential. Passwords should not be based on easily discoverable personal information like names or birthdays.

Enabling multi-factor authentication (MFA) is a critical layer of defense, with a preference for passkeys or hardware security keys where available. While MFA significantly enhances security, attackers can still attempt to phish one-time codes or session cookies. Therefore, users should never approve an unexpected MFA prompt or share verification codes with anyone.

Users are urged to treat unexpected "account warning" links received via text or email with extreme suspicion. Instead of clicking on these links, individuals should navigate directly to the service's official app or type the known web address into their browser. It is also important not to trust sponsored search results, which may lead to fraudulent websites. If an individual discovers that their intimate content has been stolen or shared, they should preserve all relevant links and evidence, secure the affected accounts immediately, and report the incident through the FBI's dedicated NCII reporting portal at ncii.ic3.gov.

Synthesized by Vypr AI