Sexual predators targeting online accounts for intimate images, FBI warns

| August 11, 2026
Sextortion

The FBI has issued a Public Service Announcement (PSA) warning that criminals are breaking into social media and personal accounts to steal and distribute intimate images and videos without consent. The FBI refers to this type of content as non-consensual intimate images (NCII).

The stolen material may be posted or sold on criminal marketplaces alongside victims’ names, phone numbers, email addresses, and social media handles, creating opportunities for harassment, stalking, and sextortion.

According to the FBI, criminals use a mix of account takeover and social engineering tactics:

  • Password and PIN guessing: Criminals make high-volume login attempts using data from breaches, public social media profiles, leak sites, and other publicly available sources. Known victims may be targeted using name variations, birth dates, and other predictable personal details.
  • Fake customer service texts: Victims receive a message claiming their social media account will be locked or disabled. The criminal triggers a legitimate password reset request, then persuades the victim to hand over the resulting verification code.
  • Phishing emails: Lookalike support domains and email addresses warn of a “new login” and direct victims to a fake password change page designed to steal credentials.

This is different from the familiar “I recorded you” sextortion email, which typically relies on intimidation rather than a real account compromise. Still, if such an email includes a password you still use, change it immediately wherever it remains in use.

How to stay safe

There are several ways to reduce the risk of becoming a victim:

  • Avoid storing sensitive images on social media platforms or other internet-connected services when possible. Breaches and leaks happen, and those images can end up in the wrong hands.
  • Use a password manager to create a unique, long password for every account. Don’t base passwords or PINs on names, birthdays, or other public information.
  • Turn on multi-factor authentication (MFA), preferably with passkeys or hardware security keys where available. MFA is valuable, but criminals can still phish one-time codes and session cookies, so never approve an unexpected prompt or share a verification code.
  • Treat unexpected “account warning” links in texts and emails as suspicious. Open the service’s official app or type the known web address yourself instead. Don’t trust sponsored search results to take you to the correct website.

If you discover that intimate content has been stolen or shared, preserve any relevant links and evidence, secure the affected accounts, and report it through the FBI’s NCII reporting portal at ncii.ic3.gov.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

About the author

Pieter Arntz

Malware Intelligence Researcher

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.