The Federal Bureau of Investigation has issued a public service announcement warning that cybercriminals are actively targeting consumer social media and online accounts to steal explicit photos and videos. These account takeover schemes feed into larger criminal operations involving sextortion, online blackmail, and the illicit sale of victims’ personal data across underground marketplaces. Attackers leverage stolen media to coerce victims into paying ransoms or providing additional private media, often using the target’s compromised credentials to re-victimize them directly on their own public profiles.
In a paired alert issued the same day, the FBI joined forces with the National Collegiate Athletic Association (NCAA) to warn university compliance staff, athletic department leaders, and coaches that student-athletes are specifically being targeted in similar sexual exploitation schemes.
How Threat Actors Compromise Accounts
Rather than exploiting complex software vulnerabilities, these campaign operators rely heavily on credential harvesting, smishing, and social engineering to bypass authentication controls. The primary vector involves tricking account holders into relinquishing access credentials or multi-factor authentication (MFA) tokens through urgent, deceptive communications.
The FBI highlighted several key indicators and tactics used in these campaigns:
- Lure Texts (Smishing): Targets receive unsolicited text messages claiming their account is scheduled to be disabled unless they immediately submit a verification code.
- Fake Password Resets: Victims receive unsolicited emails alleging a new login attempt took place, accompanied by an embedded link directing them to a credential-harvesting landing page disguised as a legitimate password reset portal.
- MFA Proxy Interception: When victims interact with these fraudulent portals, attackers capture usernames, passwords, and real-time One-Time Passwords (OTPs), allowing them to complete login sequences and establish persistent sessions.
Once access is gained, threat actors scrape private direct messages, photo archives, and connected cloud storage repositories for explicit images or videos. They also aggregate personally identifiable information (PII)—including names, dates of birth, phone numbers, email addresses, and social media handles—to construct extortion dossiers.
These dossiers are then sold on criminal forums or used directly against the victim. Extortionists frequently demand monetary payment or additional explicit content under threat of broadcasting the stolen media to the victim’s family, friends, or school community. In severe cases, attackers hijack the victim’s social media page to advertise the stolen content directly to their followers.
Increased Risk for Higher Education and Student-Athletes
The joint alert from the FBI and the NCAA underscores an expanding blast radius for academic institutions and collegiate athletic programs. Student-athletes possess high public profiles, active social media presences, and clear ties to institutional brands, making them high-value targets for coercion and brand impersonation.
While the primary harm of sextortion is personal and psychological, account takeovers involving student-athletes create operational and reputational risks for institutions:
- Brand and Compliance Exposure: Compromised accounts can be used to broadcast illicit material or fraudulent links under the banner of a recognized university program or athlete.
- Lateral Account Risks: Students frequently reuse passwords across personal accounts, social media platforms, and institutional Single Sign-On (SSO) portals, opening avenues for broader campus network exposure.
- Public Impersonation: Hijacked accounts allow threat actors to target teammates, fans, and athletic staff with secondary phishing lures, compounding the impact across the institution.
Threat Landscape Context and Enforcement
This public alert reflects a persistent surge in financially motivated and predatory account takeover schemes. The FBI previously issued warnings regarding sharp increases in sextortion complaints in September 2021, and law enforcement agencies continue to prioritize the prosecution of these networks.
Penalties for these offenses are severe when perpetrators are apprehended. For example, in May, a Canadian national was sentenced to 33 years in federal prison following an eight-year sextortion scheme that targeted more than 145 children across the United States. Despite high-profile prosecutions, the low barrier to entry for credential harvesting tools and the high success rate of urgency-based phishing lures keep these tactics widely utilized by cybercriminals.
Mitigation and Defense Recommendations
Preventing credential harvesting and subsequent account compromises requires a combination of strict authentication hygiene and operational awareness across both individual users and institutional networks.
For End Users and Student-Athletes:
- Ignore Verification Prompts: Never reply to unsolicited SMS messages or emails asking for verification codes, temporary PINs, or password resets. Legitimate service providers will never prompt users to text back security codes or verify access via unrequested links.
- Eliminate Sensitive Media Storage: Avoid storing unencrypted explicit photos or videos on cloud-connected services, social media drafts, or internet-accessible direct message threads.
- Password and MFA Hygiene: Utilize complex, unique passwords that exclude easily researchable PII such as birth dates, middle names, or athletic jersey numbers. Enable multi-factor authentication across all personal and institutional accounts.
For Institutional IT and Athletic Departments:
- Shift Away from SMS MFA: Where possible, migrate users away from SMS-based multi-factor authentication toward phishing-resistant authentication methods, such as FIDO2/WebAuthn hardware keys or push-based authenticator apps with number-matching enabled.
- Awareness Campaigns: Conduct immediate briefings for athletic staff, coaches, and student-athletes outlining the specific smishing lures (e.g., “account disabled” texts and unexpected login alerts) currently in circulation.
- Incident Protocol: Instruct targets of extortion schemes to cease all communication with attackers immediately, preserve communications for evidence, and report the incident to campus security and law enforcement without paying ransom demands.
Related content
Black Hat USA 2026 Vendor Wrap-Up: Focus Turns to Agentic AI and Virtual Patching
Security NewsBlack Hat USA 2026: AI Agents, Continuous SecOps, and Exposure Management Take Center…
Security NewsAttackers Spoof OAuth Client IDs to Evade Microsoft Cloud Sign-in Logs
Security NewsActively Exploited Critical OS Command Injection Flaws in FortiSandbox (CVE-2026-39808,…
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call