Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. FBI: Hackers Using Social Engineering to Breach Accounts and Steal Explicit Content
FBI: Hackers Using Social Engineering to Breach Accounts and Steal Explicit Content
NEWS

FBI: Hackers Using Social Engineering to Breach Accounts and Steal Explicit Content

The FBI warns hackers are breaching social media accounts to steal explicit content via credential stuffing, impersonation, and fake clone sites.

Dylan H.

News Desk

August 13, 2026
3 min read

The FBI has issued a public alert warning that hackers are systematically breaching social media accounts — belonging to both adults and children — to steal explicit content. The stolen material is then sold on criminal marketplaces, often bundled with the victim's personal information, enabling ongoing re-victimization through harassment, sextortion, stalking, and targeted attacks. In some cases, stolen content is advertised back to victims directly on their own social media pages.

How the Attacks Work

The FBI identified several distinct attack methods depending on the target and the attacker's prior knowledge:

Credential stuffing from breached data — Attackers use leaked passwords and PINs sourced from data breach sites to gain direct account access. Victims who reuse passwords across platforms are at highest risk.

Password guessing against acquaintances — When targeting known individuals, attackers try password variations based on birthdates, names, or other personal details they already possess.

Platform impersonation — Threat actors impersonate social media representatives, claiming the victim's account has been compromised. Victims are then "message bombed" with texts requesting password resets or verification codes, which enable account takeover.

Cloned phishing sites — Fake versions of social media login pages capture credentials in real time, forwarding them directly to the attacker.

Who Is Being Targeted

Both adults and children are targeted. Victims include random targets of opportunity and known acquaintances of the attackers. The combination of personal information bundled with explicit content creates compounding harm — victims face not just exposure, but ongoing targeted abuse campaigns.

Real-World Cases

The scale of individual attacks underscores the severity of the threat:

  • An Illinois man (27) pleaded guilty in February after hacking approximately 600 women's Snapchat accounts to steal explicit content.
  • A former University of Michigan assistant coach was indicted for accessing the medical records of approximately 150,000 students across more than 100 universities, using that information to breach female athletes' social media accounts.

Snapchat is specifically mentioned in connection with high-profile cases, though the advisory covers social media platforms broadly.

How to Protect Yourself

The FBI's advisory implicitly points to the attack vectors as the defensive roadmap:

  • Use unique passwords for every account — avoid personal information like birthdates or names
  • Enable multi-factor authentication on all social media accounts to block credential-based takeovers
  • Be skeptical of unsolicited messages claiming to be from platforms requesting resets or verification codes — legitimate platforms don't operate this way
  • Verify login page URLs carefully before entering credentials — cloned sites are designed to look identical to the real thing
  • Do not respond to message bombing with verification codes under pressure

The advisory reinforces that social engineering remains one of the most effective attack vectors precisely because it bypasses technical controls by manipulating human behavior. No amount of platform security protects an account when the user hands over the credentials directly.

#social-engineering#fbi#phishing#account-takeover#sextortion

Related Articles

When Credentials Are No Longer Enough: Device Trust in the AI Era

AI is making phishing, credential theft, and MFA bypass faster and cheaper than ever. As traditional trust signals — passwords, MFA codes, IP geolocation — become routinely defeated, security teams must shift toward hardware-anchored device trust and continuous session evaluation to maintain meaningful access control.

6 min read

Valve Notifies Steam Hardware Customers of CEVA Logistics Data Breach

Valve is notifying Steam hardware customers in Europe that hackers stole shipping and personal data after compromising its logistics partner CEVA Logistics between July 29 and August 1, 2026. No Steam account credentials or payment data were exposed, but the stolen PII creates a high-quality phishing dataset.

4 min read

Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

Phishing kits now fingerprint victims via user-agent headers to deliver OS-specific payloads automatically — device code phishing attacks spiked 1,380% in...

4 min read
Back to all News