The FBI Says Hackers Are Breaking Into Social Media Accounts to Steal Private Photos

The FBI issued a public alert on August 10, 2026, warning that cybercriminals are hacking into the social media accounts of adults and children to steal intimate explicit images and videos. In a Public Service Announcement, the Bureau's IC3 division — the part of the FBI that tracks internet crime — detailed how perpetrators rely largely on social engineering, which means tricking people into giving up access rather than breaking through technical security, to compromise targets who are subsequently extorted or have their stolen content published online IC3.
According to the advisory, attackers use several methods to gain account access. They try passwords that were leaked from other data breaches, hoping people reused the same one. They also impersonate customer service representatives, pretending to work for Instagram and other social media companies, and contact targets alleging that they need to recover their account. Some hackers use phishing emails that rely on fake websites designed to look like legitimate social media log-in pages TechCrunch.
The FBI wrote that victims often face re-victimization through harassment, sextortion, stalking, or other targeted attacks. In some cases, attackers advertise stolen content on a victim's own social media page. Rachel Tobac, CEO of the security awareness training firm SocialProof Security, said the FBI's public alert could indicate that these incidents are now on the rise. Tobac noted that these attacks especially target young boys and constitute a significant public health issue, given that victims are sometimes driven to self-harm in response.
The FBI did not respond to TechCrunch's request for comment about the alert. The FBI has interviewed sextortion victims as young as 8 years old, and the Bureau states that sextortion affects children of both genders and crosses all ethnic groups.
These types of sextortion crimes have been known for years, according to reporting on the current alert. The Bureau has documented escalating exploitation tactics across several recent advisories. In March 2025, the IC3 issued a public service announcement about violent online networks targeting vulnerable and underage individuals. In April 2026, the FBI's Milwaukee field office published an open letter to parents, guardians, and caregivers describing predator networks that employ tactics called Sadistic Online Exploitation, seeking out children online through mobile messaging.
The current advisory also follows a June 2023 warning from the FBI that criminals are increasingly using artificial intelligence to create sexually explicit deepfake content — realistic-looking but fake images or videos — for sextortion and harassment. That same month, the IC3 issued a separate public service announcement warning about malicious actors creating synthetic content by manipulating benign photos and videos.
The FBI advisory urges people to avoid storing sensitive and intimate pictures in online accounts. It recommends using unique passwords stored in a password manager, enabling multi-factor authentication, which means requiring a second step like a code sent to your phone in addition to your password, and being suspicious of unsolicited contact from people claiming to work for a social media company.
The methods described in the advisory are not new. They rely on well-documented weaknesses in how people manage their passwords and respond to trickery, rather than on sophisticated hacking of the platforms themselves. The escalation lies in the downstream impact and the deliberate targeting of minors, where account compromise cascades into severe psychological harm and, in extreme cases, physical self-harm.
In my view, what this advisory makes clear is that the threat to personal accounts remains heavily concentrated at the user layer. The combination of reused passwords and social engineering continues to bypass sophisticated platform defenses. For security practitioners, the FBI's guidance reinforces standard identity hardening, including unique credentials and multi-factor authentication. The burden of prevention, however, continues to fall on individual users, many of them children, who are least equipped to recognize a fake website or a bogus customer service representative.


