FBI Warns: Hackers Use Social Engineering to Hijack Accounts and Steal Explicit Content
The FBI has issued a new public alert warning that threat actors are increasingly using social engineering and cyber intrusion techniques to compromise social media accounts belonging to both adults and children, stealing explicit content and trading it on criminal marketplaces. According to the bureau's Monday notice, attackers are targeting "specific individuals of interest—who may or may not be known to the actor—or general targets of opportunity," often publishing stolen personal information alongside the illicit content. Victims frequently face re-victimization through harassment, sextortion, stalking, and targeted attacks, including having stolen content advertised on their own social media pages.
The tactics documented by the FBI include repeated credential-stuffing attempts using passwords and PINs harvested from data leak sites, as well as variations of birthdays and names when the attacker personally knows the victim. In other cases, criminals impersonate social media company representatives, bombarding targets with text messages requesting password resets or delivering one-time codes that allow the attacker to take over the account directly. Some operations have even relied on cloned social media platforms designed to mimic legitimate login pages, capturing credentials the moment they are entered. Security professionals strongly recommend that users verify any unsolicited password reset requests through official channels and routinely audit their credentials using an password strength checker to ensure unique, complex passwords across every account.
The alert follows several high-profile prosecutions related to similar schemes. In February, a 27-year-old Illinois man pleaded guilty after the Department of Justice accused him of orchestrating a campaign that compromised approximately 600 women's Snapchat accounts. Last year, federal prosecutors also indicted a former University of Michigan assistant football coach for infiltrating student-athlete databases at more than 100 colleges—accessing medical records for roughly 150,000 individuals—and leveraging that data to break into female student athletes' social media profiles. Given the scale of credential exposure on the dark web, individuals can confirm whether their information has appeared in known dumps by running an email breach check and immediately rotating any compromised credentials.
To reduce exposure, the FBI advises enabling multi-factor authentication on all social media accounts, scrutinizing unsolicited messages that reference account activity, and avoiding SMS-based verification codes shared with unknown contacts. Users should also conduct a comprehensive privacy checkup across their accounts to review active sessions, authorized third-party apps, and recovery options. As these social-engineering campaigns continue to evolve, defenders stress that account hygiene—not just endpoint security—remains the first line of defense against targeted exploitation.