The FBI has issued a fresh public service announcement highlighting a disturbing rise in sextortion schemes, where hackers breach social media and personal accounts to steal explicit content. According to the FBI’s Internet Crime Complaint Center (IC3), these criminals are downloading saved photos and videos, then distributing them on criminal forums alongside victims’ personal details, including names, emails, phone numbers, and dates of birth. Victims often remain unaware of the breach until they receive demands for money or additional explicit material.
This alert underscores a critical shift in cybercrime: attackers are no longer just after your credit card data. They are targeting your privacy and using it as leverage. Understanding how these attacks work and implementing robust sextortion prevention strategies is now essential for every internet user.
How Sextortion Attacks Unfold
Sextortion is not a new concept, but the scale and sophistication of these attacks have grown significantly. The FBI’s warning focuses on how actors break into “social media and personal accounts” to harvest saved explicit content. Once stolen, this material is often shared on dark web marketplaces or used to blackmail the victim directly.
The insidious nature of these attacks lies in their stealth. You may not know your account was compromised until it is too late. The hacker initiates contact through a message demanding payment or new explicit content, often threatening to release the stolen material to your contacts, employer, or the public. In some cases, victims only discover the breach when they notice unusual activity, such as login alerts from unknown devices or messages sent from their account without their consent.

Core Security Measures to Stop Account Takeovers
The FBI’s guidance aligns with fundamental cybersecurity best practices. Since these attacks rely on unauthorized access, the most effective defense is securing your accounts against credential theft and phishing.
- Use unique, strong passwords: Never reuse passwords across accounts. A breach of one service should not compromise your others.
- Enable two-factor authentication (2FA): Add an extra layer of security that requires a second verification step, such as a code from your phone or a biometric scan.
- Adopt passkeys where possible: Passkeys are a modern, phishing-resistant alternative to passwords. They are tied to a specific device or service and cannot be exploited through traditional credential stuffing attacks.
- Ignore suspicious lockout messages: If you receive a message claiming your account will be locked unless you verify a code, do not respond. Hackers often initiate password resets to generate real verification codes, which they then use to take over your account.
These steps are not just theoretical. In practice, enabling 2FA and using passkeys significantly reduces the risk of unauthorized access. Password managers can help you generate and store complex, unique passwords for every account, eliminating the temptation to reuse credentials.
What to Do If You Are Targeted
If you suspect you are a victim of sextortion, the FBI advises against paying the ransom or sending additional explicit content. Doing so rarely ends the harassment and often escalates the demands. Instead, take these immediate steps:
- Secure your accounts: Change your passwords by logging directly into the service through its official website or app. Do not click links in suspicious emails.
- Document everything: Save screenshots of messages, demands, and any threats. This evidence is crucial for law enforcement.
- Report the crime: File a report with the FBI’s IC3 at ic3.gov. You can also contact your local law enforcement agency.
- Seek support: Organizations like the National Center for Missing and Exploited Children (NCMEC) offer resources and assistance for victims of online exploitation.

What This Means for You
This FBI warning is a clear signal that digital privacy is under active threat. Sextortion attacks exploit trust and shame, making them particularly effective. However, they are also preventable with the right security habits.
For everyday users, the takeaway is straightforward: treat your accounts as you would your home. Use strong, unique locks (passwords and 2FA), and never leave the door open for strangers (phishing links or suspicious messages). The effort required to secure your accounts is minimal compared to the potential fallout of a breach.
How to Get Started
Implementing these security measures does not require technical expertise. Start by enabling 2FA on your most important accounts, such as email, social media, and banking. Consider switching to a password manager to handle the complexity of unique passwords. For supported services, explore passkeys as a more secure and convenient login option.
The FBI’s alert is not just a warning; it is a call to action. By taking these steps, you protect not only your privacy but also your peace of mind.
Source: PCWorld
Over to you: Have you enabled two-factor authentication on your social media accounts yet?



