
The FBI has issued a fresh public alert about sextortion, a form of online extortion in which hackers gain access to private social media and other personal accounts to steal sexually explicit photos and videos. According to PCWorld, the warning is aimed at both adults and children.
According to the FBI, attackers break into accounts and download any saved explicit content. They then distribute the stolen images and videos on criminal forums and marketplaces, often attaching personal details such as the victim's name, email address, phone number, social media username, and date of birth. In many cases, victims do not immediately realize their accounts were compromised. They may only discover the hack after receiving a demand for money or additional explicit material, or after other forms of harassment or attack begin.
PCWorld's advice for preventing this type of attack mirrors standard account security practices: be careful about what you click and protect your accounts with strong login habits. The article highlights two common tactics used by hackers to take over accounts. First, a hacker can initiate a password reset that sends a legitimate verification code to the victim. If the victim shares that code with the attacker, the attacker can then change the password and lock the victim out. Second, phishing emails may contain fake password reset links that appear to be from a real service. These links are designed to steal login credentials either directly or by capturing authentication cookies or tokens.
The PCWorld writer recommends using passkeys whenever possible. Passkeys are unique to each service or device, whether a hardware security key, a Microsoft or Google account, or an independent password manager. Because of this design, passkeys are naturally more resistant to credential stuffing and phishing attacks than traditional passwords. A hacker cannot exploit a passkey in the same way as a stolen or reused password.
If passkeys are not available, the article advises creating complex, unique passwords for each account and enabling two-factor authentication wherever possible. To manage this burden, it suggests using a password manager, which can generate and store strong passwords automatically. The writer calls this the "better way to be lazy about passwords."
While the FBI alert describes a disturbing trend, the preventive measures are straightforward. Avoiding suspicious links, never sharing verification codes, and adopting passkeys or a password manager can significantly reduce the risk of account takeover and subsequent sextortion.
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST

