Tuesday, August 25, 2026

Independent technology reporting and practical analysis

Manila ·
CYBERSECURITY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Cybersecurity / news

FBI Warns Hackers Are Stealing Explicit Photos and Blackmailing Victims—Here’s How to Stay Safe

The FBI has issued a new warning about sextortion, saying hackers break into social media and personal accounts to steal intimate images and then demand money or more explicit content.

Featured image for FBI Warns Hackers Are Stealing Explicit Photos and Blackmailing Victims—Here’s How to Stay Safe
Featured image for FBI Warns Hackers Are Stealing Explicit Photos and Blackmailing Victims—Here’s How to Stay Safe

The FBI has issued a fresh public alert about sextortion, a form of online extortion in which hackers gain access to private social media and other personal accounts to steal sexually explicit photos and videos. According to PCWorld, the warning is aimed at both adults and children.

According to the FBI, attackers break into accounts and download any saved explicit content. They then distribute the stolen images and videos on criminal forums and marketplaces, often attaching personal details such as the victim's name, email address, phone number, social media username, and date of birth. In many cases, victims do not immediately realize their accounts were compromised. They may only discover the hack after receiving a demand for money or additional explicit material, or after other forms of harassment or attack begin.

PCWorld's advice for preventing this type of attack mirrors standard account security practices: be careful about what you click and protect your accounts with strong login habits. The article highlights two common tactics used by hackers to take over accounts. First, a hacker can initiate a password reset that sends a legitimate verification code to the victim. If the victim shares that code with the attacker, the attacker can then change the password and lock the victim out. Second, phishing emails may contain fake password reset links that appear to be from a real service. These links are designed to steal login credentials either directly or by capturing authentication cookies or tokens.

The PCWorld writer recommends using passkeys whenever possible. Passkeys are unique to each service or device, whether a hardware security key, a Microsoft or Google account, or an independent password manager. Because of this design, passkeys are naturally more resistant to credential stuffing and phishing attacks than traditional passwords. A hacker cannot exploit a passkey in the same way as a stolen or reused password.

If passkeys are not available, the article advises creating complex, unique passwords for each account and enabling two-factor authentication wherever possible. To manage this burden, it suggests using a password manager, which can generate and store strong passwords automatically. The writer calls this the "better way to be lazy about passwords."

While the FBI alert describes a disturbing trend, the preventive measures are straightforward. Avoiding suspicious links, never sharing verification codes, and adopting passkeys or a password manager can significantly reduce the risk of account takeover and subsequent sextortion.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Featured image for Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud
Cybersecurity

Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud

Philips LatteGo 4400 Series espresso machine on a kitchen counter.
Guides

Philips LatteGo 4400 espresso machine drops to AU$613 on Amazon Australia

Alice talks to Nora and Frank
Entertainment

How AI and assistive tools are helping disabled actors like Steve Way thrive on 'Furious'