Sexual Exploitation Actors Stealing and Leaking Explicit Content

Imported from official source

Alert

Cybersecurity Classified by Officially

The Federal Bureau of Investigation (FBI) warns the public about sexual exploitation (SE) actors targeting adult and underage victims1 by illegally accessing their social media and personal accounts to steal and post their explicit content (also known as non-consensual intimate images, or NCII) for sale on criminal marketplaces. SE actors are using a variety of social engineering and cyber intrusion tactics to target specific individuals of interest — who may or may not be known to the actor — or general targets of opportunity. Once the sexually explicit images or videos are accessed and stolen, typically unbeknownst to the victim, SE actors are sharing or posting the content within community forums or selling them to illicit marketplaces. Personally identifiable information — such as name, date of birth, email, phone number, and social media username — is often posted along with the victim's explicit content, exposing them to continued re-victimization.

How Explicit Content is Accessed and Exposed

The FBI has observed SE actors using various tactics for illegal access to victim accounts, including:

  • Password and PIN Targeting SE actors use high volume password and PIN attempts on social media and personal accounts based on curated lists obtained from a variety of sources, such as data leak sites, social media, and open source. The lists include personal information, such as date of birth or name variations, when the victims are known to them.
  • Social Media Customer Service Impersonations SE actors send victims text messages stating their social media account is being disabled or locked unless they respond with a verification code. SE actors then request a password reset for the victim's social media account, which generates a code and is sent to the victim. Once the victim shares the code, the SE actor can reset the victim's password and access the account.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://www.ic3.gov/PSA/2026/PSA260810

    Officially imported this from Internet Crime Complaint Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Internet Crime Complaint Center — imported from official source
    Official source
    https://www.ic3.gov/PSA/rss RSS
    Imported
    September 24, 2026 09:30
    Versions
    1 recorded
    Identity
    260810

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.