FBI Warns of Social-Engineering Attacks to Steal Accounts and Explicit Content
The FBI issued a public alert on a surge of social-engineering attacks in which hackers breach victims' accounts โ often via SIM-swapping and phished recovery flows โ to steal explicit photos and videos and extort victims.
Key Facts
| Attribute | Detail |
|---|---|
| Authority | FBI (public alert) |
| Method | Social engineering, SIM-swapping, phished account-recovery flows |
| Target | Personal accounts; explicit content as extortion leverage |
| Guidance | Account-recovery hardening, MFA, caution with recovery flows |
Context
The advisory is a reminder that credential-theft campaigns now target the personal-content layer โ not just financial assets โ and that account-recovery flows have become a primary attack surface. The same social-engineering tradecraft applies to enterprise accounts, where attackers abuse helpdesk and recovery processes to bypass MFA. For AU/NZ readers it parallels ACSC guidance on account compromise and reminds organisations to treat recovery-process abuse as an MFA bypass vector, not just a consumer problem.
Related Pages
- Long Running Data Theft Campaign Targeting Salesforce And Servicenow โ credential-harvesting campaigns
Sources: raw/digests/Cyber-Digest-2026-08-13