Criminals are breaking into people’s personal accounts to steal explicit and intimate images and sell them online, the US Federal Bureau of Investigation has warned.
Hackers are breaking into social media and personal accounts to steal explicit pictures, which the agency refers to non-consensual intimate images, or NCII. They will then sell the images on criminal marketplaces, often with personal details about the person depicted attached, the FBI warned.
The cyber attackers use a whole variety of different tactics to break into the accounts of people they may or not know, it said. Users may not even know they are being attacked through the hacks, the FBI warned.
The pictures are then either shared within forums or sold on “illicit marketplaces”. They are often accompanied by personal information, including the victim’s name, date of birth, email, phone number and social media username.
The FBI said that the attacks were not only intrusive but served to re-victimise the people caught up in the attacks. That might extend to harassment, stalking, or even distributing the stolen content through people’s own social media pages, it warned.
harassment, sextortion, stalking or other targeted attacks, such as advertising stolen content on a victim's own social media page.
Hackers use a variety of tactics through the attacks.
They include taking passwords from leaks, or simply trying a variety of likely passwords taken form information known about the victim. They might also impersonate official messages from social media services – posing as a customer service agent who is looking to shut down an account, for instance – or sending genuine looking emails that make a person think that their account has been hacked and they need to change their password.
The FBI warned people to avoid storing sensitive images or videos on those sites in the first place, if possible. It also urged users to ensure that they use unique and complex passwords and logins, avoiding more easily guessed ones such as people’s names or birthdays.
It also warned people to be specifically careful about any messages that appear to be from the social media sites themselves. Users should check any link they are sent, or preferably go directly to the service’s official website to change any passwords.
It also asked anyone affected by the hacks to report it to the FBI, through a special website. That will ask for a variety of information, including when the content was stolen, how it was found, any links to sites that are sharing it, and any details about any other stalking or harassment that has happened since it was stolen.