FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures
In a new alert, the FBI said cybercriminals are targeting adults and minors in an attempt to steal their personal and intimate pictures in extortion campaigns.
The FBI's latest alert is a quiet confirmation of a shift in the extortion economy. The target is no longer the corporate server room; it is the private photo library on a personal phone. The bureau's warning that cybercriminals are hacking into online accounts to steal intimate pictures of adults and minors is not a novel technique, but a scaling of an old one.
The mechanics are unglamorous. Credential stuffing, phishing, and SIM-swapping remain the entry points. Once inside an account, the attacker does not need to be sophisticated. They simply search for the most damaging material and then apply the oldest pressure in the book: pay or be exposed. The FBI's involvement signals that this has moved beyond isolated incidents into a pattern with enough volume to warrant federal attention.
What is notable is the explicit mention of minors. That detail changes the legal stakes for the attacker and the emotional stakes for the victim. It also complicates the response. A victim who is a minor faces a different set of reporting obligations and support structures. The FBI's alert is a reminder that the infrastructure of extortion is now built on the most personal data a person owns.
For the remote workforce, this is not a distant threat. The same accounts that hold intimate images often hold work documents, client communications, and authentication tokens. A breach that starts as a personal violation can become a corporate liability in the same session. The FBI's advice—use strong, unique passwords and enable multi-factor authentication—is the same advice that has been issued for a decade. The difference is that the cost of ignoring it has never been higher.
The story here is not the hack. It is the normalization of extortion as a business model. The FBI's alert is a public acknowledgment that the line between personal privacy and professional security has dissolved. For anyone who manages a remote team, the lesson is quiet but firm: the weakest link is not the firewall. It is the human habit of reusing a password.