Hackers want your nudes. Here’s how to keep your privates, private
Sexploitation isn’t a new concept. Long before the internet, people blackmailed others over sexually explicit photos or videos. But this week, the US Federal Bureau of Investigation released a fresh warning around hackers and sexortion—an alert aimed at both adults and children.
In its public service announcement, the FBI says sexual exploitation actors have been breaking into “social media and personal accounts” to download any saved explicit content. The stolen images and video then gets spread to criminal forums and marketplaces, often with personal details like name, email, phone number, social media username, and date of birth also shared.
Victims usually don’t immediately know their accounts were compromised. Instead, they may only realize the hack after receiving a demand for money or additional explicit material. Or if other forms of harassment or attack begin.
So, how do you prevent sextortion from hackers? The same as preventing any unauthorized access to your accounts. Be careful about what you click and protect your accounts with good login habits:
- Use unique, strong passwords and PIN codes for all accounts
- Ignore messages that threaten account lockout unless you reply with a verification code
- Change your password by logging into a site directly, then going to your settings. Don’t click a link in an email unless you just directly requested a password reset
- Switch to passkeys whenever possible
These tips protect you from credential stuffing attacks and phishing attempts. A verification code request? A hacker can initiate a password reset for an account that generates a real verification code. Share that info with the bad actor and boom—now they can change your password and take over. Email messages with password reset links? Might be a hacker impersonating the real service, hoping to steal your login details either directly or through stealing authentication cookies or tokens.
My advice? Use passkeys often you can. This form of login is naturally more protected against credential stuffing and phishing attempts. Every passkey is unique and tied to a specific device (e.g., security hardware key) or service (Microsoft account, Google account, independent password manager). Hackers can’t exploit a passkey in the same ways as a password.
If you’re stuck with passwords, make them complex and unique, and also enable two-factor authentication wherever possible. You can offload all the work to a password manager—it’s actually the better way to be lazy about passwords.