A New Twist on an Old Crime
The FBI has issued a fresh alert with a disturbing twist on an old crime. According to the bureau, cybercriminals are hacking directly into victims’ online accounts – email, cloud storage, and messaging services – to steal personal and intimate photographs, then leveraging those images in extortion campaigns aimed at both adults and minors. The shift from tricking someone into sending images to simply breaking in and taking them changes who is at risk and how the crime unfolds.
From Trickery to Breaking In
Traditional “sextortion” often began with a fake romance or a compromised account that convinced a victim to share material willingly. The pattern the FBI describes removes that step. Attackers gain access through stolen credentials, reused passwords, or a compromised device, then rifle through synced photos as if they owned the account. Because so many people’s intimate images live automatically backed up to a cloud service, a single breached login can expose years of private life in minutes.
How the Extortion Works
The extortion that follows is brutal in its mechanics. Victims – or, in the case of minors, their families – receive a message demanding payment or further material, backed by the threat of the images being published or sent to contacts. The FBI notes that the targeting spans adults and children, which raises the urgency: young people may be less likely to report the abuse out of fear or shame, exactly the reaction extortionists depend on.
Why Reused Passwords Open the Door
Behind the alert sits a familiar root cause: weak account security. When one password is reused across many services, a single leak – at a retailer, a game, a forum – can unlock the account that holds everything. Multi-factor authentication (MFA) is the single most effective defence, because even a perfect stolen password is useless without the second step. The FBI and allied agencies have long urged MFA on every account that offers it, and this alert is another data point for why.
Cut Your Exposure: Five Steps
There are concrete steps anyone can take today. Turn on MFA everywhere it is available, prioritising email and cloud storage, since those are the skeleton keys to the rest of your life. Stop reusing passwords; a password manager removes the temptation. Review which apps and devices have access to your photo library and revoke anything unfamiliar. And consider keeping intimate images off automatically-synced cloud backups, or storing them in a separately encrypted space rather than the default gallery.
A Conversation for Parents
For parents, the alert is a conversation starter rather than a scare story. Talk with children about not sharing intimate images, about what to do if they are threatened (tell a trusted adult and report it – do not pay), and about the reality that extortionists rely on silence. Reporting to the platform, to local police, and to the FBI’s IC3 tip line (ic3.gov) both helps the individual case and builds the intelligence picture that disrupts these rings.
If You Are Targeted, Do This
If you are targeted, the guidance is consistent: do not pay, preserve the evidence (screenshot the demands and sender), lock down the compromised account immediately by changing the password and signing out all sessions, and report. Paying funds the operation and rarely stops the threats. The FBI’s message is that this is a growing, organised threat – but one where basic hygiene and fast reporting sharply reduce the damage.
Source: Original report. Rewrite for Your News Website.


