Comply with ZDNET: Add us as a most popular supply on Google.
ZDNET’s key takeaways
- Hackers are stealing and promoting specific pictures from social media accounts.
- The hackers use social engineering and different techniques to realize entry.
- Keep away from posting any such photographs and be careful for potential hacking makes an attempt.
Storing sexually specific pictures of your self on social media or private accounts is rarely an important concept. That is very true now because the FBI is warning about hackers stealing and promoting such photographs.
In an advisory revealed on Monday, the FBI stated that sexual exploitation hackers are concentrating on each adults and minors by illegally hacking into their social media and private accounts to seize specific photographs. From there, the attackers promote the pictures on the darkish net, usually accompanied by private particulars such because the sufferer’s title, date of start, electronic mail tackle, and cellphone quantity.
As soon as the private photographs and particulars are up for grabs on the darkish net, a prison can exploit them to run sexual extortion (aka, sextortion) schemes by which they blackmail the focused individual. That re-victimizes the sufferer, inflicting them additional ache and grief.
Hackers sometimes use varied social engineering and cyber intrusion strategies to realize entry to the social media and private accounts of their targets. In its advisory, the FBI highlighted three totally different techniques.
- Focusing on passwords and PINs. Right here, the hackers begin with curated lists of internet sites which have suffered information leaks. These lists sometimes embrace the names, birthdates, and different private particulars of customers. The hackers then flip to password-cracking software program and different brute-force instruments to attempt to get hold of passwords and PINs related to the leaked accounts.
- Impersonating customer support. With this tactic, a hacker sends textual content messages to social media customers, posing as the corporate’s customer support rep and claiming that the consumer’s account is being disabled or locked. From there, the hacker requests a password reset from the precise firm. After the consumer shares that code with the hacker, the sufferer’s password is reset, permitting the hacker to entry their account.
- Phishing makes an attempt. Typically, hackers will create domains and electronic mail accounts that impersonate customer support assist from a social media firm. The hackers then ship emails to focused customers, warning them of recent logins to their accounts. These emails embrace a malicious hyperlink prompting the consumer to alter their password, thus permitting the hackers to realize entry to their account.
To keep away from turning into a sufferer of those schemes, the FBI gives the next suggestions:
- This is the primary rule. Do not retailer delicate photographs or movies on social media platforms or public web websites.
- Use distinctive and complicated passwords, passphrases, and PINs in your social media websites and private accounts. When creating passwords and passphrases, do not embrace any private data, corresponding to your date of start or your partner’s title.
- When accessible, join multi-factor authentication to confirm any login makes an attempt.
- Keep away from clicking on embedded hyperlinks in emails and textual content messages. As a substitute, go on to the web site in query to check in to your account.
- Use a pc as a substitute of your cell gadget to view an surprising or suspicious electronic mail. Right here, you may hover over any embedded hyperlinks to search for atypical URLs or formatting irregularities.
- Watch out if you happen to obtain a brief password, PIN reset, or entry code that you just did not request. By no means share login credentials with anybody, even when the sender claims to be from a social media web site or different firm the place you’ve gotten an account. Use the corporate’s web site or app if you could change your password or PIN.





