August 14, 2026

Could Your Social Media Account Be the Next Target for Sextortion Scams?

by
Abhijay Bhatnagar
August 14, 2026
Copy link to blog

Most sextortion stories start the same way: someone gets a weird “new login” email, a “your account will be disabled” text, or a message asking for a verification code. It feels urgent. You react fast. And that’s the trap. The FBI is warning that attackers are taking over adults’ and kids’ online accounts to steal private photos/videos and use them for sextortion, harassment, stalking, or resale—often bundled with personal details like your name, DOB, email, phone number, and usernames.  This post breaks down how these scams actually work, what the most common lures look like, and the exact steps to protect yourself and respond if you’re targeted.

How sextortion starts now: account takeover, not “random DMs”

That “new login” alert you almost clicked? That’s the whole game.

A lot of people still picture sextortion scams as some stranger sliding into DMs and asking for photos. That still happens, but the faster, uglier pattern the FBI is calling out is social media account takeover: attackers hijack an account (yours, or someone you trust), pull whatever private content they can, then use it to blackmail you or sell it.

Here’s why that shift matters. When a scammer has your login, they don’t need to “convince” you to send anything. They can:

  • Search DMs, camera rolls, and archived content for sexually explicit images/videos
  • Grab screenshots of conversations, contacts, and followers
  • Change passwords and recovery settings to lock you out
  • Use your own account to reach friends and family for extra pressure

The FBI warning is blunt about what happens next: once explicit content is stolen, sextortion actors may post or sell it on criminal marketplaces, often bundled with personal details like your name, date of birth, email, phone number, and social media usernames.

That bundle is what makes it stick. You’re not dealing with one creep and one threat. You’re dealing with a file that can be traded, resold, and reused. The FBI notes that this can lead to re-victimization: harassment, sextortion, stalking, and even attackers advertising stolen content on a victim’s own social media page.

The “panic click” is the entry point

The most relatable part is also the most dangerous: the moment it feels urgent.

You see a message that says your account was accessed. Or your account will be disabled. Your brain goes, “I need to fix this right now.” That split-second reaction is what scammers design for—because if they can get you to hand over access once, they can turn a normal account into a long-term sextortion problem.

The 3 lures that keep working (and the one rule that kills them)

Once attackers decide they want your account, they don’t start with threats. They start with a login trap—something that makes you act fast and think later.

The FBI called out a few repeat patterns that show up again and again in sextortion-driven account takeover attempts.

Lure #1: “Your account will be disabled” texts that demand a code

This one usually hits by SMS, WhatsApp, or a DM.

The message claims your account is about to be locked, deleted, or “reported.” You’re told to confirm ownership by sending back a verification code. The FBI explicitly flags unsolicited texts claiming an account will be disabled unless you provide a verification code.

What’s happening behind the scenes:

  • The scammer is trying to log in to your account
  • The real platform sends you an MFA code
  • You hand them the code, and you’ve just approved the takeover

Lure #2: “New login” emails with an embedded password reset link

You get an email that looks official: “New login detected” or “Suspicious sign-in.” It includes a button/link to “secure your account.”

The FBI also flags unsolicited emails referencing a new login with an embedded link to reset a password.

What to watch for:

  • A link that rushes you (“verify in 10 minutes”)
  • A login page that looks right but isn’t (phishing)
  • A reset flow that ends with you giving away a code

Lure #3: Password reset bait (aka “I can’t access your account, help”)

This one is simpler. The attacker triggers password reset flows repeatedly, then contacts you pretending to be:

  • the platform,
  • a “support agent,” or
  • even a friend who “accidentally sent a code to your number.”

Goal: get you to share a reset code, temporary password, or PIN.

The one rule that kills all three

Legit platforms will not ask you to share a verification code, temporary password, or PIN reset code. If someone asks for it, it’s a scam.

If you remember nothing else, remember this: codes are approvals. Treat them like a signature.

Why student-athletes (and anyone with visibility) get targeted harder

Once you understand the lures, the next question is uncomfortable but practical: why do some people get hit harder than others?

The FBI and NCAA have warned that cybercriminals are targeting student-athletes’ online accounts in sexual exploitation schemes, and they’ve pushed coaches and athletic departments to raise awareness.  That isn’t random. Visibility changes the math for scammers.

Visibility gives attackers three things they want

  1. A pressure cooker

If you’re a student-athlete, creator, streamer, or anyone whose reputation is tied to a public audience, the threat of exposure carries extra weight. Scammers know you may feel like you have “more to lose,” and they use that social pressure to rush decisions.

  1. A ready-made target list

Public accounts come with public graphs: followers, teammates, classmates, tagged photos, comments, and mutuals. That makes “prove it to your friends/team” threats easier to execute—because the attacker doesn’t have to guess who matters to you.

  1. A clearer “why you” story

Attackers don’t need to invent credibility. Your profile already signals:

  • where you go to school / work
  • what team or community you’re part of
  • who might respond if they message from your account

That context makes account takeover + sextortion attempts feel more personal, even when it’s scripted.

Guardrails for public-facing accounts (simple, tactical)

These aren’t about paranoia. They’re about removing easy wins.

Tighten what strangers can learn from your profile

  • Reduce link-in-bio sprawl. Fewer links = fewer places to impersonate you or route friends into scams.
  • Audit what’s visible. If your email/phone is public for “business inquiries,” that’s also a doxxing shortcut.

Make your DMs harder to use as a weapon

  • Limit DMs from people you don’t follow.
  • Treat message requests like cold calls: if it’s urgent, it’s probably bait.

Set one response rule for “urgent” messages

If someone claims your account is at risk and wants you to act fast, pause and verify inside the app (settings/security), not through a link in a message. The FBI specifically warned people not to reply to messages asking for verification codes or to click password reset links.

Defense checklist: make account takeover genuinely hard

If your account has any real-world stakes (work, school, a public profile), treat security like a routine—same way you treat locking your car. The FBI’s guidance is clear: attackers are getting in through basic account weaknesses, then using what they find for sextortion.

1) Passwords: stop giving attackers “one guess”

  • Use a strong, complex password for every social account.
  • Make it unique per account. Reused passwords turn one breach into five takeovers.
  • Avoid passwords/PINs that include names, birthdays, or other easy personal info. The FBI specifically calls this out as risk-reducing.

2) Turn on MFA (and pick the strongest option you can)

The FBI recommends enabling multi-factor authentication whenever possible.

Do it for:

  • your social accounts
  • your email (because email often controls password resets)

3) Lock down account recovery (this is where takeovers stick)

Recovery settings are the “back door.” Review and update:

  • recovery email
  • recovery phone number
  • any “backup codes” location (store them safely, offline if you can)
  • connected devices/sessions (sign out of anything you don’t recognize)

4) Treat codes + reset links as hazardous by default

The FBI warns people not to reply to messages asking for verification codes and not to click password reset links in unsolicited texts/emails.

If you need to reset a password, do it the boring way:

  • open the app
  • go to settings/security
  • start the reset from there

5) Stop storing sensitive content where an account takeover can grab it

This is blunt but important: the FBI advises against storing explicit photos or videos on social media accounts or other internet-accessible sites.

Even if your account is “private,” a hijacked login sees what you see.

6) Add a privacy buffer: separate your real contact info from your accounts

A lot of sextortion fallout is fueled by doxxing—your real number/email becoming part of the pressure campaign.

Where possible, use masked emails and phone numbers for signups and recovery so your primary contact info isn’t the thing getting traded around. Cloaked is one example: it lets you create separate emails/phone numbers for different accounts, which can reduce how much personal data gets exposed if an account is compromised.

If you’re targeted: what to do in the next 30 minutes

If you get a sextortion threat, your goal is simple: stop the damage from spreading and get the right people involved fast. The FBI has advised victims to stop all interaction immediately and contact law enforcement as soon as possible.

Minute 0–5: Stop feeding the attacker

  1. Don’t reply. Don’t negotiate. Don’t argue.

Silence cuts off their ability to steer you into panic decisions.

  1. Don’t send money or gift cards.

Paying doesn’t buy you “closure.” It often buys you a bigger target on your back.

Minute 5–12: Preserve evidence (before it disappears)

  1. Screenshot everything (threats + account details), including:
  • usernames/handles (their account + any burner accounts)
  • the exact messages
  • timestamps
  • any URLs/links they sent
  1. If it’s a call or voice note, screen-record or save the audio if the app allows it.

This isn’t busywork. Evidence is what platforms and investigators can actually use.

Minute 12–20: Secure your accounts (containment)

  1. Change your password immediately (start with email first if you suspect takeover).

If your email is compromised, every other reset is compromised too.

  1. Revoke active sessions / log out of other devices inside account settings.

If the attacker is already in, password changes alone may not kick them out.

  1. Turn on MFA if it’s not already enabled.

Minute 20–25: Report to the platform (get the account back + limit reach)

  1. Use in-app reporting for:
  • impersonation / hacked account
  • blackmail / harassment
  • non-consensual intimate imagery (if applicable)
  1. Ask trusted friends to report the attacker’s account too. Platforms move faster when multiple reports hit.

Minute 25–30: File reports (this helps you and future victims)

  1. File a report with the FBI’s IC3 and contact local law enforcement. The FBI’s guidance is to contact law enforcement as soon as you can.

A calm note to keep you grounded

Attackers want speed. You want control.

Fast containment + evidence + reporting is what reduces the odds of repeat harassment and re-victimization.

Free number scan to see what info about you is exposed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
View all
Privacy Tips
September 1, 2026

Are You Really Vetting Your Match for Online Dating Safety?

Privacy Tips
August 30, 2026

Is Your Account Hygiene Putting You at Risk on Dating Apps?

Privacy Tips
August 28, 2026

Could You Spot Romance Scams Before They Ask for Money?