# The FBI's Sextortion Warning Buries the Worst Part
Five years ago, the FBI put out an alert about sextortion. Last week, they put out another one. The threat didn't shrink. It metastasized.
The bureau's latest public service announcement warns that criminals are actively breaking into adults' and children's social media and online accounts to steal sexually explicit images and videos — then using that content as leverage. What the coverage is largely skimming past is the re-victimization engine underneath: once an image is stolen, it enters a criminal marketplace that treats victims like inventory.
---
## Not a Shakedown. A Supply Chain.
Most people picture sextortion as a single bad actor demanding money not to send photos to a victim's family. That's the retail version. The industrial version is what the FBI is describing here, and it's considerably worse.
When hackers compromise an account and find explicit content, they don't just extort. They sell — packaging the images alongside the victim's name, email, phone number, date of birth, and social media handles. Other criminals then buy that bundle and apply pressure from a new angle, demanding more explicit material, not money. The victim, who thought the threat was over, discovers they're in a loop with no obvious exit.
"Victims often face re-victimization through harassment, sextortion, stalking or other targeted attacks, such as advertising stolen content on a victim's own social media page," the FBI wrote. Read that last clause again: criminals advertising the stolen content back on the victim's own profile. That is calculated cruelty designed to maximize shame and isolate the target from their own support network.
---
## Student-Athletes Got Called Out for a Reason
The same week as the general warning, the FBI partnered with the NCAA to issue a joint advisory specifically about student-athletes. That specificity is meaningful.
Student-athletes occupy a peculiar threat surface. They have public-facing social media presence by institutional design — programs push athletes to build followings. They're recognizable within their campus communities and often beyond. They have reputations built around physical image. And they have coaches, compliance offices, and sponsorship considerations that make the threat of exposure feel existentially dangerous.
Criminals aren't picking student-athletes randomly. They're picking a population where shame is a force multiplier, where the victim has specific people they desperately don't want to see the content, and where the social stakes make compliance feel more likely. It's targeting by psychology as much as by access.
The FBI asked coaches, compliance staff, and athletic department leadership to raise awareness. That's the right call. Institutional framing matters — a coach telling their team "here's what this looks like and here's what to do" lands differently than a poster in a gym.
---
## How They're Getting In
The technical vector here isn't sophisticated. The FBI flagged two specific lures: unsolicited texts claiming an account will be disabled unless the recipient hands over a verification code, and unsolicited emails about a new login containing a password reset link.
These are phishing and smishing — nothing new, nothing cutting-edge. What makes them effective isn't technical novelty; it's that the pressure tactics exploit exactly the kind of anxiety that makes people act before thinking. An account getting disabled is urgent. The window is closing. Type the code now.
The FBI's guidance is correct but familiar: don't provide verification codes to unsolicited messages, use passwords that don't include personal information, enable multi-factor authentication. What they're not saying — and what's worth sitting with — is that even good hygiene isn't a guarantee. Once an attacker has valid credentials through a phishing attack or a credential dump from an earlier breach, they're often working inside defenses that weren't designed to distinguish them from the legitimate account holder.
---
## When "Prevention" Scores Mislead
There's a number buried at the bottom of the FBI's coverage context that deserves more attention: once attackers are operating with valid credentials, only 37% of their subsequent actions are blocked by enterprise defenses. That figure comes from simulated attack data across production environments — real organizations, real controls, real gaps.
The implication for individual users is sobering. Most consumer-grade security is designed to stop unauthorized login. Once the credentials are valid — because someone clicked a link and typed their password into a convincing fake page — the account is open, and the protections that matter to you, the actual owner, mostly evaporate.
Multi-factor authentication meaningfully changes this calculus, which is why both the FBI and security practitioners keep hammering on it. An MFA prompt that the legitimate user didn't initiate is a signal worth acting on. If you get a code you didn't ask for, someone is trying to log in as you.
---
## HackWire Analysis
The FBI doesn't issue public service announcements into a vacuum. They publish them when case volume is climbing and the field offices are seeing enough incidents to warrant pushing prevention messaging to the public. The 2021 sextortion warning came after a "massive increase" in complaints. This one didn't come with volume statistics, but the timing and the NCAA partnership suggest the bureau is watching a meaningful uptick — one that's hitting specific, identifiable communities hard enough to warrant targeted outreach.
What concerns me about the coverage cycle around these warnings is that sextortion tends to get treated as a personal safety story rather than a criminal infrastructure story. The infrastructure is the point. The marketplaces where victim data gets packaged and sold are the engine that turns a single compromise into months or years of re-victimization. Shutting down a single extortionist doesn't touch that layer. The Canadian man sentenced in May to 33 years — targeting over 145 children across eight years — operated alone. The marketplace-driven model distributes that risk across many actors, making it harder to prosecute and harder to stop.
Defenders — whether that's campus security teams, parents, or individuals — should understand that the immediate extortionist may not be the only threat actor with their information. If explicit content was stolen and the victim faced initial extortion, there's a reasonable chance the underlying data has been sold. Monitoring for stalking behaviors, unusual contact from strangers, or content appearing in unexpected places is part of the longer-tail response that most guidance doesn't discuss.
The practical next step for institutions with identified vulnerable populations — schools, athletic programs, employers with high-profile staff — is to build explicit social engineering training that covers this specific playbook: the fake verification code, the fake password reset, the account-disabled pressure tactic. Once people recognize the template, they stop complying.
— HackWire Editorial
---
## Related Coverage