FRAUD CHECK — Squire It™
sharelivefraud.com/squire-it
LIVE FRAUD ALERT
LIVEFRAUD Check #2
FBI WARNS

A federal advisory describes sexual exploitation actors breaking into personal and social media accounts to steal explicit images and videos, then posting or selling that content — plus the victim's identifying details — on criminal marketplaces and forums.

MODERATE CONFIDENCEPublished 2026-08-15
S
Q
U
I
R
E
D
E
S
K
·
C
H
E
C
K
E
D
·
B
A
T
T
L
E
D
·
R
E
C
E
I
P
T
E
D
·
S

What we found

An FBI public service announcement published 2026-08-10 warns that sexual exploitation actors are illegally accessing victims' social media and personal accounts to steal explicit content, also referred to as non-consensual intimate images, and post or sell it on criminal marketplaces. The advisory describes three access tactics the FBI says it has observed: high-volume password and PIN guessing using curated lists built from data leak sites, social media and open sources; impersonation of social media customer service by text message, telling the target their account will be disabled unless they reply with a code that the actor has actually triggered through a password reset; and phishing from look-alike domains and email accounts that mimic platform support and warn of a "new login" to lure a click on a password-change link. According to the advisory, the theft typically happens without the victim's knowledge, and personal details such as name, date of birth, email, phone number and social media username are often posted alongside the stolen content. The FBI states victims then frequently face re-victimization through harassment, sextortion, stalking or other targeted attacks, including having the stolen content advertised on the victim's own social media page. The single strongest defensive cue in the advisory is the unrequested code: a temporary password, PIN reset or access code you did not ask for is treated as a warning sign, and the advisory says not to share login information with anyone, even someone claiming to represent a platform you use. If you get a message like this, do not reply with the code and do not use links in the message — open the service's official app or type the site address yourself to check your account. The advisory also recommends unique, complex passphrases and PINs that are not tied to your identity or a relative's name or birthday, multi-factor authentication, caution with embedded links, and avoiding storage of sensitive images on social platforms or internet-accessible sites. The advisory points victims to a dedicated FBI reporting intake for this activity and lists the specific details investigators want, including when the content was taken, whether the person was under 18 in the material, how it was obtained, and where it was found. We have not independently observed these campaigns and cannot judge how widespread they currently are.
THE RULE
Treat any unrequested account code or reset notice as a takeover attempt in progress; sharing that code can hand over an account containing private images.

What we don’t know

The bench — who voted

2 INDEPENDENT AI MODELS REVIEWED THIS. ALL 2: HIGH RISK.

The card names a count. Here are the seats behind it, with what each one said.

ANTHROPICclaude-opus-5 · HIGH
The single evidence row covers only the three intrusion tactics and the sale/posting of stolen content with identifying details. Roughly half the finding rests on nothing in the harvest: the re-victimization consequences (harassment, sextortion, stalking, content advertised on the victim's own page), the assertion that theft 'typically happens without the victim's knowledge', the full mitigation list (passphrases, MFA, avoid storing images online), the 'unrequested code' framing as the strongest defensive cue, the dedicated FBI reporting intake, and the enumerated intake fields (when taken, whether the subject was under 18, how obtained, where found). These may all be in the advisory, but the reviewer has been given no row that says so.
DISSENT, PRESERVEDOn danger I would not soften: account-takeover leading to non-consensual intimate image distribution and follow-on sextortion carries severe, often irreversible personal harm, and the code-harvesting vector defeats SMS-based MFA for ordinary users. Even with prevalence unknown, the per-encounter harm justifies a high grade.
DISSENT, PRESERVEDThe operational advice in the finding (never relay a code you did not request, do not click links in such messages, open the official app or type the address yourself) is standard, low-risk guidance that would not mislead a reader even if it were unattributed. My objection is to its sourcing, not its substance, and I would not want it stripped from a published alert on procedural grounds — I would want it cited to a specific advisory passage.
DISSENT, PRESERVEDIf the harvest genuinely contains only one row, the honest fix is to shrink the finding to what that row says and label the remainder as unverified paraphrase, rather than to raise stated confidence.
GROQopenai/gpt-oss-120b · HIGH
Finding adds details (re‑victimization, defensive cue of unrequested code, specific security recommendations, dedicated FBI intake) not present in the sole evidence row.

Reviewed by 2 independent models; all judged the finding to go beyond the evidence.

▼ Protocol & challenge record
Objection (high): Material omission of scope: the PSA's first sentence says SE actors target "adult and underage victims," and the intake asks whether the victim "was under the age of 18 in the images and/or videos." The finding buries minors only inside the reporting-intake sentence, and the claim says nothing about them at all. Underage victimization changes the legal character of the activity (CSAM, mandatory NCMEC referral — note the PSA links NCMEC and NetSmartz) and the urgency of the advice. A reader of claim+finding would reasonably conclude this is an adults-only NCII problem. Fix required in the claim line, not just the body.
Not resolved — preserved on the record.
Objection (medium): Editorial ranking presented as advisory content: "The single strongest defensive cue in the advisory is the unrequested code" attributes a priority judgment to the FBI that the FBI does not make. The PSA presents an unordered bulleted tips list with no weighting. This is the analyst's call and must be labeled as such ("the most operationally distinctive cue, in our reading") or dropped. As written it is source-to-claim stretch on the one sentence readers are most likely to act on.
Resolved: Reframe as desk judgment, e.g. "In our reading, the most operationally distinctive cue in the PSA's unordered tips list is the unrequested code," or delete the ranking and simply report the tip as one of several.
Objection (medium): Confidence framing is internally confused. The claim as worded is purely descriptive of a document ("A federal advisory describes..."). That claim is fully established by the primary source at high confidence; nothing about it depends on corroboration, victim counts, or geography. The confidence_reasons instead grade the truth of the underlying real-world phenomenon. Either raise confidence to high for the document-description claim, or rewrite the claim to assert the phenomenon ("actors are compromising accounts to steal and sell NCII") — in which case "moderate" on a single uncorroborated source is defensible. Right now the label and the claim do not match, and readers cannot tell which uncertainty is being reported.
Not resolved — preserved on the record.
Objection (medium): Closed-list implication. The PSA says "various tactics for illegal access ... including:" — an explicitly non-exhaustive list. The finding says "The advisory describes three access tactics the FBI says it has observed," and the evidence row's claim_sentence enumerates the same three, which invites the inference that these are the observed tactics. It should read "three tactics among others" / "including". Defenders will over-narrow if they read this as the full tactic set.
Resolved: Change to "three of the tactics the FBI says it has observed (the PSA's list is explicitly non-exhaustive)" and mirror that hedge in the evidence row's claim_sentence.
Objection (medium): Omitted victim-remediation resources that are the most actionable content in the source for the affected population: the FTC "Take It Down" portal, NCVIC, NCMEC/NetSmartz. The finding routes victims only to ncii.ic3.gov (report to law enforcement) and says nothing about the takedown pathway. For an NCII item, omitting the takedown route while including the reporting route is a real harm-relevant gap, not a stylistic one.
Not resolved — preserved on the record.
Objection (low): Unsourced guidance sentence: "If you get a message like this, do not reply with the code and do not use links in the message — open the service's official app or type the site address yourself" carries row_ids: []. It is largely derivable from the PSA ("Do not share login information with anyone"; "Go directly to the service's website or official app"), so the empty row_ids appears to be an attribution error rather than genuinely independent advice. Either cite the row or state plainly that this is the desk's restatement. Leaving it uncited in an otherwise single-source item reads as if there is a second basis.
Resolved: Attach row_id 64c88a8f-c171-4035-8727-5cfc57bfc950 to the guidance sentence (it paraphrases the PSA's "do not share login information" and "go directly to the service's website or official app") or mark it explicitly as desk restatement.
Objection (low): Dropped concrete detection tip: the PSA's advice to view suspect emails on a computer to hover over links and inspect for formatting inconsistencies in the sender address/URL — explicitly because "viewing from a mobile device could cause emails to appear legitimate at first glance" — is compressed into "caution with embedded links." That mobile-vs-desktop point is the most specific inspection instruction in the source and it is the one lost.
Not resolved — preserved on the record.
Objection (low): Omitted targeting model. The PSA states actors target "specific individuals of interest — who may or may not be known to the actor — or general targets of opportunity," and that credential lists include victim-specific data (DOB, name variations) "when the victims are known to them." The finding drops the known-acquaintance vector entirely, which matters because it implies a non-random threat model (ex-partners, acquaintances) and partially answers one of the listed unknowns.
Not resolved — preserved on the record.
Objection (low): Date currency and provenance hygiene not stated. The item is dated 2026-08-10 and the finding gives no as-of date for the check, so a reader cannot tell whether this is days or many months old — relevant given the finding's own caveat that it cannot judge current activity level. Separately, the harvested text contains an unresolved footnote marker ("underage victims 1") whose content was not captured; the harvest is incomplete on exactly the minors point raised in OBJ-1. Also note the URL is bare ic3.gov/PSA/2026/PSA260810 — worth confirming against the canonical www.ic3.gov PSA listing before publication.
Not resolved — preserved on the record.
Objection (low): Entity/document-type wording: the claim calls this a "federal advisory" and the finding says "advisory" nine times. It is an IC3/FBI Public Service Announcement — a public-awareness notice, not a technical advisory of the CISA/joint-advisory kind. Consistent use of "advisory" mildly inflates the document's evidentiary weight; the PSA carries no IOCs, no TLP, no attribution methodology. Use "public service announcement" or "PSA" after first mention.
Resolved: First mention as "an FBI/IC3 public service announcement," thereafter "the PSA"; drop "advisory" as the default noun.
Objection (low): "criminal marketplaces and forums" in the claim vs the source's split between "sharing or posting the content within community forums" and "selling them to illicit marketplaces." The claim's compound "posting or selling ... on criminal marketplaces and forums" blurs which venue does which. Minor, but the free-sharing-in-forums vs paid-sale-in-marketplaces distinction is the one detail the source is careful about.
Resolved: Split the venues in the claim: "...then sharing it in community forums or selling it on illicit marketplaces, together with the victim's identifying details."
Preserved dissent
ON THE RECORDI do not agree that this item is ready as drafted. The PSA's own opening sentence covers "adult and underage victims," and the intake form asks whether the victim was under 18 in the material. The claim line omits minors entirely and the finding mentions them only as a reporting field. That is the single most consequential fact in the source and it has been flattened out of the headline claim. I would not publish without fixing the claim line itself.
ON THE RECORD"The single strongest defensive cue in the advisory is the unrequested code" is not in the source and is not attributable to the FBI. The PSA gives an unordered tips list. Ranking may be good analysis, but presenting the desk's ranking as the advisory's is exactly the kind of source-to-claim stretch this review exists to catch.
ON THE RECORDGrading a document-description claim at "moderate" because there is no second source is a category error. Nothing in "a federal advisory describes X" needs corroboration beyond the advisory. The moderate label communicates doubt about the wrong thing and will train readers to discount official primary sources they can read for themselves. Either assert the phenomenon and hedge it, or describe the document and stop hedging.
ON THE RECORDFor an NCII item, routing victims to the reporting intake while omitting the FTC Take It Down portal that the source itself links is a defensible editorial choice only if stated. I think it is the wrong choice.

The sources

Official sourceSexual Exploitation Actors Stealing and Leaking Explicit Content2026-08-10
The FBI warns that actors are compromising social media and personal accounts via password and PIN guessing, customer-service impersonation texts that harvest reset codes, and look-alike phishing domains, in order to steal explicit content and sell or post it with the victim's identifying details.
Authority: official. Retrieved 2026-08-15.
Limitation: Official advisory text only; it does not name affected platforms, quantify victims or incidents, specify regions, or state how the FBI attributes or dates the observed tactics, and this harvest contains no second source.
Open the original source →

Other checks

Every check we have published →

Share this receipt
sharelivefraud.com/check/9YRohUU

Approved by ihubglobalhq on 2026-08-17, after review of the alert and its sources.

Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.

Phishy? Send it → sharelivefraud.com/squire-it

Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.

Naming a source is not an endorsement, and being named here is not an accusation against any company.

Powered by SquireIt™

Verify this receipt at squireit.com

Join Squire’s First Watch

Alerts before the feed. Credit when your summons becomes a receipt. A vote on what we check next. Founding names are permanent.

Get the next one

We publish a receipt for every alert, including the ones we decide not to run.

We will ask you to confirm before anything is sent. Your address is used for this and nothing else, and is never shared.