Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • US Offers $10M for IRGC Cyber Leader Do Son
    The US offers a $10 million reward for Amir Yaryab, an IRGC cyber commander linked to CyberAv3ngers attacks on critical water infrastructure. Related Posts: Mirage Kitten Malware Targets Aviation and Fintech Sectors Coder Registry Attack: Hijacked Cloudflare Pool Served Malicious Terraform Modules Toy Ghouls Backdoor Uses HiveMQ and Element for C2 The post US Offers $10M for IRGC Cyber Leader appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • The Gentlemen Ransomware Deploys in Under 24 Hours Do Son
    The Gentlemen ransomware, run by GOLD SHERWOOD, encrypts networks in under 24 hours. See the affiliate playbook and how to defend against it. Related Posts: PHP Web Server Rootkit Targets F5 BIG-IP Devices StreamRat Banking Trojan Targets Spanish Android Users Silver Fox Fake Software Installers Disable Windows Defender The post The Gentlemen Ransomware Deploys in Under 24 Hours appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Cisco Secure Email S/MIME Flaws Publicly Disclosed Do Son
    A public announcement exists for the Cisco Secure Email vulnerability pair in S/MIME decryption, plus a Cisco phone SIP denial-of-service flaw. Related Posts: CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE Apache Allura Security Vulnerabilities Patched in v1.21.0 CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation The post Cisco Secure Email S/MIME Flaws Publicly Disclosed appeared first on Daily CyberSecurity.
     
  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: ExfilSquad Emerges BushidoToken
    What HappenedIn mid-2026, an emerging cybercriminal group known as ExfilSquad launched a high-profile extortion campaign targeting prominent UK organisations across the public sector, education, and law enforcement, as well as other firms worldwide.Unlike traditional ransomware groups, ExfilSquad does not deploy encryptors or destructive malware. Instead, they operate as a pure data extortion group, stealing data and threatening to publish it on their onion-based Data Leak Site (DLS) if a ransom
     

UK Cybercrime Journal: ExfilSquad Emerges

2 de Setembro de 2026, 06:00

What Happened

  • In mid-2026, an emerging cybercriminal group known as ExfilSquad launched a high-profile extortion campaign targeting prominent UK organisations across the public sector, education, and law enforcement, as well as other firms worldwide.
  • Unlike traditional ransomware groups, ExfilSquad does not deploy encryptors or destructive malware. Instead, they operate as a pure data extortion group, stealing data and threatening to publish it on their onion-based Data Leak Site (DLS) if a ransom is not paid.
  • Several prominent UK entities have confirmed breaches linked to the group:
    • UK Department for Education (DfE): Approximately 600,000 records stolen from its Help Portal containing parent and staff contact details (names, emails, phone numbers, job titles), plus around 7,000 records from the Turing Portal.
    • Police National Legal Database (PNLD): Stole 1.9 GB of data (around 135,000 records) containing contact information for over 100,000 serving police officers, staff, and criminal justice professionals, alongside around 21,000 "Ask the Police" public inquiry records.
    • Newcastle University: Approximately 440,000 records compromised containing applicant and student contact information, personally identifiable information (PII), and admissions database records caused by a technical configuration flaw connecting to an admissions system.
  • Analysis of the details left on the data leak site revealed that ExfilSquad's primary attack vector involves exploiting misconfigurations in cloud portals, customer relationship management (CRM) platforms, internal case management systems, as well as Microsoft Power Pages data tables left publicly accessible without proper authentication.
  • To force compliance and prove their claims are real, ExfilSquad uploaded multi-gigabyte torrent files for each victim to their TOR leak site. Resecurity noted that ExfilSquad assigns a distinct Torrent Tracker and initial Web Seed per victim.

Analyst Comment

While ExfilSquad is a new group, they appear to be already experienced at running these types of attacks, suggesting they have a history of cybercrime. Plus, ExfilSquad’s recent campaign highlights the growing trend of transitioning from file-encrypting ransomware to extortion driven entirely by cloud and SaaS misconfigurations. Organisations that have invested in defending against endpoint-based threats are often leaving critical business application interfaces exposed.

SaaS platforms continue to be primary targets of English-speaking cybercrime communities. In recent years,  customers of major SaaS providers, such as Salesloft, Salesforce, and Snowflake have all been extorted. Microsoft Power Pages portals, CRM databases, and customer support helpdesks frequently hold vast repositories of sensitive contact data and interaction histories. When internet-facing API endpoints or data table permissions are left unauthenticated or unpatched, cybercriminals can systematically scrape massive volumes of data without ever needing to drop a payload or escalate privileges internally.

ExfilSquad’s reliance on torrent distribution further amplifies reputational and operational damage. While gangs like LockBit, Clop, and Akira have previously utilised torrents, ExfilSquad’s operational twist of assigning unique Torrent Trackers and dedicated Web Seeds to individual victims ensures that leaked files distribute rapidly across P2P networks, making it extremely difficult to perform a takedown.

While ExfilSquad’s breaches have largely compromised contact directories and administrative support records, the real-world risks remain significant. Exposing work emails, names, and organisational structures for over 100,000 police officers and civil servants poses distinct social engineering, spear-phishing, and physical security concerns that impacted institutions will have to manage long after the breach occurs.

Defensive Takeaways

  • Audit Microsoft Power Pages and Public SaaS Tables: Regularly review public data table permissions, web API settings, and unauthenticated browser views across Microsoft Power Pages, CRMs, and customer support portals to ensure backend data tables are not exposed to the public internet.
  • Harden CRM and Case Management Integrations: Treat external-facing admissions portals, helpdesks, and case management systems as high-risk platforms. Implement strict access controls, conduct routine configuration audits, and enforce proper API token security.
  • Deploy External Attack Surface Management (EASM): Utilise continuous external attack surface scanning to detect newly exposed web endpoints, misconfigured database connectors, and publicly exposed storage buckets before malicious actors locate them.
  • Incorporate Pure Extortion into Incident Response Plans: Security teams must adapt incident response playbooks for data-theft-only scenarios. Organisations may seek to establish protocols for monitoring peer-to-peer (P2P) networks and managing public disclosures when stolen data is distributed via torrents.

Relevant Sources

  1. https://www.computing.co.uk/news/2026/security/newcastle-university-data-breach-exfilsquad
  2. https://www.thetimes.com/uk/crime/article/who-are-exfilsquad-hackers-cyberattacks-dtzhvvzgj
  3. https://www.ncl.ac.uk/press/articles/latest/2026/07/statementonpotentialunauthoriseddataaccess/
  4. https://www.bbc.co.uk/news/articles/cq6dmgrp21po
  5. https://www.pnld.co.uk/article/?id=7ebf3c0e-598e-f111-8077-7ced8d3aa78f

Relevant CTI Sources

  1. https://www.ransomware.live/group/ExfilSquad
  2. https://www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents
  3. https://socradar.io/blog/dark-web-profile-exfilsquad/
  4. https://www.sans.org/blog/hunting-saas-threats-insights-for589-course-cybercriminal-campaigns

  • ✇Cybersecurity News
  • AnonyMousKIT Uses AI Voice Calls to Unlock Stolen iPhones Do Son
    AnonyMousKIT is an AI-powered PhaaS platform that phones iPhone theft victims as fake Apple Support to steal passcodes and beat Activation Lock. Related Posts: Dark Caracal Deploys New GoCaracal Malware Framework Cambodia Malware Campaign Uses PNG Files to Deliver SparkRAT BREEZE COMET Threat Actor Attacks Brazilian Banks The post AnonyMousKIT Uses AI Voice Calls to Unlock Stolen iPhones appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • WeedHack Malware Still Hits Minecraft Gamers via Fake Sites Do Son
    WeedHack malware still targets Minecraft gamers through fake client sites and Minecraft SEO poisoning, McAfee Labs warns. Related Posts: SynkLoader Malware Deploys Multi-Language Attack Tools macOS ClickFix Malware Exploits Polygon C2 Cruciferra Malware Loader Uses ClickFix Lures to Kill EDR The post WeedHack Malware Still Hits Minecraft Gamers via Fake Sites appeared first on Daily CyberSecurity.
     

TikTok Agrees to $400M Settlement Over Children’s Privacy

25 de Agosto de 2026, 14:41

TikTok and ByteDance agree to pay up to $400 million to settle US allegations involving children’s data, parental consent and account deletion.

The post TikTok Agrees to $400M Settlement Over Children’s Privacy appeared first on TechRepublic.

  • ✇@BushidoToken Threat Intel
  • UK Cybercrime Journal: ACRO Breach Report BushidoToken
    What HappenedOn 7 August 2026, the UK Information Commissioner's Office (ICO) disclosed that between July 2021 and June 2023, the ACRO Criminal Records Office suffered three separate compromises involving its customer portal website (acro.police.uk).ACRO is a national police unit providing public services such as issuing Police Certificates, International Child Protection Certificates, and processing Subject Access Requests.In March 2023, ACRO was notified about an SQL injection attack that repo
     

UK Cybercrime Journal: ACRO Breach Report

26 de Agosto de 2026, 06:00


What Happened

  • On 7 August 2026, the UK Information Commissioner's Office (ICO) disclosed that between July 2021 and June 2023, the ACRO Criminal Records Office suffered three separate compromises involving its customer portal website (acro.police.uk).
  • ACRO is a national police unit providing public services such as issuing Police Certificates, International Child Protection Certificates, and processing Subject Access Requests.
  • In March 2023, ACRO was notified about an SQL injection attack that reportedly exposed 15 sets of credentials, the majority of which belonged to its employees.
  • A subsequent forensic investigation uncovered long-term threat actor activity within the website's environment, spanning from 9 July 2021 to 22 June 2023.
  • The website was built on the Kentico CMS and was running version 12.0.0 between September 2019 and March 2023. This version had multiple known vulnerabilities at the time of the incident, but suffered from ambiguity around who was accountable for patching led to missed hotfixes and updates.
  • Between 15 and 16 February 2023, an unknown threat actor staged personal data for exfiltration, which included Police Certificate Applications, Subject Access Request (SAR) forms, and International Child Protection Certificate forms.
  • Due to insufficient log retention, ACRO could not definitively determine if the data was successfully exfiltrated. A maximum of 10,920 data subjects had their data staged, but ACRO ultimately notified 84,048 data subjects on a precautionary basis in April 2023.
  • Notably, on 23 February 2023, the ICO learned that ACRO's Trend Micro antivirus software detected and quarantined four attempts to install the well-known credential harvesting tool Mimikatz. However, because ACRO operated without a documented patching policy and lacked a structured process for analyzing security alerts, these warnings were never reviewed or acted upon.

Analyst Comment

The Information Commissioner's Office (ICO) reprimand against the ACRO underscores the persistent issue within many organisations of a breakdown in basic IT governance and accountability. The fact that a threat actor was able to operate within the environment for nearly two years highlights systemic failures in both vulnerability management and security monitoring. Running an outdated content management system with known vulnerabilities for several years is a critical oversight. The ambiguity surrounding patching responsibilities created a dangerous blind spot that adversaries successfully exploited. 

Further, the failure to act on critical security alerts is also a classic breakdown in the incident response chain. While the deployed Trend Micro antivirus successfully detected and quarantined a known threat, the alerts were ultimately ignored. Security tools are only as effective as the teams monitoring and responding to them. Without a structured review process, even the most sophisticated detection capabilities fall flat.

It is important to note, however, that while private sector organisations will receive a hefty fine for data protection offences, public sector organisations like ACRO receive a public reprimand from the ICO rather than receive a fine that confiscates public funds.

At the time of writing, the data has not yet appeared on any cybercrime forums or underground chat channels. The use of an open source tool like Mimikatz combined with SQL injection attacks indicates a likely opportunistic adversary rather than a stealthy cyber-espionage operation. However, both cybercriminal and nation state groups are known for opportunistic attacks. Current attribution for who or what was responsible this breach remains uncertain from an open source intelligence (OSINT) perspective.

On a positive note, the ICO highlighted that ACRO’s network segmentation effectively prevented the threat actor from pivoting from the compromised web environment into core policing systems. This containment significantly reduced the scale of harm and demonstrates the immense value of architectural defense-in-depth strategies. Following the breach, ACRO has migrated its portal to the Salesforce Experience Cloud for automated patching and hotfixes and implemented a Security Information and Event Management (SIEM) system to improve visibility.

Defensive Takeaways
  • Establish Clear Accountability for Patching: Organisations must have a documented patching policy with clearly defined ownership, especially for public-facing web applications and Content Management Systems (CMS). Ambiguity in IT governance directly leads to unpatched vulnerabilities which then get exploited.
  • Implement Structured Alert Monitoring: Deploying antivirus or Endpoint Detection and Response (EDR) solutions alone is insufficient if alerts are not actively monitored and investigated. It is recommended to establish either structured internal processes or an outsourced 24/7 Managed Detection and Response (MDR) or SOC service to review and respond to critical security alerts promptly.
  • Maintain Robust Network Segmentation: Ensure that public-facing web infrastructure is strictly segmented from internal corporate networks and core operational systems. As demonstrated in this incident, strict segmentation is a crucial control for stopping an attacker's lateral movement.
  • Ensure Adequate Log Retention: Insufficient logging severely hinders incident response and forensic investigations. Implement comprehensive logging policies and utilise a SIEM to aggregate logs, ensuring they are retained long enough to accurately determine the scope of data exfiltration during a compromise.

  • ✇Cybersecurity News
  • Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update Do Son
    Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update appeared first on Daily CyberSecurity.
     
  • ✇Firewall Daily – The Cyber Express
  • Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data Samiksha Jain
    The UK Ukraine AI partnership will give Britain access to Ukraine’s Avengers AI Labs, bringing together Ukrainian battlefield experience, operational data and engineering expertise with the UK’s AI ecosystem. The agreement, signed by President Volodymyr Zelenskyy and Prime Minister Andy Burnham in Ukraine, will focus initially on defence and national security. Under the partnership, British innovators and researchers will gain access to data and insights collected across the battlefield. The
     

Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data

26 de Agosto de 2026, 02:26

UK Ukraine AI partnership

The UK Ukraine AI partnership will give Britain access to Ukraine’s Avengers AI Labs, bringing together Ukrainian battlefield experience, operational data and engineering expertise with the UK’s AI ecosystem. The agreement, signed by President Volodymyr Zelenskyy and Prime Minister Andy Burnham in Ukraine, will focus initially on defence and national security. Under the partnership, British innovators and researchers will gain access to data and insights collected across the battlefield. The UK government described Avengers AI Labs as a “goldmine of battlefield data,” offering researchers access to real-world operational information used to train AI models.

How Avengers AI Labs Uses Battlefield Data

The data is collected through thousands of daylight cameras and infrared sensors deployed across the battlefield. The systems capture images and information involving tanks, artillery, air defence systems, infantry and aerial targets, including Shahed drones and reconnaissance UAVs. The data is used to train AI models to recognize and classify battlefield objects. Ukraine’s Defense Ministry has previously said that systems trained using the Avengers Labs platform analyze more than 100,000 drone video feeds each month and help identify about 70% of enemy targets in real time. The UK’s access to the platform is intended to allow British startups, researchers and engineers to work with operational insights and develop technologies based on real-world datasets. The partnership will initially bring together engineers, academics, businesses and military operational expertise from both countries to address national security challenges. The two countries will also explore additional platforms for future collaboration.

UK Ukraine AI Partnership Test New Defence Technology

Several pilot projects involving British startups have already been rolled out as part of the agreement. The companies named are Bristol-based Sintela, Oxford’s Mind Foundry and London’s Skyral. The first technology is due to be deployed at a UK defence site to help protect bases from protestors and hostile actors seeking intelligence. The project combines Ukrainian data with UK technology and turns buried fibre-optic cables into an AI-enabled sensor. The technology could also be used in other critical locations, including airports, prisons, railways and energy plants, according to the information released about the partnership. A second project will examine the development of next-generation low-power AI chips designed for future drones, robotics and autonomous systems. If successful, the technology could support machines designed to operate for longer, respond faster and function in environments where conventional systems face limitations.

AI Sovereignty and Defence Innovation

The agreement forms part of the UK and Ukraine’s 100 Year Partnership and expands cooperation between the two countries in AI and defence technology. The UK will provide access to its universities, researchers, technology companies and AI ecosystem, while Ukraine will provide access to operational experience and datasets generated during the war. Minister for AI Kanishka Narayan described the arrangement as AI sovereignty in practice, focused on developing national capabilities and turning frontline experience into technologies for military and critical infrastructure protection. The partnership also follows the UK government’s announcement that defence firm MBDA can release classified information on UK components for the long-range SCALP missile to establish local assembly lines in Ukraine. The broader agreement is intended to combine Ukrainian battlefield data with British scientific, engineering and technology expertise, with the initial focus remaining on defence, national security and the development of future defence technology.
  • ✇Cybersecurity News
  • Balonx Sistema: Mexican PhaaS Adds AI Vishing and RAT Do Son
    Group-IB exposed Balonx Sistema, a Mexican PhaaS platform bundling real-time phishing, an Android RAT, and AI-driven vishing against 20+ banks. Related Posts: Core Werewolf Deploys New CoreRAT Malware Against Russian Targets StopAndProtect Malware Turns Hacked WordPress Sites Into a Botnet Cisco Talos Exposes UAT-10147 Agentic AI Attacks The post Balonx Sistema: Mexican PhaaS Adds AI Vishing and RAT appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • TikTok Secures $400 Million Privacy Settlement Do Son
    TikTok and ByteDance finalize a massive $400 million settlement with the US Department of Justice, resolving severe violations of children's privacy laws. Related Posts: OneDrive Folder Exclusions Roll Out for Development Environments Claude Fable 5 Intelligence Drop Sparks Concerns OpenAI Advocates Stricter California AI Regulations The post TikTok Secures $400 Million Privacy Settlement appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Spring Data REST and Spring AI Vulnerabilities: Four High-Severity Flaws Patched Do Son
    Four Spring vulnerabilities hit Spring Data REST and Spring AI, including CVE-2026-47849, a privilege escalation flaw. Patch to the fixed versions now. Related Posts: EverShop CVE-2026-72843 Flaw Allows Unauthenticated Account Takeover CVE-2026-77806: SPIP Unauthenticated RCE Exploited in the Wild as Public Exploit Lands CVE-2026-75501: Public PoC for Calix Router Flaw That Bypasses NAT and Firewall Protections The post Spring Data REST and Spring AI Vulnerabilities: Four High-Severity Flaws
     
  • ✇Cybersecurity News
  • CVE-2026-47627: CVSS 9.8 Denial of Service Hits NVIDIA Triton Do Son
    NVIDIA Triton vulnerability CVE-2026-47627 scores CVSS 9.8. Learn how the denial of service flaw works and why you must update to 26.06 now. Related Posts: CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) The post CVE-2026-47627: CVSS 9.8 Denial of Service Hits NVIDIA Triton appeared first on Daily CyberSecurity.
     
  • ✇Schneier on Security
  • Police Are Hiding Their Use of Flock Surveillance Cameras Bruce Schneier
    A usage policy for Flock license plate reader cameras tells police not to talk about the cameras: When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain terms, to keep them a secret: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.”
     

Police Are Hiding Their Use of Flock Surveillance Cameras

20 de Agosto de 2026, 06:48

A usage policy for Flock license plate reader cameras tells police not to talk about the cameras:

When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain terms, to keep them a secret: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.”

This reminds me of IMSI-catchers (Stingray was the most popular) a couple of decades ago. Police would go to even more extremes to hide their usage.

  • ✇Cybersecurity News
  • CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1) Do Son
    CVE-2026-71290 (CVSS 9.1) is an Apache HttpClient TLS vulnerability that lets attackers intercept and modify traffic via MITM attacks. Update to 5.6.4. Related Posts: PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public The post CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic
     
  • ✇Cybersecurity News
  • CVE-2026-66804: PoC Exploit Gains SYSTEM via Cross Device Service Do Son
    A public PoC for CVE-2026-66804 escalates a standard Windows user to SYSTEM via the Cross Device Service. Details and exploit code are now disclosed. Related Posts: CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1) PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups The post CVE-2026-66804: PoC Exploit Gains SYSTEM via Cross Device Service appeared
     
  • ✇Cybersecurity News
  • Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs Do Son
    Apache Struts DoS flaws span CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635, plus two JSON plugin bugs. Upgrade to 7.3.0. Related Posts: CVE-2026-19188: Haiwell HMI Gateway Flaw Lets Attackers Execute Arbitrary OS Commands With Root Privileges (CVSS 10.0) Linux AF_PACKET Race (03390aa): PoC Exploit Enables Local Privilege Escalation Citrix NetScaler Pre-Auth RCE CVE-2026-8452 Gets Public Exploit Code The post Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs appeared fir
     
  • ✇Firewall Daily – The Cyber Express
  • Hackers Target Social Media Accounts to Steal Explicit Content, FBI Warns Samiksha Jain
    The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge. According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity
     

Hackers Target Social Media Accounts to Steal Explicit Content, FBI Warns

13 de Agosto de 2026, 03:10

sexual exploitation actors

The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge.

According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity. After gaining access to accounts, they steal explicit content and share it through community forums or illicit marketplaces.

The FBI said personally identifiable information, including a victim's name, date of birth, email address, phone number and social media username, is often posted alongside the stolen material. This can expose victims to continued harassment and re-victimization.

How Sexual Exploitation Actors Access Accounts

The FBI has identified several methods used by sexual exploitation actors to gain access to victims' accounts.

Password and PIN Targeting

In password/PIN targeting, actors use high-volume password and PIN attempts against social media and personal accounts. The information used in these attempts can come from data leak sites, social media and open-source information.

When victims are known to the actors, curated lists may include personal details such as names, date of birth or variations of those details.

Social Media Customer Service Impersonation

Another tactic involves social media customer service impersonation through text messages. Victims may receive messages claiming their account is being disabled or locked unless they provide a verification code.

The actor then requests a password reset, causing a code to be sent to the victim. If the victim shares the code, the actor can reset the password and access the account.

Phishing Emails

The FBI also warns about phishing campaigns using look-alike domains and email accounts designed to appear as social media customer support.

These messages may claim there has been a new login and contain an embedded link asking the victim to change their password. Clicking the malicious link can give the actor access to the account.

Stolen Content Can Lead to Further Attacks

Once explicit content is stolen, sexual exploitation actors may post or sell it while including personal information about the victim. The FBI said victims can subsequently face harassment, sextortion, stalking or other targeted attacks.

The actors may also advertise stolen content through a victim's own social media page, increasing the potential for further exposure.

FBI Shares Steps to Protect Accounts

The FBI advises people to avoid storing sensitive images or videos on social media platforms or other internet-accessible sites.

It recommends using unique, complex passphrases and PINs along with multi-factor authentication (MFA). Password information directly associated with a person's identity, including names or birthdays, should be avoided.

Users should also be cautious with links received through emails and text messages. The FBI recommends going directly to the relevant website to address account concerns and checking URLs before clicking.

Unrequested temporary passwords, PIN resets or access codes should also be treated with caution. The FBI advises users not to share login information, even when someone claims to represent a platform or service.

People who believe their explicit content was stolen or leaked can provide information through the FBI's NCII reporting site. The FBI also advises the public to continue reporting fraud, scams and cyber threats to the Internet Crime Complaint Center or a local FBI Field Office.
❌
❌