AI News HubLIVE
サイト内リライト2 分で読了

翻訳待ち:Hackers are hunting for your private photos, FBI warns: 6 ways to avoid a sextortion nightmare

AI サービスが一時的に利用できないため、復旧後に翻訳を補完します。ソース概要:Hackers who steal compromising images of you from social media and personal accounts are selling them on the dark web. Here's how to protect yourself.

ソースZDNet AI

AI サービスが一時的に利用できないため、復旧後に翻訳を補完します。

Follow ZDNET: Add us as a preferred source on Google.ZDNET's key takeawaysHackers are stealing and selling explicit photos from social media accounts.The hackers use social engineering and other tactics to gain access.Avoid posting any such images and watch out for potential hacking attempts.Storing sexually explicit photos of yourself on social media or personal accounts is never a great idea. That's especially true now as the FBI is warning about hackers stealing and selling such images.In an advisory published on Monday, the FBI said that sexual exploitation hackers are targeting both adults and minors by illegally hacking into their social media and personal accounts to grab explicit images. From there, the attackers sell the images on the dark web, often accompanied by personal details such as the victim's name, date of birth, email address, and phone number.Also: Why managers are ransomware's top targets now - and 6 ways to stay safeOnce the personal images and details are up for grabs on the dark web, a criminal can exploit them to run sexual extortion (aka, sextortion) schemes in which they blackmail the targeted person. That re-victimizes the victim, causing them further pain and grief.Hackers typically use various social engineering and cyber intrusion methods to gain access to the social media and personal accounts of their targets. In its advisory, the FBI highlighted three different tactics.Targeting passwords and PINs. Here, the hackers start with curated lists of websites that have suffered data leaks. Those lists typically include the names, birthdates, and other personal details of users. The hackers then turn to password-cracking software and other brute-force tools to try to obtain passwords and PINs associated with the leaked accounts.Impersonating customer service. With this tactic, a hacker sends text messages to social media users, posing as the company's customer service rep and claiming that the user's account is being disabled or locked. From there, the hacker requests a password reset from the actual company. After the user shares that code with the hacker, the victim's password is reset, allowing the hacker to access their account.Phishing attempts. Often, hackers will create domains and email accounts that impersonate customer service support from a social media company. The hackers then send emails to targeted users, warning them of new logins to their accounts. Those emails include a malicious link prompting the user to change their password, thus allowing the hackers to gain access to their account.Also: Your ChatGPT account just got more secure, but you have to opt in - here's howTo avoid becoming a victim of these schemes, the FBI offers the following tips:Here's the number one rule. Don't store sensitive images or videos on social media platforms or public internet sites.Use unique and complex passwords, passphrases, and PINs for your social media sites and personal accounts. When creating passwords and passphrases, don't include any personal information, such as your date of birth or your spouse's name.When available, sign up for multi-factor authentication to verify any login attempts.Avoid clicking on embedded links in emails and text messages. Instead, go directly to the website in question to sign in to your account.Use a computer instead of your mobile device to view an unexpected or suspicious email. Here, you can hover over any embedded links to look for atypical URLs or formatting irregularities.Be careful if you receive a temporary password, PIN reset, or access code that you didn't request. Never share login credentials with anyone, even if the sender claims to be from a social media site or other company where you have an account. Use the company's website or app if you need to change your password or PIN.