Cybersecurity Girl Weekly Drop
Cyber news, tools & one smart career path.
5 min read

Quick Reality Check
The FBI is warning that sexual predators are breaking into social media and personal accounts to steal intimate images and videos, then posting or selling them alongside victims’ personal information.
What happened:
According to the FBI, criminals use a mix of account-takeover and social-engineering tactics to get inside victims’ accounts. Once inside, they steal sensitive content to post or sell on criminal marketplaces alongside victims' real names, phone numbers, email addresses, and social media handles
In many cases, they are using information already floating around from past breaches, public social-media profiles, leak sites, and other public sources to guess passwords or PINs. Names, birthdays, and predictable password variations make the job easier.
Another tactic is fake customer-service messages. A victim gets a text claiming their social-media account is about to be locked or disabled. The criminal triggers a legitimate password-reset request, then convinces the victim to hand over the verification code. At that point, the attacker does not need to break in. The victim just gave them the key.
Why it matters:
This goes far beyond a standard account compromise. When criminals gain access to private libraries of intimate images, they weaponize them for harassment, stalking, and sextortion.
The part that makes these attacks especially effective is that they often look legitimate. They're using your leaked data to make phishing attempts feel personal, they're weaponizing authentication codes you think are safe, and they're targeting your most intimate moments to extort you. The goal is total compromise: financial theft, identity theft, and psychological harm all at once.
Read more here
60-Second Protection Fix
Here is what you can do to protect yourself:
-
Avoid storing intimate or sensitive images on cloud services when possible. If you must keep them on your phone, use your device's built-in "hidden" or locked folder.
-
"Disappearing" messages don't actually disappear. When you send a photo on Snapchat, Instagram, or any platform with "disappearing messages," the platform stores it on their servers. Someone on the receiving end can take a screenshot of it before it disappears. The image then exists on their device, in their cloud backup, their computer, wherever they save it. Once that happens, it's completely out of your control.
So before taking or sending any picture, ask yourself: Would I be ok if this were seen publicly? -
Enable multi-factor authentication (MFA) EVERYWHERE.
-
Never share authentication codes, even if the caller claims to be your bank. Legitimate companies won't ask for these codes. If you get a call or text requesting one, hang up and call the official number yourself. Scammers spoof phone numbers to look real.
-
Delete inactive accounts and remove your data from people-search sites. The less personal information floating around in databases and data brokers, the harder it is for criminals to build a convincing phishing attack or guess your security answers.
-
Think before you click or respond to unsolicited messages. If you didn't expect it, don't click, don't respond, and report it immediately.
What You Missed This Week
Playing Cyber Myth or Fact with the OG MythBuster herself
Did you know these Cyber Myths or Facts? 👀
Would YOU let an AI agent into your personal email?
I played “This or That” with the CEO of a company that secures 20% of the Fortune 100, and I had him answer some controversial questions…
Reasons to follow or unfollow me …
Here are a few reasons!
Quick giveaway update: Due to a busy couple of weeks, including a conference and illness, the winner announcement has been pushed back. The winner will be announced on August 19th. Thank you so much for your patience and understanding!
Let’s keep building together!
Stay protected,
Cybersecurity Girl
Know someone who’d enjoy this? Pass it along and have them sign-up here! And if you have thoughts or feedback, just hit reply, I’d love to hear from you.



Responses