What we found
- The sole basis is a single official FBI public service announcement with a clear publication date and named reporting channel, which is a strong source type.
- No independent corroboration in this harvest — no press reporting, community reports or detector/lookup results were available to cross-check.
- The advisory describes tactics qualitatively but gives no figures on case volume, geography, targeted platforms or time window, so scale and current activity level cannot be assessed.
- Reviewed by 2 models, 1 from independent houses.
What we don’t know
- Which specific platforms or services are being impersonated or breached — the advisory refers only generically to social media customer support.
- How many victims, reports or marketplaces are involved, and over what time period the observed activity occurred.
- Whether the described tactics are the work of one coordinated group or many unrelated actors.
- Which countries or regions targets are located in.
- Whether any takedown, arrest or platform remediation action has followed.
- Whether current message wording or sender infrastructure has changed since publication.
The bench — who voted
2 INDEPENDENT AI MODELS REVIEWED THIS. ALL 2: HIGH RISK.
The card names a count. Here are the seats behind it, with what each one said.
DISSENT, PRESERVEDOn danger I would not soften: account-takeover leading to non-consensual intimate image distribution and follow-on sextortion carries severe, often irreversible personal harm, and the code-harvesting vector defeats SMS-based MFA for ordinary users. Even with prevalence unknown, the per-encounter harm justifies a high grade.
DISSENT, PRESERVEDThe operational advice in the finding (never relay a code you did not request, do not click links in such messages, open the official app or type the address yourself) is standard, low-risk guidance that would not mislead a reader even if it were unattributed. My objection is to its sourcing, not its substance, and I would not want it stripped from a published alert on procedural grounds — I would want it cited to a specific advisory passage.
DISSENT, PRESERVEDIf the harvest genuinely contains only one row, the honest fix is to shrink the finding to what that row says and label the remainder as unverified paraphrase, rather than to raise stated confidence.
Reviewed by 2 independent models; all judged the finding to go beyond the evidence.
▼ Protocol & challenge record
ON THE RECORDI do not agree that this item is ready as drafted. The PSA's own opening sentence covers "adult and underage victims," and the intake form asks whether the victim was under 18 in the material. The claim line omits minors entirely and the finding mentions them only as a reporting field. That is the single most consequential fact in the source and it has been flattened out of the headline claim. I would not publish without fixing the claim line itself.
ON THE RECORD"The single strongest defensive cue in the advisory is the unrequested code" is not in the source and is not attributable to the FBI. The PSA gives an unordered tips list. Ranking may be good analysis, but presenting the desk's ranking as the advisory's is exactly the kind of source-to-claim stretch this review exists to catch.
ON THE RECORDGrading a document-description claim at "moderate" because there is no second source is a category error. Nothing in "a federal advisory describes X" needs corroboration beyond the advisory. The moderate label communicates doubt about the wrong thing and will train readers to discount official primary sources they can read for themselves. Either assert the phenomenon and hedge it, or describe the document and stop hedging.
ON THE RECORDFor an NCII item, routing victims to the reporting intake while omitting the FTC Take It Down portal that the source itself links is a defensible editorial choice only if stated. I think it is the wrong choice.
The sources
Official sourceSexual Exploitation Actors Stealing and Leaking Explicit Content2026-08-10
The FBI warns that actors are compromising social media and personal accounts via password and PIN guessing, customer-service impersonation texts that harvest reset codes, and look-alike phishing domains, in order to steal explicit content and sell or post it with the victim's identifying details.
Other checks
Approved by ihubglobalhq on 2026-08-17, after review of the alert and its sources.
Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.
Phishy? Send it → sharelivefraud.com/squire-it
Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.
Naming a source is not an endorsement, and being named here is not an accusation against any company.
Powered by SquireIt™