Police Say Never Keep This Photo on Your Phone

Scroll far enough back in your camera roll and you hit things you forgot were ever there. A screenshot of a bank balance. A picture of your passport from a trip years ago. A photo of a boarding pass you no longer need. And, for a lot of people, photos that were only ever meant for one other person.

That last group is what federal investigators spent August 2026 warning Americans about. The FBI issued a public alert on August 10, 2026, saying criminals are breaking into social media and personal accounts of both adults and children for one specific purpose: finding intimate photos and videos and taking them. The bureau’s first piece of advice was about as blunt as government advice gets. Avoid storing sensitive images or videos on social media platforms or any internet-accessible site.

The Photo Federal Agents Say Not to Store Online

The FBI calls the people doing this sexual exploitation actors, or SE actors, and it calls the stolen material non-consensual intimate images. Once they have the files, victims are often extorted, or the content simply gets published. In the alert, the bureau wrote that “victims often face re-victimization through harassment, sextortion, stalking or other targeted attacks, such as advertising stolen content on a victim’s own social media page.”

Stolen images are also packaged for sale on criminal marketplaces with identifying details attached: name, date of birth, email address, phone number, social media username. That pairing is the whole business model, because an anonymous photo is worth far less to a buyer than a photo tied to a real person who can be found and pressured again.

One detail in the bureau’s press release surprised a lot of people who read it. The FBI said it “has determined that student-athletes are frequently targeted due to their public profiles, which are often expanded through Name, Image and Likeness activity, and their visible standing within their schools and communities.” High visibility online, a searchable name, a school roster page, and a following make a target easier to research. Rachel Tobac, CEO of the security awareness training firm SocialProof Security, said these attacks especially target young boys, and that the bureau going public may mean the cases are climbing.

They Are Not Cracking Passwords, They Are Reusing Old Ones

The methods listed in the FBI’s advisory are unglamorous. Attackers run high volumes of password and PIN attempts against accounts, using lists curated from data leak sites, social media and open sources, and salted with the victim’s own date of birth or name variations when they know who they are after. They also impersonate customer service staff, posing as a platform’s support team, and they text people claiming the account is about to be locked unless a verification code is sent back. Some send phishing emails built on fake domains that look like a real social media login page.

The bureau’s guidance includes one rule worth taping to your forehead: never share login information with anyone, even if the person says they work for a platform you use. Tech companies generally do not reach out to customers unprompted. If you get a temporary password, a PIN reset, or an access code you did not ask for, treat that as a break-in attempt in progress, not a glitch.

Another tip is oddly specific and genuinely useful. Read suspicious emails on a computer instead of your phone, because you can hover over a link and see the real destination before you touch it. On a phone, you mostly cannot. And when something about an account looks wrong, type the official web address in yourself rather than tapping whatever link showed up in the message.

The Cloud Copy You Forgot You Made

Deleting a photo from your phone and deleting it from your life are two different things. A lot of these thefts do not start with a hacked phone at all. They start with an account, and the cloud photo library quietly attached to it. Once someone is inside, they work through the stored images and pull anything usable, then move to the extortion stage.

This is why the warning applies to people who assume it does not. You do not have to be sending pictures to anyone. Years of automatic backups can pile up material you never thought of as a theft risk, because you never thought of it as stored anywhere. Auditing what is actually sitting in your cloud-connected photo library is the unsexy step almost nobody takes.

Twelve Other Photos Worth Deleting Tonight

Your camera roll has slowly turned into a filing cabinet, and a fair amount of what is filed in there should not be. Photos of your driver’s license or passport, which carry your full name, date of birth, home address, ID numbers and signature. Pictures of credit or debit cards, where the number, expiration date and security code are all sitting in one frame.

Then there is the one most people have never considered: the identity verification selfie. Banks and financial apps ask you to photograph yourself holding your ID, which welds your face to your documents in a single image. Once the account is open, that file has no reason to stay on your phone.

The rest of the list runs through screenshots of one-time passcodes, saved passwords and Wi-Fi codes, bank statements and tax documents, boarding passes and hotel confirmations with their booking references and QR codes, work documents with customer information or internal reports, QR codes tied to personal accounts or digital wallets, password reset emails with live recovery links, digitally signed contracts, and other people’s documents. That last one matters more than it sounds. A photo of your kid’s passport or a coworker’s ID puts their information in your risk pile, not yours in theirs.

Your Wallet Has the Same Problem

Identity fraud and scams cost Americans an estimated $38 billion in 2025, with 36 million victims, according to Javelin Strategy & Research, which has both figures down on 2024. A good share of that starts with something physical that was carried around for convenience.

Michael Sullivan, a personal finance consultant at a nonprofit credit counseling and debt management agency, put the logic simply in a Capital One guide to wallet contents: “Anything that’s convenient for you would be convenient for a thief.” His list of things to leave home includes your Social Security card or any document with the number on it, since those nine digits can be used to open accounts or file a tax return in your name.

Sullivan is blunt about written PINs. “Certainly carrying the PIN that goes with the debit card or even the credit card is downright foolhardy,” he said. “So you should never do that.” Linda Jacob, a certified financial planner and accredited financial counselor, adds a category most people never think of as sensitive: the answers to your security questions. Your first pet’s name and your mother’s maiden name are keys, and they should not be written down in your back pocket. Also on the list are checks and deposit slips, stacks of gift cards, a pile of rarely used store credit cards, large amounts of cash, and spare house keys, which turn a stolen wallet into a stolen address.

The App Permission That Reads Your Whole Phone

On March 31, 2026, the FBI released a separate public service announcement about foreign-developed apps, noting that as of early 2026 many of the most downloaded and top-grossing apps in the United States are built and maintained by foreign companies, particularly ones based in China. Apps that keep their digital infrastructure in China fall under China’s national security laws, which the bureau says could let the Chinese government reach user data.

The line in that notice that should stop you cold is about permissions. Once you grant access, an app can persistently collect information from across the device, not only inside the app and not only while you have it open. Default permissions on the friendly “invite your contacts” feature can hand over names, email addresses, user IDs, physical addresses and phone numbers from your address book, including for people who never downloaded the app. Some privacy policies state the collected data sits on servers in China for as long as the developers decide is necessary, and some apps will not run at all unless you agree to the sharing.

The bureau’s advice: turn off data sharing you do not need, install only verified apps from official app stores, which scan for malicious content, change passwords regularly, keep the device updated, and actually read the terms before downloading. If you think an app has compromised you, the FBI wants the report filed with the Internet Crime Complaint Center, including the app name, where you downloaded it, what permissions you granted, and what data you think was taken.

Encrypted Chat Is Not a Force Field

A March 20, 2026 alert from the FBI and the Cybersecurity and Infrastructure Security Agency described cyber actors tied to Russian Intelligence Services running phishing campaigns through Signal and possibly other commercial messaging apps, posing as automated support accounts. People who followed the instructions lost control of their accounts, and the agencies said the campaign has produced unauthorized access to thousands of individual accounts worldwide. Once inside, the attackers can read messages and contact lists, send messages, and phish the victim’s contacts.

The encryption itself was never broken, and the alert says so plainly. The accounts were. David Wiseman, vice president of secure communications at BlackBerry, told Federal News Network that people “have become overconfident in the concept of end-to-end encryption.” The bigger risk, he said, is “around identity and spoofing of identities,” and in attackers finding surreptitious ways to link themselves to someone’s account. Federal News Network singled out Salt Typhoon, the China-linked group that has infiltrated telecom networks globally, including in the United States, as the most far-reaching threat of the lot.

What the 2026 Numbers Actually Show

The Identity Theft Resource Center recorded 3,322 U.S. data compromise events in 2025, a record high and a 5% increase over 2024. FBI-reported losses from cyber-enabled crime in the United States reached nearly $21 billion in 2025. The Internet Crime Complaint Center added artificial intelligence as its own section in the 2025 annual report, logging 22,364 AI-related complaints tied to $893 million in losses, which means synthetic content has stopped being a curiosity and become ordinary fraud.

The National Center for Missing & Exploited Children received 1.4 million reports of online enticement in 2025, a 156% increase from 2024. Verizon’s 2026 Data Breach Investigations Report counts 15 attack techniques now bolstered by generative AI, with attackers using it to work faster at every stage. Leaked scraps of data, an old address, a former employer, a past purchase, get stitched together into a story convincing enough to make you click.

The FBI’s own 2026 alerts page shows how crowded the year was. Spoofed FIFA World Cup websites. Russian state-supported actors going after Western government and commercial organizations through Zimbra Collaboration Suite software since at least July 2025. China’s military intelligence services working professional networking sites and job platforms to reach Five Eyes government and military personnel. The Silent Ransom Group, also known as Luna Moth, phoning law firms while posing as their own IT staff.

If Someone Already Has Your Photos

The response guidance for sextortion is short and counterintuitive. Do not pay. Do not send more images. Report the account to the platform, block it, and save the messages and the profile, which is what lets law enforcement identify the person. Take it to the FBI whatever your age: the bureau runs a portal at ncii.ic3.gov for exactly this. Paying tends to confirm that the pressure works.

The defenses are the same boring three the FBI keeps repeating. A unique password for every account, kept in a password manager instead of a note or a screenshot. Multi-factor authentication or a passkey switched on, starting with your main email, because that inbox resets everything else. And deep suspicion of anyone who contacts you first claiming to work for a platform. The photo advice is the one piece that costs nothing and takes two minutes, and it is the one almost nobody follows.

Mike O'Leary
Mike O'Leary
Mike O'Leary is the creator of ThingsYouDidntKnow.com, a fun and popular site where he shares fascinating facts. With a knack for turning everyday topics into exciting stories, Mike's engaging style and curiosity about the world have won over many readers. His articles are a favorite for those who love discovering surprising and interesting things they never knew.

Must Read

Related Articles