Back to news
Cybersecurity Alert
August 17, 2026 by EmailMeNow IT Consulting

FBI: Lookalike Support Emails and Stolen MFA Codes Unlock Social Accounts

FBI PSA 2026-08-10: phishing lookalike domains and fake support texts steal MFA codes to take over social accounts. Audits (ideal 100%): ic3.gov 87%, instagram.com 80%, google.com 55%. Instagram MFA Pass; Facebook Strong.

Source: FBI IC3 · Malwarebytes · BleepingComputer

NewsPhishingMFAFBIInstagramPasskeysYubiKeyAuthenticator AppsCybersecurity
Laptop inbox showing a suspicious new-login email from a lookalike social-support address

The FBI’s Internet Crime Complaint Center published PSA 260810 on August 10, 2026: criminals are taking over social media and personal accounts — not with a new zero-day, but with password stuffing, lookalike support email, and stolen MFA codes. Stolen account access is then used to take non-consensual intimate images (NCII) and personal details for sale or further harassment.

This post is about the email / identity / MFA controls. It is not a how-to for storing or recovering intimate files. Malwarebytes and BleepingComputer repeated the same IC3 tactics. Cite the PSA permalink, not only a recap.

This is a different channel from Gmail recovery-contact injection. That pattern rides real Google-authenticated mail. The FBI’s phishing tactic here is lookalike customer-support domains.

Laptop inbox showing a suspicious new-login email from a lookalike social-support address

Snapshot

FieldDetail
LeadFBI / IC3 PSA 260810 (Aug 10, 2026)
ChannelLookalike support email, fake CS texts, credential stuffing
GoalAccount takeover → steal stored media and identity data
Report NCIIType ncii.ic3.gov — do not use a mail button
Same-day campus noteNCAA / FBI student-athlete outreach (Aug 10)
CourtListenerNo matching Texas or nationwide RECAP docket for this PSA (searched Aug 17, 2026)

The PSA covers adult and underage victims as a fact of the crime. If you are in immediate danger, call 911. For NCII reporting, use the FBI portal above; NCMEC and the FTC Take It Down portal are listed on the PSA.

How the FBI says accounts are taken

IC3 lists three access methods. None of them require you to click a graphic attachment.

TacticWhat you seeWhat to do
Password / PIN stuffingRepeated logins using leak-site lists, birthdays, name variantsUnique passphrase; never reuse; password manager
Fake customer service texts“Your account will be locked” unless you send a verification codeDo not share the code. Open the official app yourself
Phishing email“New login” from a lookalike support domain + reset linkDo not click. Type the real site or use a bookmark

The FBI’s wording is explicit: a legitimate platform will not ask you for a verification code, temporary password, or PIN reset code. That is the same class of OTP theft as live FaceTime bank scams — the code is meant for the real site, not for a stranger.

Fake account-lock text on a phone next to someone opening the official app instead of sharing a code

What to do on email and MFA (right now)

  1. Treat unexpected “new login” / “account disabled” mail as hostile. Hover the URL on a computer; on a phone, do not tap.
  2. Open Instagram, Facebook, or Google by typing the address or using the app you already installed — not a search-ad or mail button.
  3. Turn on phishing-resistant sign-in where the vendor documents it: passkeys, hardware security keys, and/or Google Authenticator / open TOTP. Drop SMS as the only factor.
  4. If you did not request a reset, do not send the code to anyone. Review active sessions in-account and sign out unknowns.
  5. Staff / athletic departments: the same-day NCAA notice is outreach for student-athletes’ public profiles — it is not in the PSA body. Train coaches not to click “support” mail.

MFA: YubiKey, Google Authenticator, passkeys

Directory grades use public vendor docs. SMS still being offered does not erase a documented security-key or open-TOTP path. Passkeys alone do not promote Fail → Strong when SMS/email OTP is the whole story — that rule is why Google and Facebook can be Strong while a portal that only documents email OTP stays Fail.

PlatformDirectory gradeDocumented methods
Google AccountStrongPasskeys, YubiKey-class keys, Google Authenticator / open TOTP
FacebookStrongU2F / FIDO2 security keys, authentication app, Meta passkeys (SMS still offered)
InstagramPassAuthentication app (Google Authenticator / Duo named); Meta passkeys; SMS still offered

Instagram’s own 2FA help asks you to choose SMS or a third-party authentication app. That is enough for Pass (open TOTP). Hardware keys are documented on Facebook / Meta Account 2FA (“tap your security key”) and adding a U2F/FIDO2 key — we do not mark Instagram YubiKey = Yes from Facebook’s article alone. Meta passkeys cover Instagram.

MethodPrefer against this PSA?
Passkeys (FIDO / WebAuthn)Yes — bound to the real origin, not a lookalike page
Hardware security key (YubiKey-class)Yes — phishing-resistant
Google Authenticator / open TOTPYes — better than SMS; still hide the code from texts
SMS / voice OTPAvoid as the only factor (SIM-swap and “send me the code”)

Docs: Google passkeys · Google Authenticator / 2-Step · Google security keys · Instagram authentication app · Facebook 2FA · Meta passkeys · MFA directory

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
YubiKey 5 / 5C NFC caseKeychain protection for the keyAmazon
Proton PassPasskeys + authenticator-style TOTP vaultProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key, authenticator app, and passkey prompt beside an MFA hardening checklist

Independent cybersecurity audits

We audited reporting and social-login related hosts on August 17, 2026. 100% is the idealnone reach it. These scores are public email / transport / website posture. They do not prove a “support” message is authentic.

OrganizationDomainOverallIdentityTransportWebsitevs 100%
IC3ic3.gov87%90%45%97%−13
Instagraminstagram.com80%75%15%97%−20
Malwarebytesmalwarebytes.com71%90%45%43%−29
FBIfbi.gov64%75%45%40%−36
Facebookfacebook.com62%25%50%97%−38
Googlegoogle.com55%50%70%37%−45
NCII portalncii.ic3.gov52%0%45%100%−48

How to read this table: Type ncii.ic3.gov and ic3.gov yourself. The NCII hostname’s Identity 0% is typical of a no-MX reporting subdomain — it is not a reason to follow a mail link that claims to be IC3.

Audit links: ic3.gov · instagram.com · malwarebytes.com · fbi.gov · facebook.com · google.com · ncii.ic3.gov

Domain audit scoreboard for IC3, social platforms, and related hosts versus the 100 percent ideal

Website stack note

Passive website-tech probes on August 17, 2026:

DomainStack signal
ic3.gov / fbi.gov / ncii.ic3.govNo notable public CMS/PHP flags (government surfaces)
instagram.com / facebook.comNo notable CMS flag; CT certificates expire 2026-09-10 (~24 days) — Meta-class rotation, not a phishing tell
google.comNo notable CMS flag; HTTP→HTTPS redirect not confirmed on the probed host
malwarebytes.comWordPress, generator version hidden

Point-in-time only. Stack hygiene does not validate a “support” From address.

Blacklist and lookalike domains

Email blacklist checks (public DoH, August 17, 2026): ic3.gov, ncii.ic3.gov, malwarebytes.com, instagram.com, facebook.com, and google.com were clear on mail/domain lists we can query. fbi.gov showed an SPFBL hit on mx-west.fbi.gov (153.31.192.142) — treat as list noise, not a reason to click FBI-branded mail. Type fbi.gov / ic3.gov.

DNS lookalike scans (EmailMeNow cybersquat engine — registered DNS signals only, not WHOIS authority):

Brand scannedTo reviewLikely ownedBEC staging
instagram.com11080
google.com110102
facebook.com64630
ic3.gov1501
fbi.gov1100

High-interest registered names (investigate; not proof the FBI campaign used them):

LookalikeTechniqueNote
instagram-login.comaffixNS/A/MX on third-party DNS — login-themed
support-instagram.comaffixCloudflare NS — not Meta’s ns.facebook.com
instagramsupport.com / instagram-help.com / facebook-support.comaffixNS at *.ns.facebook.com — likely Meta-held
googl3.com / googlw.comhomoglyph / adjacent-keyGoogle BEC staging (NS, MX)
ic3.comtld-swapMX present (unrelated Cybersource mail path) — still a confusing TLD swap

Many Facebook typos already CNAME toward Facebook. Continuous monitoring: Cybersquat Domain Monitoring.


Run a free audit at audit.emailmenow.com or contact EmailMeNow for phishing response aimed at the 100% ideal.


Sources: FBI IC3 PSA 260810 · Malwarebytes, Aug 11, 2026 · BleepingComputer, Aug 12, 2026 · TechCrunch, Aug 11, 2026 · NCAA, Aug 10, 2026 · Instagram authentication app 2FA · Facebook 2FA / security keys · Meta passkeys · Google passkeys · NCMEC · FTC Take It Down. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches August 17, 2026. Domain scores: audit.emailmenow.com only.