The FBI’s Internet Crime Complaint Center published PSA 260810 on August 10, 2026: criminals are taking over social media and personal accounts — not with a new zero-day, but with password stuffing, lookalike support email, and stolen MFA codes. Stolen account access is then used to take non-consensual intimate images (NCII) and personal details for sale or further harassment.
This post is about the email / identity / MFA controls. It is not a how-to for storing or recovering intimate files. Malwarebytes and BleepingComputer repeated the same IC3 tactics. Cite the PSA permalink, not only a recap.
This is a different channel from Gmail recovery-contact injection. That pattern rides real Google-authenticated mail. The FBI’s phishing tactic here is lookalike customer-support domains.

Snapshot
| Field | Detail |
|---|---|
| Lead | FBI / IC3 PSA 260810 (Aug 10, 2026) |
| Channel | Lookalike support email, fake CS texts, credential stuffing |
| Goal | Account takeover → steal stored media and identity data |
| Report NCII | Type ncii.ic3.gov — do not use a mail button |
| Same-day campus note | NCAA / FBI student-athlete outreach (Aug 10) |
| CourtListener | No matching Texas or nationwide RECAP docket for this PSA (searched Aug 17, 2026) |
The PSA covers adult and underage victims as a fact of the crime. If you are in immediate danger, call 911. For NCII reporting, use the FBI portal above; NCMEC and the FTC Take It Down portal are listed on the PSA.
How the FBI says accounts are taken
IC3 lists three access methods. None of them require you to click a graphic attachment.
| Tactic | What you see | What to do |
|---|---|---|
| Password / PIN stuffing | Repeated logins using leak-site lists, birthdays, name variants | Unique passphrase; never reuse; password manager |
| Fake customer service texts | “Your account will be locked” unless you send a verification code | Do not share the code. Open the official app yourself |
| Phishing email | “New login” from a lookalike support domain + reset link | Do not click. Type the real site or use a bookmark |
The FBI’s wording is explicit: a legitimate platform will not ask you for a verification code, temporary password, or PIN reset code. That is the same class of OTP theft as live FaceTime bank scams — the code is meant for the real site, not for a stranger.

What to do on email and MFA (right now)
- Treat unexpected “new login” / “account disabled” mail as hostile. Hover the URL on a computer; on a phone, do not tap.
- Open Instagram, Facebook, or Google by typing the address or using the app you already installed — not a search-ad or mail button.
- Turn on phishing-resistant sign-in where the vendor documents it: passkeys, hardware security keys, and/or Google Authenticator / open TOTP. Drop SMS as the only factor.
- If you did not request a reset, do not send the code to anyone. Review active sessions in-account and sign out unknowns.
- Staff / athletic departments: the same-day NCAA notice is outreach for student-athletes’ public profiles — it is not in the PSA body. Train coaches not to click “support” mail.
MFA: YubiKey, Google Authenticator, passkeys
Directory grades use public vendor docs. SMS still being offered does not erase a documented security-key or open-TOTP path. Passkeys alone do not promote Fail → Strong when SMS/email OTP is the whole story — that rule is why Google and Facebook can be Strong while a portal that only documents email OTP stays Fail.
| Platform | Directory grade | Documented methods |
|---|---|---|
| Google Account | Strong | Passkeys, YubiKey-class keys, Google Authenticator / open TOTP |
| Strong | U2F / FIDO2 security keys, authentication app, Meta passkeys (SMS still offered) | |
| Pass | Authentication app (Google Authenticator / Duo named); Meta passkeys; SMS still offered |
Instagram’s own 2FA help asks you to choose SMS or a third-party authentication app. That is enough for Pass (open TOTP). Hardware keys are documented on Facebook / Meta Account 2FA (“tap your security key”) and adding a U2F/FIDO2 key — we do not mark Instagram YubiKey = Yes from Facebook’s article alone. Meta passkeys cover Instagram.
| Method | Prefer against this PSA? |
|---|---|
| Passkeys (FIDO / WebAuthn) | Yes — bound to the real origin, not a lookalike page |
| Hardware security key (YubiKey-class) | Yes — phishing-resistant |
| Google Authenticator / open TOTP | Yes — better than SMS; still hide the code from texts |
| SMS / voice OTP | Avoid as the only factor (SIM-swap and “send me the code”) |
Docs: Google passkeys · Google Authenticator / 2-Step · Google security keys · Instagram authentication app · Facebook 2FA · Meta passkeys · MFA directory
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| YubiKey 5 / 5C NFC case | Keychain protection for the key | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP vault | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited reporting and social-login related hosts on August 17, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not prove a “support” message is authentic.
| Organization | Domain | Overall | Identity | Transport | Website | vs 100% |
|---|---|---|---|---|---|---|
| IC3 | ic3.gov | 87% | 90% | 45% | 97% | −13 |
| instagram.com | 80% | 75% | 15% | 97% | −20 | |
| Malwarebytes | malwarebytes.com | 71% | 90% | 45% | 43% | −29 |
| FBI | fbi.gov | 64% | 75% | 45% | 40% | −36 |
| facebook.com | 62% | 25% | 50% | 97% | −38 | |
| google.com | 55% | 50% | 70% | 37% | −45 | |
| NCII portal | ncii.ic3.gov | 52% | 0% | 45% | 100% | −48 |
How to read this table: Type ncii.ic3.gov and ic3.gov yourself. The NCII hostname’s Identity 0% is typical of a no-MX reporting subdomain — it is not a reason to follow a mail link that claims to be IC3.
Audit links: ic3.gov · instagram.com · malwarebytes.com · fbi.gov · facebook.com · google.com · ncii.ic3.gov

Website stack note
Passive website-tech probes on August 17, 2026:
| Domain | Stack signal |
|---|---|
| ic3.gov / fbi.gov / ncii.ic3.gov | No notable public CMS/PHP flags (government surfaces) |
| instagram.com / facebook.com | No notable CMS flag; CT certificates expire 2026-09-10 (~24 days) — Meta-class rotation, not a phishing tell |
| google.com | No notable CMS flag; HTTP→HTTPS redirect not confirmed on the probed host |
| malwarebytes.com | WordPress, generator version hidden |
Point-in-time only. Stack hygiene does not validate a “support” From address.
Blacklist and lookalike domains
Email blacklist checks (public DoH, August 17, 2026): ic3.gov, ncii.ic3.gov, malwarebytes.com, instagram.com, facebook.com, and google.com were clear on mail/domain lists we can query. fbi.gov showed an SPFBL hit on mx-west.fbi.gov (153.31.192.142) — treat as list noise, not a reason to click FBI-branded mail. Type fbi.gov / ic3.gov.
DNS lookalike scans (EmailMeNow cybersquat engine — registered DNS signals only, not WHOIS authority):
| Brand scanned | To review | Likely owned | BEC staging |
|---|---|---|---|
| instagram.com | 110 | 8 | 0 |
| google.com | 110 | 10 | 2 |
| facebook.com | 64 | 63 | 0 |
| ic3.gov | 15 | 0 | 1 |
| fbi.gov | 11 | 0 | 0 |
High-interest registered names (investigate; not proof the FBI campaign used them):
| Lookalike | Technique | Note |
|---|---|---|
| instagram-login.com | affix | NS/A/MX on third-party DNS — login-themed |
| support-instagram.com | affix | Cloudflare NS — not Meta’s ns.facebook.com |
| instagramsupport.com / instagram-help.com / facebook-support.com | affix | NS at *.ns.facebook.com — likely Meta-held |
| googl3.com / googlw.com | homoglyph / adjacent-key | Google BEC staging (NS, MX) |
| ic3.com | tld-swap | MX present (unrelated Cybersource mail path) — still a confusing TLD swap |
Many Facebook typos already CNAME toward Facebook. Continuous monitoring: Cybersquat Domain Monitoring.
Related coverage
- Gmail recovery-contact injection (real Google mail vs lookalike domains)
- MFA support directory — YubiKey, authenticator apps & passkeys (Google Strong; Facebook Strong; Instagram Pass)
- FaceTime bank scam (live-call OTP theft)
- WindRelay / SpyNote Android NFC relay (sideload + card tap)
- Surfside Beach BEC + lookalike domains
- Top Texas colleges & universities (NCAA / campus angle)
Run a free audit at audit.emailmenow.com or contact EmailMeNow for phishing response aimed at the 100% ideal.
Sources: FBI IC3 PSA 260810 · Malwarebytes, Aug 11, 2026 · BleepingComputer, Aug 12, 2026 · TechCrunch, Aug 11, 2026 · NCAA, Aug 10, 2026 · Instagram authentication app 2FA · Facebook 2FA / security keys · Meta passkeys · Google passkeys · NCMEC · FTC Take It Down. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches August 17, 2026. Domain scores: audit.emailmenow.com only.