The FBI and NCAA are teaming up to combat cyber-enabled sexual exploitation targeting college athletes as criminals break into online accounts to steal private and intimate photos. Stolen images can be posted or sold online or used for sextortion, harassment, and stalking.
Athletes can be particularly attractive targets because large social-media followings and name, image, and likeness activity increase their public exposure and give criminals more leverage when threatening to release private material. The FBI and NCAA have not disclosed how many athletes have been victimized.
How attackers get into athletes’ accounts
Attackers are using phishing, password and PIN targeting, and fake social-media customer-service requests to gain access. One tactic involves impersonating a platform’s support team and creating urgency around a supposed password reset, a variation of phishing campaigns that impersonate trusted brands to steal credentials.
In March 2025, federal prosecutors indicted former University of Michigan football coach Matthew Weiss on computer-access and identity-theft charges. Prosecutors alleged that Weiss obtained data from athlete databases at more than 100 colleges and universities and used that information and internet research to access the social-media, email, or cloud-storage accounts of thousands of athletes, students, and alumni.
He allegedly downloaded private intimate photographs and videos from compromised accounts. The charges are allegations, and an indictment is not evidence of guilt.
Password reuse can also turn one exposed credential into access to multiple services, a common feature of credential-stuffing attacks involving reused passwords.
How athletes and campus teams can reduce the risk
CISA recommends strong, unique passwords, password managers, multifactor authentication, and heightened awareness of phishing attempts. MFA adds another authentication requirement even when a password has been compromised, while phishing-resistant methods provide stronger protection against attackers trying to capture login credentials.
Athletes should treat unsolicited account-recovery messages with suspicion, verify support requests through a platform’s official app or website, and avoid sharing passwords, PINs, or authentication codes with anyone who contacts them unexpectedly. If an account is compromised, users should change their credentials, review active sessions and recovery settings, and begin the platform’s official account-recovery process.
The FBI advises victims of sextortion or suspicious online approaches to preserve relevant messages, block and report perpetrators, and seek help rather than complying with threats. The bureau also warns that people online may not be who they claim to be and that compromised social-media accounts can be used to impersonate others.
Athletics departments and campus IT teams can incorporate those tactics into security training, particularly for athletes managing high-profile social accounts or NIL activity. A compromised personal account can expose private information while giving an attacker a trusted identity from which to target teammates, staff, or followers.
Victims can report suspected cybercrime or sextortion to the FBI and should preserve evidence before deleting messages or compromised content.
Also read: Our Windows 11 security cheat sheet covers passkeys, BitLocker, Microsoft Defender, and other built-in protections.