FBI and Researchers Warn of Sextortion and Shopify Refund Scams
FBI warns hackers are stealing explicit photos for sextortion, while researchers uncover a Shopify refund scam abusing real app notifications. Here's how to stay safe.
In an advisory published Monday, reported by ZDNet, the FBI said that hackers are breaking into social media and personal accounts to steal explicit images from both adults and minors. The images are then sold on the dark web, often with personal details such as name, date of birth, email, and phone number, which can be used in blackmail campaigns known as sextortion.
The FBI identified three primary hacking methods. One involves using password-cracking tools on lists of accounts exposed in earlier data breaches. Another relies on impersonating customer service agents, sending text messages that claim an account is disabled and requesting a password reset code. The third uses phishing emails with links that look like legitimate password-change pages but actually give attackers access.
To avoid falling victim, the FBI advises people not to store sensitive images or videos on public or social platforms. It also recommends unique and complex passwords or passphrases, enabling multi-factor authentication wherever available, avoiding embedded links from unexpected emails and texts, and checking suspicious emails on a computer where hovering over links can reveal suspicious URLs. Users should also be wary of temporary passwords or access codes they did not request.
In a separate report covered by TechRadar, security firm Huntress detailed a fake refund scam built on Shopify's infrastructure. The attackers create a new store or compromise an existing one, then place an order for the target using their phone number or email address. Because the order is a real transaction in Shopify's system, users see an authentic notification in the Shop app or as a push notification on their phone.
To lure victims into action, the scammers leave their contact details in the shipping address. In one example, the address read: “Owen Nolan 2856 If You Didnt Place This Order Call Us at 1_888_690_3420-, Albany NY United States 1_888_690_3420.” If the target calls, the scammer claims a refund was issued by mistake and asks the victim to return the money. Since the refund never occurred, the victim sends their own funds.
Huntress advises users to ignore suspicious phone numbers, email addresses, or links in order notifications and to verify with their bank whether a refund actually exists. Orders that appear fraudulent can be reported as “Not my order” in the Shop app. It also suggests checking a store's reviews and history before making purchases; many scam stores were recently created and used a “coming soon” description.