
The FBI and the National Collegiate Athletic Association (NCAA) are warning student-athletes about cyber-enabled sexual exploitation schemes, saying that athletes' public profiles—and the visibility created by name, image, and likeness (NIL) activities—can make them a target for extortionists.
The joint initiative aims to help athletes recognize the warning signs, report incidents quickly and seek support without fear or shame.
College athletes often have a larger digital footprint than other students. Team rosters, social media accounts, interviews, competition schedules and NIL partnerships can reveal names, contact details, relationships, locations and personal interests.
That visibility is valuable to criminals.
Public information can be used to personalize a phishing message, impersonate a school or social media platform, or make a threat feel more credible. An offender may also assume that an athlete has more to lose if private material is shared with teammates, coaches, sponsors or the public.
According to the FBI’s public service announcement, perpetrators seek to obtain and sell private images while exploiting victims’ concern about their reputation and position within their school or community.
NIL activity can expand that exposure. Athletes building personal brands are encouraged to be visible and accessible online, sometimes maintaining public contact information or interacting with unfamiliar accounts. Those opportunities are legitimate, but they also give scammers more chances to approach them.
The FBI identified two common warning signs:
Both messages are designed to create a sense of urgency.
The text may impersonate Instagram, TikTok, Snapchat, an email provider or another service important to the athlete’s public identity. If the victim shares a one-time code, the offender may be able to reset the password and take control of the account.
A phishing email can achieve a similar result by directing the victim to a replica login page. Any username, password or recovery information entered there goes directly to the scammer.
Once inside an account, an offender may search private messages, cloud storage or archived conversations for intimate material. They may also impersonate the victim, approach people in their contact list or use the compromised account to target others.
After obtaining an image—or convincing the victim that they have one—the offender may threaten to distribute it unless the victim pays, sends additional material or provides proof of identity.
The threat is meant to produce panic. Athletes may fear losing scholarships, sponsorships, team relationships or control over their public image. Shame and isolation can make the demand feel like a private problem that must be solved immediately.
But compliance rarely gives the victim control.
The FBI and NCAA warn that continued communication, payments and compliance with demands don’t reliably prevent distribution. Instead, they frequently result in additional demands.
The scale of the wider problem is significant. The National Center for Missing & Exploited Children (NCMEC) received more than 50,000 reports of financially motivated sextortion in 2025—an average of 137 reports a day, up from more than 36,000 in 2024.
Those figures focus on children and teens and should not be treated as a count of incidents involving college athletes. They do, however, show how rapidly image-based extortion has grown and why early education matters.
Take control of the situation:
Preserve the evidence. Save messages, usernames, profile links, email addresses, phone numbers, payment requests and transaction details. Take screenshots, but don’t redistribute intimate material while documenting the incident.
Stop communicating. Do not negotiate, argue or make promises. Preserve the available evidence and block the offender.
Do not pay or send more material. Payment does not guarantee deletion or silence. It may show the offender that further pressure could produce more money.
Do not click additional links or open files. The offender may try to steal more credentials, install malware or collect identity documents.
Secure the affected account. From a trusted device, change the password through the service’s official app or website. Sign out other sessions, review recovery details and connected applications, and enable multi-factor authentication. Consider using a password manager to avoid using the same password across multiple accounts.
Tell someone you trust. A parent, counselor, compliance officer or campus safety representative can help preserve evidence, contact platforms and reach the appropriate authorities. The FBI is asking athletic departments to prepare these resources in advance because trusted adults may be the first people an athlete approaches.
Report the incident. Non-consensual intimate images can be reported through the FBI’s NCII reporting portal. Reports can also be submitted through tips.fbi.gov or by calling 1-800-CALL-FBI.
If the person depicted was under 18 when the image was taken, NCMEC’s CyberTipline and free Take It Down service can provide additional support and help limit online distribution.
FBI Operation Director Jose Perez said:
This initiative is about making sure student-athletes, and anyone who may become a target, know that help is available.
Simply make attacks harder to carry out:
Security tools with anti-phishing protection add a layer of defense. Use Bitdefender Scam Protection to assess suspicious interactions online.
Related:
'I've hacked your devices' mail is still a common scam. Don't fall for it!
"Your account has been locked" - 7 telltale signs of a phishing scam
tags
Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.
View all posts