Fappening continues: Sarah Hyland and Kylie Jenner were victimized

•General•Lucia Danes
18 sources
Comments (0)

The rich, the famous, and the attractive — these are the main targets of the Fappening leaks [1] which have already exposed thousands of private images belonging to a few dozens of global celebrities.

You can find the names of Jennifer Lawrence, Justin Verlander, Emma Watson and Scarlett Johansson in the list of the Fappening victims and this list continues to grow even longer [2].

According to the latest reports, Sarah Hyland, a co-star of the TV drama Modern Family was in for an unpleasant surprise when she found out that her iCloud account could have potentially been broken into and the images, as well as some video material of her posted on some underground Internet photo dumps [3]. Nevertheless, some claim that the images actually belong to Hyland's lookalike and not the celebrity herself.

Despite all the uncertainties regarding the situation, Hyland's representatives have announced that legal mechanism is already running and the publishers or distributors of actress private data will be prosecuted.

Kylie Jenner's Snapchat leaves hackers empty-handed

Hacking is a win-or-lose game in which you can never know what comes out of it. Kylie Jenner's case shows that you can never be too careful with your social media. The Internet celebrity's Snapchat account has been recently hacked, followed by the perpetrator's threats to publish naked photos found on the app.

Fortunately, after a few days of digging up, the hackers had to admit that this Fappening leak attempt was a fail and there was no information on Jenner's account that could be regarded as "valuable" to them.

Neither the star's spokespeople, nor Kyle herself has commented on the situation, but the attacker's source has already been banned.

Protecting your private information

While the images can be an eye-candy for some, you can only imagine how uncomfortable the whole situation is for the people involved. You should remember that it is not only the famous people that get involved in the hackers' traps.

For instance, there are ransomware viruses such as Petya, Cerber or Chimera that can steal your personal files and demand a ransom for their recovery and even threaten to publish the stolen data online if the ransom is not paid in time.

To stay safe, take precautions listed below:

  1. Secure your social media accounts with strong passwords, consisting of at least 8 different characters and including special symbols. Make sure you don't use the same password for several accounts as well.
  2. Be careful what you share or post online. There are things that are better be left private.
  3. Create backup copies of your sensitive documents, images, video and audio material. This way the information will remain safe even if your device gets broken into.
  4. Make sure applications you are using are updated to the latest versions. Vulnerabilities of unpatched or outdated apps can be exploited more easily.

Fappening timeline: Sarah Hyland, Kylie Jenner and the wider leak wave

The old report above covers two separate stories: a claim about Sarah Hyland's iCloud account and a takeover of Kylie Jenner's Snapchat. This update adds the dates, the court record, the law and the protection steps that the original did not include. It is written for anyone who stores private photos in a cloud account, famous or not.

Key dates around the Fappening leaks and the court cases that followed
DateWhat happenedWhy it matters
Nov 2012 to Sep 2014A Pennsylvania man runs a phishing scheme against Apple and Google accounts[5]Investigators identified over 600 victims, yet found no evidence that he posted anything online[5]
Nov 2013 to Aug 2014An Illinois man phishes more than 300 iCloud and Gmail accounts[6]At least 30 of the accounts belonged to celebrities[6]
Apr 2013 to Oct 2014A Connecticut man phishes about 240 iCloud accounts[7]He traded passwords and stolen material with other people[7]
Aug 31, 2014Rumors spread that celebrity photos were taken from iCloud[4]Start of the leak wave known as Celebgate or the Fappening
Sep 2, 2014Apple says certain accounts fell to a targeted attack on user names, passwords and security questions[4]Apple said none of the cases it examined came from a breach of its own systems[4]
Sep 21, 2014A second batch of photos appears on image boards and Reddit[18]Shows how one leak feeds the next
Oct 26, 2016The Pennsylvania man is sentenced to 18 months in federal prison[5]A felony under the Computer Fraud and Abuse Act[5]
Jan 24, 2017The Illinois man is sentenced to nine months and ordered to pay $5,700 restitution[6][8]The charge carried a maximum of five years[8]
Jul 23, 2017Fans notice that Kylie Jenner's Snapchat Stories show content from a hacker[9]No personal photos were shared, and the hacker later said none existed[9]
2017 reportsSarah Hyland is named in leak reports; her representatives announce legal action[3]Whether the images were hers was disputed[3]
Aug 29, 2018The Connecticut man is sentenced to eight months plus three years of supervised release[7]Charged in January 2018 and pleaded guilty in April 2018[7]
Timeline of the Fappening celebrity account leaks from August 2014 to the August 2018 sentencing of the third phishing hacker, with victim counts from three federal cases
Timeline built by 2-Spyware from the dates in Apple's 2014 statement, three Justice Department press releases and the Allure report on the Snapchat takeover.

Two points stand out. First, the dates of the crimes sit in 2013 and 2014, while the sentencing news arrived in 2016, 2017 and 2018. Headlines about a new Fappening in those years often described older thefts or new takeovers of other accounts. Second, the court documents describe phishing, not a break into Apple's servers.[4][5][6][7]

What the sources say about the Hyland and Jenner reports

The original article says Sarah Hyland's iCloud account could have been broken into, that some people claimed the pictures showed a lookalike, and that her representatives promised legal action against anyone who publishes or distributes the material.[3] That is still the full public picture in the sources we read. We found no court filing, police statement or Apple statement that confirms how any Hyland account was accessed.

Kylie Jenner's case is better documented. Allure reported that on Sunday, July 23, 2017, fans saw a Snap code for a user who claimed to hold private photos of her. According to the same report, no personal photos were shared, the hacker later posted that no such photos existed, the suspect's Twitter account was suspended and her Snapchat returned to normal.[9] The old text says the hackers needed a few days of digging before admitting failure, so the sources differ on timing. They agree that nothing was published.

A takeover without a leak still counts as an attack. The account owner lost control for a time, and the intruder could post whatever they wanted to millions of followers. That is why the protection steps below matter even when an attacker finds nothing.

How celebrity account takeovers happen

The federal cases give an unusually clear view of the method, because the defendants pleaded guilty and the plea agreements spelled out what they did. In all three, the main tool was a fake message that made the victim hand over a password.[5][6][7]

How the accounts in the court cases were reached
MethodHow it workedDefence
Phishing emailMessages that looked like they came from Apple, Google or an internet provider's security team asked for a user name and password[5][6][7]Never answer a message that asks for a password; the FTC says legitimate companies do not email links to update your payment information[11]
Fake sign-in pageVictims were sent to a website that quietly collected what they typed[6][7]Type the address yourself or use the official app
Guessable security questionsApple described the 2014 attack as aimed at user names, passwords and security questions[4]Use answers that cannot be found online, or a password manager to store random ones (our analysis)
Password only, no second checkA stolen password was enough to open the account (our analysis of the plea documents)Two-factor sign-in asks for a code on a trusted device as well[12]
Cloud backup downloadIn some cases a program pulled the whole iCloud backup of the victim[5]Protect the cloud account first, because the backup holds everything from the phone[5]
Reused or weak passwordsNot stated in the cases; Apple advised a strong password in 2014[4]A different password for every account (our analysis)

For the Snapchat case, the reports we read do not say how the account was taken over. Do not assume phishing there. The only claim we can make is that the attacker gained enough access to post into the Stories feed.[9]

If you want a plain walk-through of the second layer of protection, read our guide to two-step verification. If a message already tricked you, use our guide to reporting phishing and the FTC steps at IdentityTheft.gov.[11]

What the law says in the UK and the US

The law treats a leak as two separate acts: getting into the account, and sharing what was found. Both are covered. This is general information, not legal advice, and the details depend on where you live.

Main laws that apply to account takeovers and leaked private images
CountryLawWhat it covers
United KingdomComputer Misuse Act 1990, section 1Unauthorised access to computer material; up to two years in prison on conviction on indictment[13]
United KingdomSexual Offences Act 2003, section 66B, added by the Online Safety Act 2023Sharing an intimate image without consent and threatening to share one; in force from January 31, 2024[14][15]
United KingdomOnline Safety Act 2023, priority offence statusPlatforms face duties to deal with this illegal content, since the Government made sharing intimate images a priority offence in 2024[15]
United StatesComputer Fraud and Abuse ActThe three phishing cases ended in guilty pleas to unauthorized access to a protected computer to obtain information[5][6][7]
United StatesTAKE IT DOWN Act, passed April 28, 2025Criminalizes publishing nonconsensual intimate images, including digital forgeries, in certain circumstances[16]
United StatesTAKE IT DOWN Act, platform dutyCovered platforms must remove an image within 48 hours of a valid notice, and the FTC enforces this[16][17]

Two details help in practice. The UK sharing offence removed the earlier need to prove that the person meant to cause distress.[15] In the US, the removal clock of 48 hours starts when a platform receives a valid request, so keep a record of when and where you sent it.[16][17]

The sentences in the celebrity cases were short compared with the harm. The Illinois judge called the crime abhorrent, and the FBI said the lasting harm to celebrities and non-celebrities alike cannot be overstated.[6] Prison terms of eight to eighteen months were the outcome in all three cases, in our view a modest figure next to hundreds of victims.[5][6][7]

Leak headlines as malware bait

Every leak headline creates a wave of searches, and criminals build traps around those searches. Malwarebytes documented one such campaign in March 2017, tied to another so-called Fappening. About 300 spam posts appeared on Twitter within 24 hours, and the shortened link in them was clicked close to 7,000 times.[10]

The chain worked like this, according to Malwarebytes. The link led to a request to install a Twitter app, which asked for permission to read the timeline, follow people, update the profile and post on the user's behalf. After that, the visitor was pushed through several pages to an Amazon gift card survey that collects an email address, with no guarantee of any file at the end.[10] The app then spammed the same bait from the victim's account.[10]

  • Fake download links. Archives and PDFs that claim to hold leaked photos are a common way to deliver malware. The FTC warns that links and attachments in scam messages can install harmful software.[11]
  • App permission traps. An app that wants to post for you can turn your own account into a spam tool, as in the 2017 campaign.[10]
  • Survey and gift card funnels. They harvest email addresses and personal details for marketers and scammers.[10]
  • Credential theft. A page that asks you to sign in to view anything is a phishing page until proven otherwise.[11]

If you clicked something, update your security software, run a full scan and remove anything it finds.[11] Our guides on removing malware leftovers and running a Defender offline scan cover the steps. If you typed a password into a page you did not trust, change it from a different device and follow the FTC advice at IdentityTheft.gov.[11]

There is also a simple moral point. The photos in these leaks were taken without permission. Malwarebytes put it bluntly: the sensible choice is to leave the leak alone.[10]

Six steps to protect your cloud and social accounts

Six steps that block most account takeovers: unique password, two-factor sign-in, distrust login links, fix recovery options, review devices and apps, know where to report
The six steps in one picture. Details for each step follow below.

1. Give every account its own password. Apple's 2014 advice was to use a strong password and turn on two-step verification, and that advice still applies.[4] A password manager creates and stores long random passwords, so you do not have to remember them.

2. Turn on two-factor sign-in, starting with email and cloud storage. With two-factor authentication on an Apple Account, a new device or browser needs your password plus a six-digit code from a trusted device or phone number.[12] The FTC describes the same idea as something you know plus something you have or are.[11] Prefer an authenticator app or a security key to text messages where the service allows it. Our two-step verification guide walks through the setup.

3. Do not sign in from links in messages. Open the official app or type the address yourself. If a message claims there is a problem with your account, contact the company on a phone number or website you already know.[11] Report fake messages through our guide to reporting phishing.

4. Check your recovery options and security questions. Apple said the 2014 attack targeted security questions as well as passwords.[4] Make sure the recovery email and phone number are yours, and replace any answer that someone could find on your public profile.

5. Review devices and connected apps. Sign out of devices you do not recognize, and remove apps that you no longer use or that ask to post for you.[10][12] Do this twice a year, and after any suspicious message.

6. Know where to report before you need to. For a takeover or fraud, use our guide to reporting cybercrime and the FTC at ReportFraud.ftc.gov in the US.[11] For private images posted without consent, contact the platform first, because covered US platforms must act within 48 hours of a valid notice.[16][17] Keep screenshots of the dates and links you reported.

If your details may also be in a wider data breach, check our breaches hub and consider a credit freeze if your personal numbers were exposed. Before you open any link from a message about a leak, paste the address into our website safety checker.

What is still unknown

  • Whether the Hyland images are hers. The old report says some people claimed they belong to a lookalike, and the sources we read do not settle it.[3]
  • How any Hyland account was accessed. We found no police, court or company statement that names a method.
  • Who ran the 2017 Snapchat takeover. Allure reports a Snap code and a suspended Twitter account, but no named suspect or method.[9]
  • What the so-called 2018 wave was. The only 2018 court document we read is the sentencing of a man whose phishing ran from 2013 to 2014. It does not describe a new 2018 operation.[7]
  • Who posted the photos. Investigators said they found no evidence linking the Pennsylvania and Illinois men to the postings.[5][6] The Connecticut man traded stolen material with others.[7]
  • Whether other victims were never told. The Pennsylvania case alone had more than 600 identified victims, and the public releases do not list them all.[5]

More on 2-Spyware

Frequently asked questions

Was Sarah Hyland's iCloud account confirmed as hacked?

No public court, police or company source we read confirms it. The original report says the account could have been broken into and that some people claimed the images belonged to a lookalike. Her representatives said legal action was under way against anyone who publishes or distributes the material.

Did Apple's iCloud get breached in the Fappening?

Apple said no. In September 2014 it said certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, and that none of the cases it examined came from a breach of its systems, including iCloud and Find my iPhone.

How do hackers get into celebrity cloud accounts?

Mostly by phishing, according to the federal cases. Three men pleaded guilty to sending fake security emails that made victims hand over their passwords, often on a fake sign-in page. A password was then enough to open email, iCloud and in some cases the full backup.

Is it illegal to share leaked private photos?

In many places, yes. In England and Wales, sharing an intimate image without consent is an offence under section 66B of the Sexual Offences Act 2003, in force from January 2024. In the US, the TAKE IT DOWN Act criminalizes publishing nonconsensual intimate images in certain circumstances.

Can links about leaked photos infect my device?

Yes. Criminals use leak headlines as bait for fake downloads, app permission traps and survey scams. Malwarebytes documented a 2017 Twitter campaign that reached close to 7,000 clicks on one link. The FTC warns that links and attachments in scam messages can install harmful software.

Does two-factor authentication stop account takeovers like these?

It blocks most takeovers that rely on a stolen password alone. With two-factor sign-in, a new device also needs a code from a trusted device or phone number, so the password by itself is not enough. It does not help if you hand the code itself to a scammer.

What should I do if my private photos are posted without my consent?

Report them to the platform at once and keep screenshots of the links and dates. Covered US platforms must remove a reported image within 48 hours of a valid notice. Then report the account takeover to the police or the FTC, and change your passwords from a clean device.

Comments (0)

What do you think?

0 comments

No comments yet. Be the first.

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year