Mikaela Hoover's nude photos leaked in Fappening 2018

- Hackers do not intend to stop
- iCloud accounts remain vulnerable
- Protect yourself from iCloud's hack
- Mikaela Hoover leak at a glance
- Fappening 2018 timeline
- What the court cases show about how these thefts work
- What the law says in the UK and the US
- How iCloud and other cloud accounts get taken over
- How criminals use celebrity leaks as malware bait
- Protect your cloud account: six steps
- If private images of you were shared or threatened
- What is still unknown
Almost four years after the scandal known as the Fappening[1] or Celebgate was registered for the first time, hackers keep hacking celebrities' iCloud accounts and spread their nude photos all around the world. Last week, Mikaela Hoover became the second victim of the Fappening 2018.
A 33-years-old actress, best known for playing Nova Prime's assistant in Guardians of the Galaxy, has contacted the LAPD[2] already and reported a cyber crime against her, causing the loss of nearly 40,000 private photos and videos, in some of which she is captured nude. According to a report from TMZ,[3] 119 of Hoover's nudes were uploaded to the Fappening website.
Nevertheless, Hoover hasn't talked about a new wave of the Fappening that touched her personally, but, based on the news that police is under investigation, the alarm seems to be true.
Hackers do not intend to stop
Although four hackers responsible for the first two massive Fappening waves between 2014 and 2017 have been arrested, their partners keep attacking celebrities in 2018.
The first instance of the iCloud hack was registered in 2014 with the Oscar-winning Jennifer Lawrence as the most prominent victim of the scandal so far.
Hackers stopped for a while and returned in 2017 leaking personal pictures of such celebrities as Kate Upton, Miley Cyrus, Amanda Seyfried, Kristen Stewart, Dakota Johnson, Faye Brookes, Nicole Scherzinger, Maria Kanellis, Anne Hathaway, Charissa Thompson, and a newly hacked Mikaela Hoover. Most of their nude pictures leaked to sharing site 4chan,[4] Reddit, Twitter, and other media sources.
iCloud accounts remain vulnerable
Since the Fappening scandal is not a phenomenon, experts do not expatiate on the hack itself. Nonetheless, we feel the need to remind that Fappening is a scandal related to iCloud accounts. By initiating target phishing attacks, hackers manage to break into iCloud accounts and leak every piece of information stored on it.
Experts point out that in most of the cases hackers obtain the nude pictures of celebrities from Apple devices with the automatic backup function enabled. Although people can disable this feature, for the sake of data loss, most of Apple users keep iCloud service enabled by default.
FBI has already confirmed that four suspects[5] for breaking into celebrities' iCloud accounts and leaking their private photos have been arrested. All of them were sentenced from 9 to 18-months imprisonment, but that did not stop their campaigners to keep iCloud's hacks.
Protect yourself from iCloud's hack
Although hundred percent protection from Fappening hasn't yet been found, experts warn that most of the credentials to access Apple iCloud accounts were gather by initiating phishing campaigns. Potential victims received phishing emails impersonating Apple Security Department and urging people to identify themselves by entering personal details.
Keeping such strategies in mind, it's crucial to check email letters carefully. Although Apple Security Department may send confirmation requests to the Apple device users, such messages will never contain grammar or typo mistakes. Besides, they are sent to confirm the login from another device to the same account, so if you haven't logged to your account using the alternative device, report the message as spam. Having reliable anti-spyware is also a good idea.
Mikaela Hoover leak at a glance
This section adds what the press, police statements and court records have published since the first report. It describes no images and links to none. The case is a theft of private files from a cloud account, and the person to protect is the account owner.
| Question | Answer |
|---|---|
| Who | Mikaela Hoover, an American actress known for playing Nova Prime's assistant in Guardians of the Galaxy[3] |
| What was reported stolen | Up to about 40,000 private photos and videos from her iCloud storage, of which 119 were reported on a Fappening website[3][6] |
| When it was reported | Early February 2018, by TMZ, Newsweek and International Business Times[3][6][7] |
| What police did | The LAPD was investigating. TMZ reported that officers traced a couple of IP addresses and used search warrants to get account details[3][6] |
| Suspect | No suspect is named in any page we read[3][6] |
| Hoover's comment | She did not respond to Newsweek's request for comment[6] |
| How the account was entered | Not reported. No source we read says whether it was phishing, a reused password or something else[3][6][7] |
Fappening 2018 timeline

The dates below come from United States Department of Justice press releases, news reports and the original sources of this article. The 2018 leaks and the earlier court cases are separate events, and the pages we read do not link the convicted men to Hoover's leak.
| Date | Event |
|---|---|
| August 2014 | The first mass leak of private celebrity photos is posted online[6] |
| October 27, 2016 | Ryan Collins is sentenced to 18 months in federal prison for a phishing scheme against Apple and Google accounts[8] |
| January 2017 | Edward Majerczyk is sentenced to nine months for accessing at least 300 iCloud and Gmail accounts[9] |
| March 2017 | A second round of leaks circulates, and scammers use it as bait for fake apps and surveys[6][21] |
| About August 2017 | A third round follows, nearly six months before the Hoover report[6] |
| October 23, 2017 | Emilio Herrera is charged over more than 550 iCloud and Gmail accounts and signs a plea agreement[10] |
| January 2018 | Fox Sports host Charissa Thompson is reported as a victim, and a fourth defendant admits stealing from iCloud accounts[5][7] |
| Early February 2018 | TMZ, Newsweek and IBTimes report the theft from Mikaela Hoover's iCloud account and the LAPD inquiry[3][6][7] |
| August 29, 2018 | George Garofano is sentenced to eight months for phishing more than 200 iCloud accounts[13] |
What the court cases show about how these thefts work
Four men were charged or convicted in the Justice Department's Celebgate investigation, which concerns the 2014 leak. Their cases are the best public record of how iCloud accounts were taken, so they explain the method even though none of them is tied to Hoover.
| Defendant | Method and scale | Outcome |
|---|---|---|
| Ryan Collins | Emails that looked like they came from Apple or Google collected passwords. He reached at least 50 iCloud and 72 Gmail accounts, and investigators identified over 600 victims[8] | 18 months in federal prison, October 2016[8] |
| Edward Majerczyk | Emails that looked like they came from internet provider security teams sent victims to a site that collected passwords. At least 300 accounts, at least 30 of them belonging to celebrities[9] | Nine months in federal prison and $5,700 restitution, January 2017[9] |
| Emilio Herrera | A phishing scheme from April 27, 2013 to the end of August 2014 against more than 550 iCloud and Gmail accounts. The Los Angeles Times reported that investigators had found no evidence that he shared the files[10][11] | Charged October 2017 with unauthorized access, up to five years. We did not find his sentence in the pages we read[10] |
| George Garofano | Emails posing as Apple security collected iCloud passwords from April 2013 to October 2014, reaching at least 250 accounts. He traded passwords and stolen material with other people[12] | Eight months in prison, August 29, 2018[13] |
The judge in the Majerczyk case called the crime abhorrent, according to the Justice Department.[9] Sentences were short next to the five year maximum.[10] They did not end the leaks. The 2018 reports show that new victims kept appearing while the first cases were still in court.[6][7]
What the law says in the UK and the US
This is a plain summary of the texts we read and is not legal advice. Two kinds of offences matter: breaking into an account, and sharing private images without consent. The UK and the US treat both as crimes.
| Country | Law | What it covers | Penalty as written |
|---|---|---|---|
| UK | Computer Misuse Act 1990, section 1 | Causing a computer to give access to data when the access is unauthorised and the person knows it | Up to two years on conviction on indictment, or a fine, or both[17] |
| UK | Online Safety Act 2023, section 188 (new section 66B) | Sharing, or threatening to share, an intimate photograph or film of someone without consent | Up to two years on indictment for sharing with intent to harm or for sexual gratification, and for threats[18] |
| US | Computer Fraud and Abuse Act | Unauthorized access to a protected computer to obtain information, the count used in the Celebgate pleas | Statutory maximum of five years in the cases we read[10][12] |
| US | TAKE IT DOWN Act, signed May 19, 2025 | Publishing intimate images of an identifiable person without consent, and threatening to do so | Up to two years for adult victims. Platforms must remove reported images within 48 hours[19][20] |
Platforms had to be ready to receive removal requests by May 19, 2026, and the Federal Trade Commission enforces that duty. It runs TakeItDown.ftc.gov, where people can complain about a platform that ignored a valid request.[20] In 2018 these tools did not exist in this form. We did not assess which law applied to the 2018 leaks.
How iCloud and other cloud accounts get taken over
The court records point to one method above all: phishing. The reports on Hoover do not say how her account was entered, so the list below describes the usual routes and not her case.[3][6]
- Phishing emails. In all four cases the men sent emails that looked like security messages from Apple, Google or an internet provider and asked for a username and password.[8][9][10][12]
- Fake sign in pages. Majerczyk's emails pointed to a website that collected whatever victims typed in.[9]
- Reused passwords. The UK National Cyber Security Centre says that if you reuse a password and one account is compromised, an attacker can try the same password on your other accounts.[15]
- No second step at sign in. Apple says two-factor authentication makes sure you are the only person who can get into your account even if someone else knows your password.[14] The NCSC calls two-step verification the most important first step if a password is phished.[15]
- Full backups. Collins used a software program to download the whole contents of victims' iCloud backups, which shows why a stolen password can expose years of files at once.[8]
- Trading access. Garofano traded passwords and stolen material with other people, so one phished account can reach several hands.[12]
The FTC lists common signs of a phishing message: a claim of suspicious activity or a problem with your account, a request to confirm personal information, and a generic greeting.[16] Those are the same tricks the court records describe.
How criminals use celebrity leaks as malware bait
Each new leak brings a second wave of scams from people who never touched the original files. Malwarebytes documented one in March 2017, when links promising leaked material for a wrestler led to a Twitter app request and a survey page.[21]
- Close to 300 bait posts appeared in 24 hours, and one shortened link was clicked close to 7,000 times.[21]
- The link asked people to accept a Twitter app. Once installed, the app posted more bait from the victim's own account.[21]
- The next pages asked for an email address to win a gift card, which handed the address to marketers.[21]
- Malwarebytes said the visitor was not guaranteed to get any pictures at all, and it urged readers to leave the leak alone.[21]
This is our analysis: a fresh name in the news, such as Hoover's in February 2018, is the kind of search term this bait feeds on. A page that says you must install an app, an extension or a download before you can see anything is the threat, whatever it promises. Check any link first with our website safety checker. The same warning is in our guide to celebrity leak malware lures.
Protect your cloud account: six steps

1. Turn on two-factor authentication. Apple describes it as a password plus a six-digit code shown on a trusted device or sent to a trusted phone number.[14] Apple also says that most accounts already use it, so check that yours does and that your trusted phone number is current.
2. Use a different password for every account. The NCSC advises against reusing passwords, above all for email, banking, shopping and social media, and recommends a password manager so you do not have to remember them.[15]
3. Never respond to an account alert from an email. Do not click the link, even if it looks like Apple or Google. Open the official app or type the address yourself, and check whether the alert is real there. The FTC says to forward phishing emails to reportphishing@apwg.org and report them at ReportFraud.ftc.gov.[16]
4. Review which devices and phone numbers are trusted. Two-factor codes go to those places, so remove any device you no longer own or do not recognize. This step is our advice, built on how Apple describes trusted devices.[14]
5. Secure your email account first. Email is the key to every reset link, so give it the strongest password and two-step verification. The NCSC puts email at the top of its list of important accounts.[15]
6. Know where to report before you need to. Report phishing through our guide to reporting phishing and crime through our guide to reporting cybercrime. If a platform will not remove private images, use TakeItDown.ftc.gov in the US.[20] If someone has also taken money or card details, see what to do after paying a scammer.
If private images of you were shared or threatened
Keep screenshots of the posts, the account names and the dates, and do not reply to anyone who threatens you. Report the posts to each platform, which in the US must remove reported intimate images within 48 hours once the law applies to them.[19][20] In the UK, threatening to share an intimate image is itself an offence.[18] Then report the theft to the police, as Hoover did with the LAPD.[3] If your credit or identity data was also exposed, a credit freeze is free and worth a look, and our data breaches hub lists confirmed incidents.
What is still unknown
- Who took the files from Hoover's account and whether anyone was charged. No page we read names a suspect.[3][6]
- How the account was entered. TMZ and Newsweek report the theft and the police inquiry, not the method.[3][6]
- Whether the 2018 leaks are linked to the men in the Celebgate cases. We found no source that connects them.
- The exact count of images posted. TMZ and Newsweek say 119, while IBTimes says more than 110.[3][6][7]
- Herrera's sentence. The pages we read stop at his charge and plea agreement.[10]
- Whether the original article's claim of four hackers each serving 9 to 18 months matches every case. The Justice Department pages show 18, 9 and 8 months for three of them, and we found no sentence for Herrera.[8][9][10][13]
We will update this article if police or a court publish more. It was last checked on October 6, 2026.
Frequently asked questions
Was Mikaela Hoover's iCloud account hacked?
Yes, according to TMZ and Newsweek, which reported that up to about 40,000 private photos and videos were taken from her iCloud storage in early 2018. The LAPD was investigating. Neither report says how the account was entered, and Hoover did not respond to Newsweek's request for comment.
Who leaked Mikaela Hoover's photos?
Nobody has been named in any report we read. TMZ said police traced a couple of IP addresses and used search warrants to get account details, and that the hunt for a suspect was on. We found no later report of an arrest or charge.
Are the Celebgate hackers behind the 2018 leaks?
No source we read links them. The men in the court cases were charged or sentenced for thefts that happened between 2013 and 2014, and they were sentenced between 2016 and 2018. The Hoover reports do not say who took her files.
How do hackers get into iCloud accounts?
Mostly through phishing, according to the court records. The men sent emails that looked like they came from Apple, Google or an internet provider and asked victims for a password. Reused passwords and a missing second sign in step make that theft easier.
Is it illegal to share leaked private photos?
In the UK, sharing an intimate image of someone without consent is an offence under section 66B of the Online Safety Act 2023. In the US, the TAKE IT DOWN Act makes publishing such images a federal crime. This is a summary of the laws and not legal advice.
Is it safe to search for leaked celebrity photos?
No, because leak searches are a common route to scams. Malwarebytes documented bait links in 2017 that pushed people to a Twitter app and a survey page, and it told readers to leave the leak alone. The material was also taken without consent.
How can I protect my iCloud account from a leak?
Turn on two-factor authentication, use a password you use nowhere else, and never sign in through a link in an email. Apple says two-factor authentication stops others from getting in even if they know your password. Secure your email account first.
What should I do if my private images were leaked?
Save evidence, report the posts to each platform and report the crime to the police. In the US the TAKE IT DOWN Act requires covered platforms to remove reported images within 48 hours, and TakeItDown.ftc.gov takes complaints about platforms that do not. Do not pay anyone who threatens you.
Sources
- International Business Times (IBTimes). A growing digital global news
- Official Site of The LOS ANGELES POLICE DEPARTMENT
- TMZ. Entertainment news
- Wikipedia. The Free Encyclopedia
- The Hacker News
- Newsweek
- International Business Times
- US Department of Justice
- US Department of Justice
- US Department of Justice
- Los Angeles Times
- US Department of Justice
- CNN via WRAL
- Apple Support
- National Cyber Security Centre
- FTC Consumer Advice
- legislation.gov.uk
- legislation.gov.uk
- Congress.gov (CRS)
- Federal Trade Commission
- Malwarebytes
Log in to comment
No comments yet. Be the first.