The Fappening in 2026: Celebgate Hackers and iCloud Risks

•Security•Lucia Danes
8 sources
Comments (0)

The Fappening in 2026: the short answer

The Fappening, also known as Celebgate, is a closed criminal case. Private photos of Jennifer Lawrence, Kate Upton and other celebrities leaked online in 2014, and by 2019 five men had been convicted and sentenced in the United States.[6][7] George Garofano, the subject of our original report below, received eight months in prison in August 2018.[2]

The most important lesson has not changed. iCloud itself was not broken into. Investigators found that the attackers used phishing emails and guessed security questions to take over accounts one by one.[6] The same tricks still work in 2026, which is why Apple keeps warning users about fake Apple messages and calls.[8] We found no new criminal case tied to the 2014 leak as of 2026.

The Fappening (Celebgate) at a glance
QuestionAnswer
When did the leak happen?The photos surfaced in 2014[6]
Was iCloud hacked?No security flaw was found; accounts were taken over through social engineering[6]
How many people were convicted?Five men by March 2019[7]
Longest sentence34 months for Christopher Brannan in 2019[6]
Garofano's sentenceEight months in prison and three years of supervised release[6]
Main attack methodPhishing emails that looked like Apple or Google security messages[6][7]

Timeline: from the 2014 leak to the last sentence

Timeline of The Fappening celebrity photo leak from the 2014 iCloud phishing attacks to the five Celebgate sentences handed down by 2019
The Fappening (Celebgate) case from 2014 to 2019. Sources: AppleInsider, Refinery29.
Celebgate sentences by date
DateEvent
2014Nude photos and videos of celebrities surface online and spread on file-sharing services[6]
October 2016Ryan Collins of Pennsylvania is sentenced to 18 months in prison[7]
January 2017Edward Majerczyk of Chicago gets nine months and must pay $5,700 for a victim's counseling[7]
March 2018Emilio Herrera of Chicago is sentenced to 16 months[7]
August 2018George Garofano of Connecticut is sentenced to eight months[7]
March 1, 2019Christopher Brannan, a former Virginia teacher, is sentenced to 34 months[6][7]

What changed since 2018

When we first covered the case in 2018, Garofano was the latest name in a growing list. Half a year later the list closed with Christopher Brannan. He admitted to unauthorized access to a protected computer and aggravated identity theft and received 34 months, the longest Celebgate sentence.[6] Court filings said he reached more than 200 victims across iCloud, Yahoo and Facebook accounts.[6]

Brannan's method shows how low-tech these attacks were. He answered password reset questions with details from the victims' public social media profiles, and he sent phishing emails from addresses that looked like Apple security accounts.[6] Ryan Collins used the same kind of fake Apple and Google emails and also asked some victims for photos under the cover of modeling jobs.[7]

One detail is often lost in the search results. Reports on Collins said that direct evidence of him leaking the photos had not been found.[7] The people convicted were punished mainly for breaking into accounts. Who first posted the files in 2014 is not settled in the sources we read.

Risks around The Fappening searches today (our analysis)

Search terms like "the fappening" and "thefappening pro" still get thousands of searches. In our analysis, that traffic is a target for scammers, not a source of real leaks.

  • Leak sites with malicious ads. Pages that promise celebrity nudes often push fake video players, "update your player" prompts and redirect chains that end in adware or scam pages. Our virus removal guides cover the most common ones.
  • Fake download buttons. A "download the full pack" file is a common way to deliver password stealers. No real archive needs an installer.
  • Phishing that copies Apple. The original attackers posed as Apple security staff.[6] Fake Apple emails, texts and support calls are still in circulation, and Apple warns about all three.[8]
  • Harm to victims and legal risk. The photos were stolen. Sharing or reposting them hurts real people, and laws on non-consensual intimate images apply in many countries.

How to protect your cloud account from a Celebgate-style attack

Six steps to protect an iCloud or Google account from Fappening-style phishing in 2026: two-factor sign-in, unique password, ignore fake Apple messages and more
Six steps that block the tricks used in The Fappening attacks. 2-Spyware, 2026.

1. Turn on two-factor authentication. Apple tells users to keep two-factor sign-in on for their Apple Account.[8] A stolen password alone is then not enough to download your photos.

2. Use a unique password. Your Apple or Google password should not be used on any other site. A leak elsewhere then cannot open your cloud storage.

3. Do not trust security emails. The Fappening attackers sent emails that looked like Apple security alerts.[6] Open Settings on your device or type the address yourself instead of tapping a link.

4. Never share passwords or codes. Apple says it never asks for your password or verification codes to provide support.[8] Anyone who asks is a scammer.

5. Make reset questions hard to guess. Brannan answered security questions with facts from public social media.[6] Keep birthdays, pet names and schools off public profiles, or use answers that are not true facts.

6. Check for leaks and act fast. Use our leak check to see whether your email appeared in a breach. If you typed your password on a suspicious page, change it at once, as Apple advises.[8]

What is still unknown

  • Who first posted the stolen files online in 2014. The sources we read link the convictions to account break-ins, not to proven posting.[7]
  • Whether any other suspects were ever charged. We found no case after the 2019 sentence as of 2026.
  • How many of the leaked files still circulate. We found no reliable count.

Our original 2018 report

The text below is our report as first published in 2018. We keep it unchanged for the record; the sections above bring it up to date.

On Wednesday, the federal judge at US district court in Bridgeport has sentenced George Garofano to eight months in prison and three years of supervised release for stealing and exposing nude photographs of Jennifer Lawrence and other celebrities in The Fappening 2014 scandal[1].

The 26-year-old hacker has managed to access private information stored on iCloud accounts of 240 people, including Hollywood stars. G. Garofano was one of four cybercriminals who hacked into the accounts and stole personal details along with intimate photos of Kate Upton, Jeniffer Lawrence, Kirsten Dunst, and others.

The prosecutors demanded a sentence of 10 to 16 months in federal prison. However, G. Garofano's lawyer asked for leniency and no more than a five-month punishment with a five-month home confinement[2]. The sentencing memo presented to the court by the prosecutor stated the following:

Mr Garofano's offense was a serious one. He illegally hacked into his victims' online accounts, invaded their privacy, and stole their personal information, including private and intimate photos. He did not engage in this conduct on just one occasion. He engaged in this conduct 240 times over the course of 18 months.

The Fappening hacker pleaded guilty in the court

George Garofano pleaded guilty in April and admitted that he hacked 240 iCloud accounts to access private information[3]. The prosecutor had a solid statement to the court for this offense and emphasized that the attacker not only stole nude photos but also leaked them online:

Not only did Mr Garofano keep for himself the photographs he stole, he disseminated them to other individuals. He may have also sold them to others to earn 'extra income'.

However, the defense said that the crime was conducted when G. Garofano was still in college. Now, he has matured and taking responsibility for such actions[4]:

He now stands before the court having matured, accepting responsibility for his actions and having not been in trouble with the law since <…> There is nothing to suggest that he would ever engage in this or any other criminal conduct in the future.

The attacker impersonated Apple's security team to obtain iCloud logins and passwords

G. Garofano explained that he managed to access 240 different iCloud accounts with the help of social engineering tactics and deceptive spam emails. The hacker impersonated Apple's security team and sent fraudulent emails to the potential targets of interest[5].

The spam emails helped him to collect logins and passwords to iCloud accounts and steal private photographs. Likewise, cybersecurity experts warn to be vigilant and never open suspicious and unverified emails even if they look legitimate. Be cautious to avoid hacking attempts.

Frequently asked questions

What was The Fappening?

The Fappening, also called Celebgate, was the 2014 leak of private nude photos and videos of celebrities such as Jennifer Lawrence. The files were stolen from personal cloud and email accounts, mostly through phishing and guessed security questions, and then spread on file-sharing sites.{6}{7}

Was The Fappening caused by an iCloud hack?

No, not by a flaw in iCloud itself. Apple denied an iCloud breach in 2014, and later investigation found the accounts were opened through social engineering. The attackers tricked victims into giving passwords or answered their security questions with public information.{6}

Who went to prison for The Fappening celebrity leaks?

Five men were convicted by 2019. Ryan Collins got 18 months, Edward Majerczyk got nine months, Emilio Herrera got 16 months, George Garofano got eight months and Christopher Brannan got 34 months in prison, according to press reports of the sentences.{6}{7}

How did George Garofano get into the iCloud accounts?

He used phishing. Garofano sent emails that pretended to come from Apple's security team and collected the logins and passwords that victims typed in. He admitted to accessing about 240 iCloud accounts over 18 months and received eight months in prison in August 2018.{2}{5}

Are sites like thefappening.pro safe to visit?

We do not recommend them. In our analysis, sites that promise leaked celebrity nudes often carry aggressive ads, fake download buttons and scam redirects. Viewing or sharing stolen intimate images can also cause real harm to the victims and may break the law where you live.

How can I protect my iCloud account from a Fappening-style attack?

Turn on two-factor authentication and never type your Apple Account password or codes into a page someone sends you. Apple says it never asks for this information to provide support. If you entered your password on a suspicious site, change it right away.{8}

Comments (0)

What do you think?

0 comments

No comments yet. Be the first.

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year