Private photos of more than 100 celebrities, including Jennifer Lawrence and Kate Upton, were stolen from personal accounts and widely distributed online after first appearing on anonymous forums such as 4chan and AnonIB, with some posters seeking bitcoin in exchange for additional material. The leak spread rapidly across social platforms and media sites, prompted FBI involvement, and drew public condemnation and threatened legal action from victims and representatives, who described the disclosures as a severe invasion of privacy. A second wave of stolen images later surfaced, extending the impact to additional public figures including Kim Kardashian, Gabrielle Union, Amber Heard, and Rihanna.
Subsequent U.S. prosecutors said the thefts were not caused by a breach of Apple’s infrastructure but by targeted phishing and account-compromise activity against iCloud and Gmail users. Ryan Collins later pleaded guilty after investigators found he had accessed more than 120 accounts by sending fake Apple- and Google-themed messages, harvesting credentials, and downloading backups and emails that contained sensitive photos. Apple said its review found no compromise of iCloud or Find My iPhone, instead pointing to attacks on usernames, passwords, and security questions, while reporting later highlighted how readily available phishing kits and backup-extraction tools lowered the barrier for the intrusions.

Get the infrastructure and lures behind it.
14 events from the most recent confirmed update back to the earliest known activity.
George Garofano, a Connecticut man tied to the 2014 celebrity photo hacking scandal, was sentenced in federal court to eight months in prison after pleading guilty. Authorities said he used phishing emails disguised as Apple security messages to steal credentials for more than 200 iCloud accounts, followed by supervised release and community service.
Court filings and reporting clarified that the 2014 celebrity photo thefts were driven by social engineering and credential theft rather than a compromise of Apple's infrastructure. The case reinforced Apple's earlier position that iCloud itself had not been breached and prompted renewed guidance on spotting phishing emails.
U.S. prosecutors said Ryan Collins unlawfully accessed at least 50 iCloud accounts and 72 Gmail accounts, compromising more than 120 accounts overall and stealing private photos through phishing emails masquerading as Apple or Google messages. Collins pleaded guilty under the Computer Fraud and Abuse Act and was expected to accept an 18-month sentence.
In June 2015, CNN reported that the FBI had obtained a search warrant and seized computers, phones, and storage media from Emilio Herrera as part of the investigation into the stolen celebrity photos. The action marked a concrete investigative step beyond the earlier general acknowledgment that federal authorities were looking into the case.
Reporting on October 7, 2014 said Nick Hogan, son of wrestler Hulk Hogan, had become the first publicly identified male victim in the celebrity photo leak scandal. The disclosure showed the incident was still expanding with additional victims named after the second wave of leaked images.
On 2014-10-02, attorney Marty Singer sent a letter threatening Google with a $100 million lawsuit, accusing the company of profiting from and failing to promptly remove stolen celebrity photos from its services. The move marked a more specific legal escalation aimed at a major internet platform rather than only condemning the original theft.
A new batch of stolen celebrity images was released less than a month after the first incident, naming additional victims including Kim Kardashian, Gabrielle Union, Amber Heard, and others, along with previously unseen Jennifer Lawrence photos. Several victims and representatives again condemned the leak and said they would contact the FBI or pursue legal action.
Victoria Justice publicly stated that some photos attributed to her were fabricated, while also calling the broader incident a massive invasion of privacy. She said she was pursuing legal action as reporting continued to describe the leak as affecting more than 100 celebrities.
Following an internal investigation, Apple said it found no evidence that iCloud or other Apple systems were compromised. The company attributed the thefts to targeted attacks on usernames, passwords, and security questions, and said it was cooperating with law enforcement.
U.S. federal investigators said they were aware of the alleged computer intrusions and unlawful release of material involving high-profile individuals and began investigating the incident. Reports around the first leak and later victim statements both referenced FBI involvement.
In the aftermath of the leak, online users focused on Bryan Hamade, who used the handle BluntMastermind, after a screenshot appeared to expose identifying details; he denied being the hacker and said he only pretended to have the images for bitcoin. Separately, an anonymous figure calling himself 'Original Guy' claimed on a deep web forum to have assembled images bought from different hackers.
Reporting highlighted a GitHub-hosted Python script that allegedly exploited a weakness in Apple’s Find My iPhone service, allowing repeated password guesses against iCloud-linked accounts without lockout or alerts. Users said the behavior changed shortly afterward, with accounts locking after five failed attempts, suggesting Apple may have quietly mitigated the issue while investigating.
After the first wave surfaced, celebrities and their representatives publicly responded, with some confirming images were authentic, others disputing fakes, and several threatening legal action over the stolen material. Jennifer Lawrence's spokesman called the leak a flagrant violation of privacy.
A large cache of intimate celebrity photos began circulating online after being posted to anonymous boards including 4chan, with some posts offering additional material for bitcoin or PayPal. The leak affected roughly 100 celebrities and quickly spread to other platforms such as Reddit.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
21 references tracked. Mallory keeps watching after this page renders.
apnews.com
Open sourcetheguardian.com
Open sourcetheguardian.com
Open sourceforbes.com
Open sourcesmh.com.au
Open sourcetheverge.com
Open sourcewashingtonpost.com
Open sourcetheguardian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.