A large-scale theft of private celebrity photos and videos was tied to targeted compromises of Apple and Google accounts, with investigators and researchers describing an underground ecosystem that used phishing, social engineering, password-recovery abuse, remote-access malware, and stolen authentication tokens to reach cloud backups. Security reporting at the time said iCloud was a frequent target because automatic backup features could expose not only photos but also messages, address books, deleted files, and broader device-management capabilities once an attacker gained access, while stolen iTunes or other local tokens could also be used to authenticate to iCloud.
U.S. prosecutors later charged Pennsylvania man Ryan Collins with illegally accessing more than 100 email accounts between 2012 and 2014 by sending phishing emails that impersonated Apple or Google and harvesting usernames and passwords; in some cases, he then accessed full iCloud backups and obtained nude photos and videos. The Justice Department said investigators found no evidence that Collins distributed the material or was responsible for the public "Celebgate" leaks, which were circulated on sites including 4chan, Reddit, and anon-ib, where the stolen media appeared to move from private trading circles into public release.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Ryan Collins conducted a phishing scheme that illegally accessed more than 100 Apple and Google email accounts, many belonging to entertainment industry members. According to prosecutors, the campaign ran from November 2012 to early September 2014 and was used to obtain credentials and, in some cases, entire iCloud backups.
The U.S. Department of Justice announced charges against Ryan Collins for felony computer hacking tied to unauthorized access to more than 100 Apple and Google accounts. Prosecutors said investigators found no evidence that Collins was responsible for the September 2014 public leaks or that he shared the stolen material.
Apple stated that the incidents resulted from targeted attacks on usernames, passwords, and security questions rather than any breach of Apple systems. A later report also noted Apple had confirmed only that certain celebrities' accounts were compromised, not that 100 iCloud accounts were affected.
Security analysis published after the leak said attackers primarily relied on social engineering, phishing, password recovery abuse, RATs, and stolen authentication tokens rather than the widely discussed iBrute Find My iPhone brute-force technique. The analysis also said compromised cloud backups could expose far more than photos, including messages and deleted files.
Private celebrity photos and videos stolen from cloud-based backup services were distributed publicly on anon-ib, 4chan, and Reddit. Reporting described the leak as the visible portion of a broader underground trading ecosystem for stolen media.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.