My iCloud Photos Were Hacked and Leaked — What to Do Now
If you just discovered that someone accessed your iCloud account and leaked your private photos, you are dealing with two problems at once: a security breach and non-consensual distribution of your images. Here is how to handle both, starting with the most urgent steps.
Before anything else, lock down your account to stop ongoing access:
Change Your Apple ID Password Right Now
- Go to appleid.apple.com or use Settings on your iPhone/Mac
- Change your password to something strong and unique — at least 16 characters, not used anywhere else
- If you cannot access your account, use Apple's account recovery process immediately
Enable Two-Factor Authentication (2FA)
If 2FA was not already on, this is likely how you were compromised. Enable it now:
- On iPhone: Settings > your name > Sign-In & Security > Two-Factor Authentication
- On Mac: System Settings > your name > Sign-In & Security
- This requires a trusted device or phone number to approve any new sign-in
Review Trusted Devices
- Go to appleid.apple.com and check the Devices section
- Remove any devices you do not recognize
- If you see unfamiliar devices, the attacker may have added their own device as trusted — remove them all and re-add only your devices
Check for Third-Party App Access
- Review any apps that have access to your iCloud data
- Revoke access for anything you do not recognize or no longer use
- Check Settings > Privacy & Security > Safety Check on iOS for a comprehensive review
Change Passwords Everywhere
If the attacker got into your iCloud, they may have accessed passwords stored in iCloud Keychain:
- Change passwords for email, banking, and social media first
- Use a password manager to generate unique passwords for each account
- Enable 2FA everywhere it is available
How iCloud Hacks Happen
Understanding how you were compromised helps prevent it from happening again:
- Phishing: Fake Apple emails or texts that trick you into entering your Apple ID credentials on a lookalike website. This is the most common method.
- Password reuse: If you used the same password on another site that was breached, attackers try those credentials on iCloud.
- Social engineering: Someone who knows your security questions or has access to your recovery email/phone number.
- Former partner access: An ex who knew your password or remained logged in on a shared device.
- SIM swapping: The attacker convinced your phone carrier to transfer your number to their SIM, then used it to bypass 2FA.
Find Where Your Photos Have Spread
Once your account is secure, assess the damage:
- Reverse image search: Use Google Images or TinEye to search for your photos. This catches copies that have been posted on websites indexed by search engines.
- Search your name: Google your name, usernames, and any handles associated with your accounts. Leaked content is sometimes posted alongside identifying information.
- Check common leak sites: Without visiting them directly, search Google for your name plus the names of known leak sites to see if results appear.
- Check social media: Search for your name or images on Twitter, Reddit, and Telegram using platform search tools.
Get the Content Removed
For every platform where you find your images, file a removal report:
- Use each platform's non-consensual intimate image reporting process
- Reference the TAKE IT DOWN Act, which requires removal within 48 hours
- For sites without a clear reporting process, send DMCA notices (you own the copyright to photos you took)
Google De-Indexing
Even before source sites remove content, get it out of search results:
- Use Google's non-consensual explicit image removal tool
- File with Bing's content removal form (also covers Yahoo and DuckDuckGo)
- This stops the content from spreading further through search
StopNCII.org
Create hashes of your compromised images through StopNCII.org. Partner platforms will automatically detect and block matching content, preventing re-uploads across Meta, TikTok, Reddit, Bumble, and other participating platforms.
Report the Crime
An iCloud hack resulting in leaked intimate images involves multiple crimes:
- Computer fraud: Unauthorized access to your account (federal crime under the Computer Fraud and Abuse Act)
- Non-consensual distribution of intimate images: Illegal under the TAKE IT DOWN Act and most state revenge porn laws
- Identity theft: If the attacker used your personal information
File reports with:
- Your local police department
- FBI's Internet Crime Complaint Center (IC3) at ic3.gov — computer intrusion and sextortion are FBI priorities
- Apple's security team at reportphishing@apple.com
Preventing Future Breaches
After securing your account and addressing the leaked content:
- Use a unique, strong password for your Apple ID that you do not use anywhere else
- Keep 2FA enabled permanently
- Be skeptical of any email, text, or call claiming to be from Apple — verify by going directly to appleid.apple.com
- Consider using Apple's Advanced Data Protection feature, which enables end-to-end encryption for iCloud data including photos
- Regularly review your trusted devices and app permissions
Getting Help With Removal
If your photos have spread to multiple sites, dealing with each platform individually while also managing the emotional toll of a breach can be overwhelming. IntimaShield handles the entire removal process — platform reports, DMCA takedowns, search de-indexing, and monitoring — so you can focus on securing your accounts and your peace of mind.
This Was a Crime Against You
Having your private photos stolen and distributed is a violation. The person who did this committed federal crimes. You are not at fault for having private photos on your own cloud storage — that is a normal, reasonable thing to do. Direct your energy toward securing your accounts, removing the content, and pursuing justice.
Start a free confidential scan →