Cybersecurity and privacy advisor for content creators, he/him. DM or email for all inquiries! sparrowlabs@proton.me

Joined May 2026
11 Photos and videos
Pinned Tweet
Hi everyone! I'm Jim, a cybersecurity professional with 10 years of experience looking to help advise and work with folks in the content creator and VTuber spaces. Mainly focused on preventing doxxing and hacking as well as improving one's personal privacy online.
1
9
1,248
Always sanitize your links and remove tracking before sharing! Don't accidentally dox yourself.
youtube has unveiled a bold new feature: doxxing people
1
55
You can also usually disable the "show my profile when sharing links" setting on most apps, but it's best to make a habit of removing tracking anyway. Additionally Some sites like TikTok make this a bit more difficult to do, here's a guide I posted: x.com/TheLabSparrow/status/2…

Replying to @TheLabSparrow
TikTok bakes in the tracking link every time you try to share something. This requires an extra step to remove the tracking which I have outlined here! This way you don't accidentally reveal a personal profile when sharing content. (2/3)
19
Sparrow Labs retweeted
Jun 11
STUPID ASS HACKER FUMBLED ME THE CHANCE OF A CENTURY SERIOUSLY MAN I COULDVE HAD IT ALLLLLLL
19
119
6,716
240,370
No joke, this is #1 way VTubers, streamers, and content creators are getting hacked right now. The Discord message "download this Minecraft mod/client/join this server" from compromised accounts is so common recently, every week I see posts like this. Verify before downloading!
this is not a joke, btmc has been hacked, this is likely the message used that he fell victim to.
1
2
5
671
If you get a message like this from someone you know/trust, contact them on a separate line of communication to verify if it is actually them. Phone call, email, DM, etc. before downloading. And once downloaded, upload it to virustotal.com/ to scan and double check.

1
56
Proper password management, MFA, and most other measures to keep accounts safe are defeated by this due to the malware stealing and exfiltrating your session tokens. The attacker literally steals your logged in session. Don't install anything you haven't verified and scanned!
31
Great example on why using virtual/secondary phone numbers and business-only emails for any brand related social media is important! Don't use any personal contact or recovery info on content creator accounts that could be used to dox you
New @instagram bug: Why bro masking emails and phone numbers during password recovery when you can just display them in full? Account recovery or account discovery? Meta care to explain? #Meta #Instagram #CyberSecurity #Privacy
2
54
Sparrow Labs retweeted
> be Zuckerberg > needs AI everywhere (apparently) > lays off a bunch of employees > replaces with AI > fast forward > AI is dog shit > AI tricked into stealing accounts > try to fix > fail like 5 times > product now leaking CEOs PII AI truly is the future, wow
89
646
8,715
265,171
Sparrow Labs retweeted
Reminder this is tomorrow! Come join the @SocksAgency public discord to see it live. Will be on YouTube shortly after.
We would like to begin to offer free seminars to the public hosted by a range of professionals in the field on things you should learn and be aware of, your first one will be with @deanelazab the date will be June 5th at 5pm EST! The seminar will include: Basic terms of contracts all content creators see, and the five biggest traps in there. It describes what to look for, what the red flags are, and how to adjust to your favor. It will also briefly cover the team the creator should build for themselves and what each role does between agent, manager, lawyer and accountant. one hour of seminar with slides, with 20-30 minutes for free questions after. These seminars will be hosted on our public discord
2
38
1,755
Sparrow Labs retweeted
We have done this partly because the first result when searching Citra on Google is a fake website, which doesn't properly disclose it's not official. It is even making profit of it by displaying ads, which is pretty shady. DO NOT USE THIS WEBSITE!
We have started hosting a backup of Citra's website before it was taken down. This page is a snapshot of the site as it was on March 4th 2024, with a few modifications that have been disclosed.
5
762
4,804
136,362
Sparrow Labs retweeted
It’s wild how Meta - a company going all-in on AI - somehow missed the memo on how AI can generate images and videos that renders ā€œtake a selfie of yourselfā€ verifications utterly useless So now Instagram accounts hacked at scale. 2FA also fully bypassed - by Meta’s own design
Today Instagram had this massive exploit where hackers were just stealing rare handles left and right. Hundreds of accounts gone. People losing handles they’ve owned since 2010, some worth hundreds of thousands. I own a few rare ones so I was actually stressed watching this happen in real time, which I haven’t been in years. Obama White House account got hit. These aren’t some random new accounts, these are verified, locked down accounts and they still got compromised. The thing is the exploit is so simple it’s almost funny. Attacker goes to Forgot Password, says their account is hacked, turns on a VPN to match the target’s location (which now you can find on the about section of the page). Instagram’s AI support flow asks them to verify with a selfie. They grab a photo from the target’s profile, run it through an AI video generator to make an animation of the person’s face moving around, upload that to Meta’s AI as proof. And Meta’s AI just accepts it because it can’t tell the difference between a real selfie and an AI-generated video of someone’s face . Once verified they change the email to theirs. Password reset link goes to their email. They own it now. 2FA gets bypassed somehow in the process but honestly I don’t know exactly how, just that it did. Point is even locked down accounts went down. Then you try to recover your account and you’re talking to a chatbot that has zero ability to help. You can’t escalate to a human. You’re just stuck. Your asset is gone and there’s no one to call. The whole thing just highlighted how stupid it is to automate account security without any human in the loop. One AI fooling another AI while there’s literally no person anywhere to catch it. Meta took hours to even acknowledge it while accounts were getting stolen every minute. Now thankfully it’s patched but I don’t think it will be the last one. Stay safe!
34
191
1,598
253,166
The Meta AI Instagram hack is *still* an issue and Meta has not patched it despite claims otherwise. Be wary of any unusual emails regarding "reactivation" etc of your Instagram account, as phishing scams are taking advantage of the confusion to further steal accounts from users
Hackers have reportedly hijacked several high-profile Instagram accounts using Meta’s own AI chatbot Attackers were able to access accounts, including Sephora’s, by asking the AI Support Assistant to change the email address linked to the profile
1
30
Sparrow Labs retweeted
In addition, we're seeing an uptick in standard IG phishing using these issues to increase clicks. Attackers are sending phishing emails and texts saying there is an issue with your IG and to click here to regain control (stealing your pw/code). Don't fall for those either!
5
27
1,907
Sparrow Labs retweeted
ā€¼ļøšŸšØ BREAKING: Meta's AI feature let attackers hijack Instagram accounts for days with nothing but a username. It was being A/B tested on a slice of users, and if you were in the test, you couldn't turn it off. Among the casualties: the official Obama White House account. The method: get on a VPN near the target's region, ask the Meta AI support agent to send a verification code to any email you control, relay that code back to the agent, and it hands over a password reset link. Without ID or human review. From there, the account is yours. The flaw lived in the AI's logic layer, which acted on recovery requests with no real identity checks. One researcher compared it to the Roblox AI assistant exploit from days earlier, where you needed a target's billing info. Instagram was easier: the username and a regional VPN were enough and victims reported sessions revoked and passwords changed with no email, text, or push alert at all. By the time it went public, the method was common knowledge in blackhat Telegram circles and had been used to allegedly hijack 100 high-value accounts. Accounts hit: - obamawhitehouse (the archived official Obama White House account, ~2.4M followers. Hackers posted an AI-generated image captioned "The White House is under Shiites' control," plus cryptic anti-Trump and pro-Iranian Stories. Meta confirmed the hack and scrubbed it. - Premium short handles like hey and jowo, worth over $1M combined, stolen and flipped on Telegram. - albert (owned by Albert Renshaw), whose owner publicly reported being locked out and unable to reach Meta support. Meta has since patched it. There was no public acknowledgment.
63
308
2,272
317,647
After a lot of consideration and the impending doom and despair that is growing in my head, my husband I have opened a GoFundMe to help me with my medical & recovery bills. Any likes, retweets, reposts, or comments are appreciated and I'm sorry to ask this of you, link below ā¤ļø
11
123
321
31,150
Sparrow Labs retweeted
May 31
if you still have the facebook app please check if you have this setting turned on absolutely crazy
188
977
6,891
857,256
Sparrow Labs retweeted
Please, don’t rush to sign anything with anyone in general, but especially during a fear moment like we are in right now. Please have everything reviewed before you sign.
4
33
1,668
Not sure if a link someone sent is safe? Copy paste it into urlscan urlscan.io/ to safely check the link destination and a preview screenshot. Especially useful if ever viewing a link sent by a chatter during stream. Make sure to set the search to private!
1
1
27
Best practice is to do this with any and every link sent to you in stream chat and over social media, even from known contacts. If a URL shortener is used (especially an IP grabber one) then this effectively bypasses that and shows the final expanded URL as well
17
semi-related, people need to stop treating scam victims as if they're stupid. scams are growing increasingly believable, and victims aren't always in the right headspace to be extra vigilant. we need more polite warnings like this, not condescending, high-and-mighty scolding.
Read to avoid this issue. Please stop getting hack.
29
2,768
9,343
121,727