Free Shipping on All Domestic Orders!

Buy Now

The ‘Call Her Daddy’ Hack: How Criminals Took Over the Control Room Behind Our Social Media Assets

image_pdfimage_print

Not Sure Where to Start?

Discover what works best for your body and lifestyle—whether you’re exploring for the first time or coming back for your favorites, we’ve got you covered.

“Guess who wants to interview you, Sister Kate. Guess!” Two of the Sisters were standing in my office in late December, excited.  “I don’t know. Who?” I asked.  They answered in unison: “Alex Cooper!”  I had to admit I didn’t know who he was.  “She,” they corrected me, “of the Call Her Daddy podcast”.

I was confused. Why would “she” want to be called Daddy?  But the Sisters persisted. “You have an email and you should answer them right away!”  And that is how it began.

I am 67 years old. I founded Sisters of the Valley more than a decade ago, and although our work has received international media attention, I do not pretend to know every major podcaster or influencer followed by women half my age. The younger Sisters knew Alex Cooper. They knew Call Her Daddy. More importantly, they believed an invitation from her team made sense.

I looked her up and saw that she had interviewed Michelle Obama, and dang, you can’t get more respectable than that, being called “Daddy” notwithstanding.

We are the Sisters of the Valley, often called the “weed nuns.” We are a women-led company with a large social media following, an unusual public story, and more than a decade of press behind us. We have been interviewed by media outlets around the world. People contact us for interviews. There was nothing inherently absurd about Alex Cooper wanting to talk to us.

That was the first thing the criminals stole from us: plausibility.  They would later steal something from Alex Cooper too: her credibility. And they would use both to get inside the control room behind our social media business.

image 1 call her daddy hack

This Was Not a Typical Hack

The people who targeted us were patient. They did not send one ridiculous email asking for a password. They did not threaten us, tell us we had won a prize, or ask us to wire money to a prince. They presented themselves as people arranging a legitimate media appearance with one of the most famous women in podcasting.

There were communications. There were scheduled calls. There was a professional Zoom meeting. There were explanations about a LIVE event and how our followers would be notified when the appearance happened. And there was one particularly powerful ingredient: Meta sponsorship.  We were told Meta was involved with the LIVE.

That mattered because the technical instructions that followed involved Meta’s own business and event-management tools. We were not being told to send a password to a stranger or download some mysterious piece of software. We were being guided through systems connected to the social media business we had already been operating for years.

The explanation sounded plausible. For a LIVE event of this size, we were told, certain event functions had to be activated so that followers could be notified and the event could be properly connected.

We followed instructions. Then nothing happened after that call. The expected interview did not happen. We heard nothing more. We assumed Alex Cooper had found someone more interesting to interview. We forgot about it.  That, we now understand, may have been part of what made the operation so effective.

hacked asset image1

Then They Came Back

Months later, on April 17, the man presenting himself as “Jeff from Call Her Daddy” contacted me again. He had an explanation for the delay. Meta was backed up. The event was still waiting for Meta approval. They needed us to do the setup again.

Think about how effective that is.  The first time we had followed the instructions, nothing terrible appeared to happen. Our Facebook page did not vanish. Our Instagram account did not disappear. No one demanded ransom. No one posted pornography on our feed. No one changed our profile picture to a skull and crossbones. Nothing happened.

So when “Jeff” returned months later and explained that the delay was on Meta’s side, the story had its own internal logic. We had already done the process once. We had survived it. Why would we suddenly think the second request was dangerous?

So I went back in. I activated the event-management function again. I used my own Sisters of the Valley business email address. I believed I was completing a technical requirement for a LIVE appearance with Alex Cooper.  And then, once again, nothing happened.  At least, nothing we could see.

The Silence Was the Point

Most of us have an idea of what being hacked looks like. You wake up and cannot log in. Your password has changed. Your page is gone. Strange posts appear. Your friends start receiving messages asking for money. Someone announces themselves. Something breaks.

That is not what happened to us.  Our pages stayed up. We could still post. We could still create content. Our followers could still see us. From the outside, Sisters of the Valley looked like Sisters of the Valley. From the inside, we continued working.

What we did not understand was that the public Facebook and Instagram pages were not the whole business.  Behind them sits another layer: the administrative machinery that controls business assets, permissions, people, pages, Instagram accounts, advertising functions and access. Most ordinary users never think about that layer. Many business owners barely look at it unless they need to change something.  The storefront was still open. But someone had apparently gotten into the control room behind it.  And we did not know.

The Most Frightening Hack Is the One That Does Not Interrupt You

This is what every influencer, creator, small business, nonprofit, media company and social media manager needs to understand: a sophisticated attacker may not want to throw you out immediately.

Why would they?  If they lock you out on the first day, you know you have been hacked. You panic. You call your staff. You change passwords. You start reporting. You warn people.  But if your page keeps working, you go back to work.  That is what we did.

We posted. We ran the business. We communicated with customers. We assumed we were in control because the parts of the business we could see still responded when we touched them.  Meanwhile, we were blind to what was happening in the administrative layer behind those pages.

We do not yet know everything that was changed, everything that was connected, or everything the people behind this operation could see or do during that period. That uncertainty is part of the danger. This kind of attack does not need to announce itself. It can wait. Changes can be made slowly. The rightful owners can continue producing content, attracting followers, running ads and building value while control behind the scenes shifts quietly.  The victim may continue feeding the very machine that has been taken from them.

image 4 call her daddy hack

Not Sure Where to Start?

Discover what works best for your body and lifestyle—whether you’re exploring for the first time or coming back for your favorites, we’ve got you covered.

The Collaboration Tools Are Part of What Makes This So Dangerous

There is another dimension to this attack that every business owner and creator should understand.  Social media platforms have spent years building tools that allow people to collaborate. Businesses can add administrators, partners, employees, agencies, event managers and other people with different levels of access. Pages can be connected to Instagram accounts. Advertising assets can be shared. Teams can work together without handing everyone the same password.

Those tools exist for legitimate reasons. Modern businesses need them.  But the same complexity creates an extraordinary opportunity for social engineering.

A criminal does not necessarily have to stand outside the system trying to smash through the front door. The criminal can persuade the rightful owner to make a change from inside the legitimate system. The victim may be clicking real buttons, inside a real business-management environment, while following fraudulent instructions delivered over a professional-looking call.

That distinction matters.  We were not asked to hand ‘Jeff’ our Facebook password. We were given a story about collaboration: a major podcast, a LIVE event, Meta sponsorship, follower notifications and event-management requirements. The technical steps were wrapped inside a business explanation that made them seem necessary.

That is what makes this type of operation so dangerous. The criminal does not merely imitate the platform. The criminal may use the platform’s own complexity, role structures and collaboration functions as part of the deception.

The victim can do the clicking.  The victim can make the changes.  The victim can believe she is preparing for a legitimate collaboration.  And the victim may not understand what she has actually changed until months later.

This Was Not a Prank

There is another reason we are telling this story plainly. Whoever did this appears to have spent months on the operation.

They used the identity and reputation of Alex Cooper and Call Her Daddy. They allegedly misrepresented themselves as connected to her team. They invoked Meta sponsorship. They communicated across electronic systems. They participated in live calls. They offered technical explanations. They guided us through business-management functions. They disappeared. They waited. Then they returned with a plausible explanation for the delay and persuaded us to repeat the process.

We do not know who “Jeff” really is. We do not know whether he worked alone. We do not know how many other people have been targeted in the same way.  But this was not a prank call.

Conduct like this can potentially implicate multiple serious federal and state crimes, depending on what investigators ultimately establish: wire fraud, unauthorized computer access, identity-related fraud, impersonation-based fraud, and potentially conspiracy if multiple people were working together. A months-long operation can also involve multiple criminal counts rather than one single offense.

We are not prosecutors, and we are not pretending to know what charges could ultimately be proved. We are saying something simpler.  Someone appears to have invested months in getting behind the administrative controls of our business.  And for more than two months after April 17, we had no idea.

We Found Out by Accident

In late June, Sister Camilla came to me with what seemed like an ordinary business matter. Instagram appeared to owe us about $175 in content earnings, and a message indicated that we needed to finish setting up banking information to receive the money.

On July 1, I went to take care of it. I followed what appeared to be a Meta-related payment path and began entering banking information.  Something felt wrong. I stopped. I checked the site.  It was a fraudulent Meta site (so now they’ve impersonated Alex Cooper and they’ve impersonated Meta).  Suddenly, everything that had happened earlier, the invitation, the planned LIVE event with Alex Cooper, claims of Meta sponsorship, event-management changes, strange administrative problems and a fake payment path no longer looked like unrelated annoyances.  We started looking behind the pages.  And that is when we realized we had a much bigger problem.

image 3 call her daddy hack

We Were Still There — But We Were No Longer in Control

This is the part that is difficult to explain until it happens to you.  We had not lost our public identity. We had lost control of the machinery behind it.  We can still post on pages associated with the business. But we can no longer properly administer the business assets we spent years building. Our Facebook and Instagram presence still exists, but the business-administration layer behind them has been compromised.

Then we tried to report it.  And that is where the story became almost impossible to believe.  When we followed Facebook links intended to help with compromised access and business problems, those links did not lead us to a functioning path for reporting this kind of business-admin takeover. On our accounts and devices, we were repeatedly taken instead to options such as:

Create a New Page.

or:

Create an Ad.

Imagine discovering that someone may have taken control of the administrative machinery behind your business and then finding that the emergency exits no longer lead outside.  One points you toward building another room.  The other asks if you would like to spend money.

This Problem Was Already Big Enough for 41 Attorneys General

We now know that we are far from the only people confronting account takeovers and failed recovery systems.  In March 2024, a bipartisan coalition of 41 state attorneys general wrote to Meta about what they described as a rise in Facebook and Instagram account takeovers by scammers and fraudsters. The attorneys general called on Meta to take action to protect users and respond to people whose accounts had been taken over.

That matters to us for a very simple reason: by the time our own business was compromised, the problem of social media account takeovers was not obscure. It was not new. It was not something no one had warned Meta about.  Forty-one attorneys general had already raised the alarm. And yet here we are.

We are a ten-year-old American company. Our business depends in part on social media assets built over years. We still have public-facing access to our pages. We can still post. But we cannot properly control the administrative machinery behind those assets, and the ordinary reporting paths we have tried do not accommodate what happened to us.

That is not merely inconvenient.

For a small business, social media assets can represent years of work, customer relationships, advertising history, audience development, intellectual property, reputation and revenue. Losing administrative control while the public pages remain active creates a particularly dangerous kind of uncertainty because the business may not even know the full extent of what has been changed.  The 41 attorneys general were warning about harm to real people and real businesses.  We are now one of them.

Alex Cooper Is Not the Villain in This Story

We want to be very clear about that. Alex Cooper was victimized too.  The people behind this operation appear to have taken something valuable from her before they ever took anything from us. They took her credibility. They took the trust associated with her name. They took the reputation of Call Her Daddy. They took the entirely reasonable belief that a successful women-led podcast might want to interview the founder of a successful and unusual women-led company.  Then they weaponized that credibility against us.

They stole our business by stealing her credibility first.  That is why we are telling this story now.  Because somewhere, right now, another influencer may be answering an exciting email. Another creator may be joining a professional-looking Zoom call. Another small business owner may be told that Meta is sponsoring a LIVE. Another social media manager may be patiently following instructions inside a legitimate business-management tool because the person on the call sounds competent, the explanation makes sense, and the opportunity is plausible.

And after they follow those instructions, nothing may happen.  Their page may stay up. Their Instagram may keep working. They may post the next morning. They may go weeks or months believing everything is fine.  That is the warning.

The new sophisticated hack may not steal your page. It may steal the control room behind your page.  It may leave the lights on. It may let you keep working.  And that may be exactly how it keeps you from realizing that someone else is already inside.

What To Do – Where To Go

On July 6, 2026, the Sisters of the Valley filed formal reports in two places: with the FBI’s Internet Crime Complaint Center and with the Federal Trade Commission.  In those filings, we provided the chronology of the months-long impersonation scheme and provided all the identifying information used by the hackers.  We preserved the emails, phone numbers, messages, domains, screenshots, administrative records and other evidence associated with the operation.

There was a moment of dystopian absurdity when I landed on the FBI’s Internet Crime Complaint landing page, and it has a huge notice on top, the first words are a warning to the public that scammers are now impersonating the Internet Crime Complaint Center itself.   I wish I wasn’t making this up. 

We do not know whether Jeff, fraudulently representing as part of the Alex Cooper Team, targeted only us.  We doubt it.

The moral of this story is that if you are approached by someone claiming to represent Call Her Daddy, Alex Cooper, another major podcast, a celebrity, or a media company — and are told that a Meta-sponsored LIVE required you to activate your event settings, STOP.  Preserve the evidence.  Report it.  Because the people who targeted us were patient enough to wait for months.  They came into our control room in a premeditated and devious way; don’t let them into yours.

 

Not Sure Where to Start?

Discover what works best for your body and lifestyle—whether you’re exploring for the first time or coming back for your favorites, we’ve got you covered.

Disclaimer: The information shared in this article is for educational and informational purposes only. Sisters of the Valley products are not intended to diagnose, treat, cure, or prevent any disease, and nothing on this website should be interpreted as medical, legal, or professional advice. All content, including references to plant-based remedies, ancestral healing practices, wellness rituals, or user experiences, reflects general information and is not a substitute for professional medical guidance. Always consult a qualified healthcare professional before using any herbal, hemp, or wellness product—especially if you have a medical condition, take medication, or are pregnant or nursing. Sisters of the Valley makes no medical or therapeutic claims, and we do not guarantee any specific results. Regulatory information regarding hemp or cannabinoids is subject to change. Any actions taken based on the content provided are at your own risk. Sisters of the Valley assumes no liability for decisions or outcomes based on the information on this website.

Comments are closed.

Navigate