What starts as a news headline about well-known public figures and celebrities being used in AI deepfakes is quickly becoming a widespread network abuse problem landing directly on the abuse desks of network infrastructure providers.
Content note: This article discusses AI-generated non-consensual intimate imagery, extortion, and the harm it can have on adults and minors. While we recognize this is a sensitive topic, we also have a duty as a mission-driven network abuse prevention company to share findings from our threat data.
The names associated with sexploitation and named as the victims of deepfake porn are mostly those of musicians, actors, athletes, and politicians, with The Guardian reporting that nearly 4,000 celebrities were found to be victims of deepfake pornography.
Today, generating this type of content is easier than ever; it’s become as simple as downloading an app and uploading a photo.
But the apps generating this content don’t check who the subject is. Many carry a sign-up waiver asking users to confirm they’re over 18 and that any image they upload is of themselves, without any real verification behind the checkbox. In practice, one photo and a few minutes is enough to produce this kind of content, regardless of who the photo is of or whether they consented.
The gap between what the apps claim to check in their sign-up waivers (age, usage and consent) and what they actually verify doesn’t stay the app’s problem. Verification happens, if it happens at all, at the point of creation, which sits entirely outside any network. What ends up on the network is the distribution of the finished content, hosted, shared, and multiplying, with none of the oversight that was supposed to catch it in the first place. Network providers didn’t create this gap, but they have ended up inheriting it.
That’s why this doesn’t stay just a celebrity headline story. Every high-profile case reported is a working demonstration of what the same tool can do to someone who isn’t famous: a classmate, a former partner, or a colleague. The press covers the celebrity cases, making it the visible layer of this growing issue, but the pattern they inspire underneath is the larger problem, and it increasingly includes minors. And every one of those cases, celebrity or not, becomes the same operational reality for an ISP, hosting provider, or registrar: a report to act on, for content someone else’s product created and someone else’s lack of verification let through.
No network sees the whole picture on its own
This is a global, ongoing problem. The victims of this content are not limited to a single region, platform, or industry. Reports span entertainment, sport, politics, everyday people, and the victims aren’t only adults: student-generated content of classmates is now a recognized and growing issue at the school level. Explicit images and videos are being created wherever the generating tools are accessible, which is almost anywhere.
The fragmented reporting process and misaligned global standards mean that no single ISP, host, or registrar sees the whole picture. A site taken down under one registrar can resurface under another within days, and what looks like an isolated report from one network is often part of a much larger criminal campaign once you compare it with what other networks are seeing.
Abusix has been working on closing that gap. Our Abusix Threat Intel processes over 12 billion threat indicators daily, drawn from our own sensor and honeypot network plus live abuse reports flowing from the ISPs, telcos, and hosting providers we already work with. 96 % of that data doesn’t appear in any standard, open-source, or repurposed feed, and that is exactly the point. This problem moves across networks faster than any single team can track it alone, and the value is in seeing the pattern before it reaches you, not only reacting once it has.
With a great network comes great responsibility
There are very real consequences when network operators neglect to take the necessary action to protect against the distribution of illicit content, including:
- Extortion: “Pay, or we post this” or Sextortion attempts are regularly reported in the press, alongside smear campaigns timed to elections or public disputes, causing reputational harm to the victim and the network provider.
- Uneven harm: The harm falls hardest on women who face being disowned by their family or fired from their job (Women in International Security). Minors are particularly vulnerable to online abuse. In April 2026, the Internet Watch Foundation stated that reports of AI-generated child sexual abuse imagery soared by 154% in a year.
- Routine intake, unusual content: Illicit content reports arrive as an abuse report like any other. Someone finds a site, someone reports it, and it lands wherever your existing abuse infrastructure routes reports about hosted content, meaning it is sitting in the same queue as reports of a compromised server sending phishing emails, a hijacked virtual machine launching DDoS attacks, a hosting account distributing malware, or infrastructure being used to host scam landing pages.
How to flag and remove abusive content
Removing this content relies on people reporting it, and when the process is made simple, it works faster than most people expect. A site hosting non-consensual intimate imagery doesn’t need a court order to come down; it needs the registrar and host to act on a report reaching the right desk. Namecheap, for example, runs a dedicated notice-and-removal process for this category, separate from general abuse handling.
One recently reported site was taken down within 48 hours of reaching the right desk, showing that the process can be fast. However, the sites that come down are rapidly replaced by others distributing the same abusive content.
Legal consequences do exist, but approaches vary across jurisdictions. In the US, the Take It Down Act creates a statutory duty for platforms to remove this content once notified. The UK has its own criminal provisions covering non-consensual intimate imagery through amendments to the Crime and Policing Bill 2025. Other jurisdictions, including Australia, are still working on their own laws regarding the generation, distribution and removal of non-consensual intimate images. This disjointed approach means a report that gets fast action in one jurisdiction may move more slowly, or rest on a different legal basis, elsewhere, demonstrating the need for a global registry and reporting tool (The Global Reporting Project).
A recent case handled by the Manhattan District Attorney’s Office seized 12 prominent domain names tied to illicit web operations, specifically platforms selling AI-generated non-consensual deepfake pornography. Their investigation showed that registrars, hosts, and law enforcement acted on the same report from many different angles.
The challenge and responsibility of network infrastructure providers
For Internet Service Providers (ISPs), hosting providers, and registrars, the reporting process for intimate deepfake content is the same as any other hosted-content abuse report:
- Report to the registrar and hosting abuse desk together, since both can act independently and neither replaces the other.
- Involve law enforcement where a statutory duty applies, without assuming it applies everywhere a customer base sits.
- Keep a clear record of what was reported and when, since this category of report can resurface in a legal request later.
The bigger issue is that every registrar and host wants the report in a different format, and some won’t accept attachments at all. That means a team that does everything right above still has to reformat the same report by hand for every recipient, which is a large part of why takedowns that should take hours sometimes take days, or months. At volume, that’s not a one-off inconvenience. It’s a standing operational cost, and it competes for the same attention as every other category in the queue.
Where Abusix fits
Abusix Ops was built to close the gap by normalizing inbound abuse reports, in whatever format they arrive, and routing them by account rather than by individual ticket, so teams aren’t reformatting the same report by hand for every recipient. It doesn’t remove the judgment calls. It removes the manual reformatting that stands between a report arriving and someone being able to act on it.
The reporting-format fragmentation described above is also the specific problem our CEO, Tobias Knecht, is raising at the INHOPE Summit in Dublin this October, in a session on the standardized reporting formats, including XARF, that decide whether a report like this gets acted on at all.
What can you do to help?
To learn more about what to do if content like this lands on your desk, click here. If you have content to report, you can create an account and submit it via our web form.
If you’d like to learn more about The Global Reporting Project, the XARF reporting standard, or to talk through how your team currently handles reports like this, contact Abusix here.