Copyright Battles Collide With Hacked Official Websites
Scammers are hijacking government and university websites to host deceptive ads for ‘leaked’ OnlyFans content, but copyright takedowns filed by adult creators are inadvertently helping to remove these malicious pages from Google search results. The unintended consequence reveals a complex intersection of digital piracy, cybersecurity, and intellectual property enforcement.
Data Reveals Scale of the Phenomenon
New research from cybersecurity firm UpGuard, shared exclusively with WIRED, reveals that more than 2,000 domains belonging to governments and educational institutions across 80 countries have received copyright takedown requests linked to adult content creators over the past 15 years. The report indicates these sites may have been compromised. Since 2020, there has been a ‘dramatic’ increase in hijackings related to individual adult creators and their ‘leaked’ OnlyFans content.
How the Scam Works
Fraudsters exploit vulnerabilities in official .gov and .edu domains—which rank high in Google search results—to upload malicious pages and PDFs offering free movies, iPhones, porn, and Fortnite skins. Increasingly, they use the names of popular OnlyFans models as bait. When users search for leaked content, they find pages with titles like ‘biggest leak yet’ and ‘leaked OnlyFans videos.’ Clicking these leads to scammy URLs advertising online dating or other suspicious pages, generating revenue for scammers.
Number of Takedown Requests
According to UpGuard director of research Greg Pollock, there have been 384,286 takedown requests covering 631,193 URLs from adult content creators targeting government and education websites since 2011. The vast majority have been filed in the past few years. Of these, Google has removed approximately 130,000 URLs, while no action was taken against 460,000. The analysis used Google’s Lumen Database and Harvard University’s DMCA archive to cross-reference requests from companies representing adult creators.
Impacts and Criticism
Adult creator Laura Lux, who has been publishing photos online for nearly two decades, uses DMCA services like Rulta to fight piracy. She says it’s ‘an endless battle’ that costs creators significant revenue. However, using copyright law against hacked official websites has drawn criticism. Dan Purcell, CEO of content removal firm Cequens, calls it ‘excessive and inappropriate’ and notes that copyright is the wrong tool for cleaning up compromised sites. Jennifer Urban, a clinical professor of law at UC Berkeley, points out that DMCA notices filed outside of legitimate copyright claims are questionable under the law.
Rulta’s Role
Estonia-based company Rulta has made approximately 90% of the recent requests, according to UpGuard. However, 11,000 adult-content-linked copyright owners represented by 554 organizations have filed requests against government and education sites. Fanlock cofounder Alexander Small says his firm only files requests when they have a good-faith belief that the page actually hosts copyrighted content, not just uses a name as bait.
Silver Lining for Security
Despite the controversy, Pollock notes that monitoring for adult creator names on official domains could serve as an early warning for small security teams that their infrastructure has been compromised. ‘When that unwanted content is injected, you can often catch it with these kinds of adult content keywords,’ he says. Laura Lux, whose name has been used on domains in Vietnam, South Africa, Bangladesh, Somalia, and Brazil, says she isn’t shocked by her brand’s misuse and wryly comments, ‘I guess sex workers save the world again.’