LIVE · cybersecurity feed
Live wire
deepfakehigh

AI Deepfakes Used to Impersonate OnlyFans Creators in New Scam

Scammers are leveraging AI-generated deepfakes to impersonate OnlyFans creators, tricking fans into sending money through platforms like Cash App. This scam not only defrauds fans but also harms creators, who face accusations from angry followers and even threats. While legal measures are being introduced, the global nature of hosting and enforcement challenges hinder effective control.

zeroday.news ·

Scammers are employing AI-generated deepfakes to impersonate OnlyFans creators, tricking fans into sending money through peer-to-peer payment platforms before disappearing. This scheme, which leverages various social media platforms, has resulted in financial losses for fans and significant distress for the creators whose identities are being stolen.

The fraud begins on platforms like TikTok, where attackers create fake accounts using photos and videos of legitimate OnlyFans creators. These accounts often feature synthetic voices to animate still images, making them appear more convincing. Viewers are then encouraged to move to direct messaging services such as Snapchat for private conversations, often under the pretense of offering exclusive content or live chats.

Once a rapport is established, the scammers request payment via Cash App, a peer-to-peer platform designed for informal transfers. The choice of Cash App is strategic, as transfers are instant and largely irreversible, making it difficult for victims to reclaim their funds once sent. After receiving payment, the scammer blocks the victim and deletes the fake account.

This type of "catfishing" has a dual impact. Fans lose money, while the real creators suffer reputational damage and potential loss of income. Some creators, like Jessieanna Campbell, have reported receiving angry messages from fans accusing them of fraud for transactions they never initiated. In more extreme cases, one creator described fans showing up at her home, leading to concerns for her personal safety.

Identifying these deepfakes can be challenging, but experts note common artifacts. For example, a TikTok video impersonating creator Elaina St. James, which animated a still photo with a cloned voice, reportedly showed distorted teeth and frozen eyebrows. These inconsistencies are often indicators of AI-generated video, particularly when the source material is limited. Malwarebytes has published a guide to help users spot deepfakes.

The issue is compounded by the international nature of the internet. While laws like the U.S. Take It Down Act criminalize non-consensual explicit content, including AI-generated material, and the EU’s AI Act requires disclosure of AI-generated images, enforcement is difficult across national borders, especially when content is hosted overseas. Research from the University of Bristol indicates that many participants continued to trust deepfake content even after being informed of its artificial nature.

This scam mirrors patterns seen in other online frauds, such as romance scams and impersonation scams involving major brands like Amazon and Apple. The underlying manipulation remains consistent: establish familiarity, create a sense of urgency, and then request payment through an irreversible channel.

To avoid falling victim, users are advised to be wary if a creator contacts them through a third-party platform and attempts to steer the conversation toward direct payment for exclusive content. It is crucial to verify any such requests through the creator's official, verified accounts before making any payments. Any request for Cash App payment from someone claiming to be a creator, particularly before any content is delivered, should be treated as a significant red flag.

deepfakeaiscamonlyfansimpersonation
ShareXLinkedInWhatsAppFacebook

More News

view all →
surveillance

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

Flock Safety, a company known for its public safety cameras, reportedly pitched a plan to utilize dashcams from rideshare and delivery vehicles to collect license plate data. This initiative, which did not proceed, would have involved a partnership with Nexar, a dashcam manufacturer, and potentially involved drivers without their knowledge. Separately, a former Flock employee alleged the company provided direct camera access to ICE and CBP through a pilot program, contradicting internal statements.

email securityhigh

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Security researchers Cory Solovewicz and Mike Sheward have inadvertently created honeypots by purchasing domains like noreply.us and deleteduser.com. Organizations are mistakenly sending sensitive data, including personal information, company secrets, and system credentials, to these domains, believing they are unmonitored. Both researchers are now working to notify affected entities and raise awareness about this widespread misconfiguration, highlighting the potential for malicious actors to exploit such vulnerabilities.

atlassianhigh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Two security firms have identified vulnerabilities in Atlassian's Rovo assistant that could allow attackers to exfiltrate data from Jira and Confluence. One vulnerability, dubbed RovoBlast by Varonis Threat Labs, allowed attackers to trick Rovo into sending data to an external server via a malicious link. Atlassian has confirmed this issue is fixed server-side. The second vulnerability, found by PromptArmor, involved injecting malicious instructions into content Rovo processes, enabling data exfiltration without explicit user approval. The status of this second vulnerability remains unconfirmed after its initial disclosure.

breach

Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered […]

malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

ai

OpenAI pledges to add Astra security as Anthropic loosens Fable's leash

Or how I learned to stop worrying and love dangerous AI