LIVE · cybersecurity feed
Live wire
copyright infringementmedium

OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear

Adult content creators are inadvertently causing hacked government and university websites to disappear from search results. This occurs when creators issue copyright takedown requests, often under the Digital Millennium Copyright Act (DMCA), to remove pirated content from search engines. Scammers have been exploiting insecure government and educational domains to host malicious pages, using the names of adult creators to lure victims. Consequently, DMCA requests aimed at protecting creators' content are leading to the removal of these compromised, but legitimate, government and educational web pages from search results.

zeroday.news · 24d ago

Adult content creators, primarily those on platforms like OnlyFans, are unintentionally contributing to the removal of compromised government and university websites from search engine results. This phenomenon arises from the creators' efforts to combat the widespread piracy of their content.

These creators frequently utilize copyright laws, such as the Digital Millennium Copyright Act (DMCA), to issue takedown requests for pages that host their stolen images and videos. This process involves notifying search engines like Google to remove links to infringing material from search results.

However, a recent analysis by cybersecurity firm UpGuard has revealed that over the past 15 years, more than 2,000 domains belonging to governments and educational institutions across 80 countries have been subjected to copyright takedown requests linked to adult content. This suggests that these official websites have been compromised.

Scammers have been exploiting the authoritative nature of .gov and .edu domains, which often rank highly in search results. They upload malicious pages and PDFs to these compromised sites, using enticing titles related to free downloads or leaked content, often mentioning popular adult creators.

The primary goal of these scams is to redirect unsuspecting users to fraudulent websites that advertise online dating services or other suspicious content, thereby generating revenue through advertising schemes.

Greg Pollock, director of research at UpGuard, explained that while creators are not intentionally aiding government websites, their copyright enforcement actions have this unintended consequence. By requesting the removal of search results, they effectively make these compromised government and educational pages invisible, even if the underlying compromise remains.

Since 2011, UpGuard's analysis indicates that adult content creators have sent approximately 384,286 takedown requests, covering over 631,000 URLs, targeting government and education websites. The majority of these requests have been made in recent years.

Google has reportedly removed around 130,000 of these URLs in response to the takedown notices. The research highlights a significant increase in such hijackings since 2020, coinciding with the boom in the adult creator economy.

copyright infringementdmcawebsite securitycybercrimecontent piracy
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.