October 28, 2025

Deepfake Sextortion: What to Do When Intimate Images Are Fabricated

Deepfake Sextortion: What to Do When Intimate Images Are Fabricated

Deepfake sextortion involves the use of fabricated or digitally manipulated intimate material to threaten, embarrass or coerce another person.

The offender may claim to possess a sexual image or video even though the victim never created or shared one. Public photographs, social-media videos or stolen account content can be altered using artificial-intelligence tools to produce material that appears genuine.

The image may be false, but the threat is real.

An offender may demand money, further intimate content, access to an account or another form of compliance. They may threaten to send the fabricated material to relatives, colleagues, employers, schools or social-media contacts.

What is deepfake sextortion?

A deepfake is synthetic or manipulated media designed to make it appear that a person said, did or experienced something that did not occur.

In a sextortion case, the material may include:

  • A fabricated nude or sexual image created from an ordinary photograph.
  • A manipulated video placing the victim’s face onto another person’s body.
  • Altered screenshots suggesting that an intimate conversation took place.
  • Synthetic audio designed to imitate the victim’s voice.
  • A false social-media profile distributing manipulated content.
  • Edited photographs presented alongside genuine personal information.

The risk is not limited to specialist deepfake software. Generative AI tools integrated into widely used online platforms may also be misused to create or distribute sexualised images. In January 2026, the European Commission opened formal proceedings concerning whether X had adequately assessed and mitigated risks associated with Grok, including the dissemination of manipulated sexually explicit images. The investigation did not determine that X had breached the law, but it illustrates the regulatory concern surrounding the accessibility and distribution of this material.

The offender may not need sophisticated equipment. Consumer software and online services can make image manipulation faster and more accessible than it was previously.

How may an offender obtain source material?

Deepfake sextortion often begins with material already available online.

Possible sources include:

  • Public social-media photographs.
  • Profile pictures.
  • Professional biographies and company websites.
  • Videos posted to social platforms.
  • Images taken from relatives’ or friends’ accounts.
  • Dating-profile photographs.
  • Stolen cloud-storage or email content.
  • Photographs submitted through a false casting, modelling or employment opportunity.

A clear image of the face may be sufficient for an offender to begin creating manipulated material.

Reducing public access to photographs may lower exposure, but it cannot guarantee that existing copies will disappear or prevent misuse.

Why fabricated material can still cause serious harm

Victims are sometimes told not to worry because the image is false.

That advice overlooks the speed at which manipulated content can circulate and the difficulty other people may have distinguishing genuine from fabricated material.

A deepfake threat may create:

  • Reputational pressure.
  • Fear of disclosure to family or colleagues.
  • Employment or professional concerns.
  • Safeguarding risks involving a child or young person.
  • Harassment or stalking.
  • Repeated financial demands.
  • Pressure to provide genuine intimate material.
  • Attempts to take control of an account or device.

The victim should not assume that simply denying the image is genuine will end the threat.

A structured response may need to address evidence, technical assessment, platform reporting, legal options and communication with affected third parties.

Can you tell whether an intimate image is a deepfake?

Some manipulated images contain visible inconsistencies, but visual inspection alone may not provide a reliable conclusion.

Possible indicators include:

  • Unnatural facial edges or skin texture.
  • Inconsistent lighting or shadows.
  • Unusual proportions or body positioning.
  • Distorted jewellery, clothing or background objects.
  • Differences between the face and the surrounding image quality.
  • Missing or inconsistent reflections.
  • Irregular movement in a video.
  • Audio that does not match mouth movements.
  • Metadata inconsistent with the claimed origin.

These signs may support further assessment, but their absence does not prove that material is genuine.

Metadata can be removed or altered. Images can also be compressed, copied between platforms or edited in ways that make technical interpretation more difficult.

Technical examination may help assess whether content has been manipulated, identify possible source material or document inconsistencies. It may not always provide a definitive conclusion.

What should you do after receiving a deepfake sextortion threat?

Preserve the evidence

Keep the communication before blocking or reporting the account.

Preserve:

  • Complete messages and emails.
  • Usernames, profile links and account names.
  • Telephone numbers and email addresses.
  • Copies of the threatened material where lawful and appropriate.
  • Payment demands and deadlines.
  • Bank details or cryptocurrency wallet addresses.
  • Voice notes and call records.
  • Screenshots showing intended recipients.
  • Links to published posts or websites.
  • Details of any payment already made.
  • A chronology of how the contact developed.

Where the material may depict someone under 18, do not download, copy or circulate the sexual image. Preserve the surrounding communications and account details, then seek police or safeguarding advice.

Preserve possible source images

Identify photographs or videos that may have been used to create the material.

Record:

  • Where the original content appeared.
  • When it was published.
  • Who could access it.
  • Whether it was later removed or altered.
  • Whether the image appeared on more than one account.
  • Whether an account may have been compromised.

Do not delete every source image immediately. Preserving the original may assist comparison and technical assessment.

Do not provide further material

An offender may claim that providing a genuine image, identity document or video will prove that the deepfake is false.

This may instead give the offender better source material.

Do not provide:

  • Additional photographs or videos.
  • Identity documents.
  • Passwords or security codes.
  • Remote access to a device.
  • Access to cloud storage.
  • Information about relatives, employers or colleagues.
  • Payment solely in return for a promise of deletion.

There is no reliable way to verify that an offender has deleted every copy.

Secure relevant accounts

Review the accounts from which source images or personal information may have been obtained.

Take proportionate steps to:

  1. Change compromised or reused passwords.
  2. Enable multi-factor authentication.
  3. Review active sessions and connected devices.
  4. Remove unfamiliar recovery details.
  5. Check email-forwarding rules.
  6. Review cloud-storage sharing permissions.
  7. Restrict access to contact lists and personal information.
  8. Preserve available login records.
  9. Review access held by former partners, employees or contractors.
  10. Seek cyber-security support where compromise is suspected.

The existence of a deepfake does not automatically prove that a device was hacked. The offender may have used publicly available material.

Should you pay a deepfake sextortion demand?

Payment does not guarantee that the material will be removed or that contact will stop.

The offender may retain the content, demand a larger amount or approach the victim again through another identity.

A payment can also demonstrate that the threat has created sufficient pressure to obtain money.

However, every case has different safety, legal and reputational considerations. Decisions about payment or continued communication should be made carefully and, where appropriate, with police, legal or specialist advice.

Keep all payment instructions even where no money is transferred.

Reporting and removal options

Where there is an immediate threat of violence, physical contact or danger to life, call 999.

Other cases may need to be reported through:

  • The police.
  • The platform hosting the account or content.
  • A website operator or hosting provider.
  • A school or safeguarding professional where a child is involved.
  • An employer’s legal or security team.
  • A solicitor.
  • The relevant bank or payment provider if money has been sent.

Reporting may result in an account or post being restricted or removed, but no adviser can guarantee that every copy will be located or permanently deleted.

Content may have been downloaded, reposted or stored on other services before removal.

The legal position in England and Wales

In England and Wales, sharing or threatening to share an intimate image without consent may constitute an offence under the Sexual Offences Act 2003, including where the image is fabricated or manipulated.

Separate offences covering the creation or requested creation of a purported intimate image of an adult without consent came into force on 6 February 2026.

The legislation defines a purported intimate image as one that appears to depict the person in an intimate state even though it is not, or is not solely, an authentic photograph or film of them.

The legal position will depend on the conduct, the victim’s age, how the image was created or shared and the purpose behind the threat.

Obtain advice from a solicitor where legal action, employment consequences or public allegations are involved.

How specialist support may assist

A structured response may include:

  • Reviewing the threat, demand and proposed disclosure targets.
  • Preserving and organising communications.
  • Comparing the manipulated material with possible source images.
  • Assessing whether accounts or devices may have been compromised.
  • Reviewing online aliases, profiles and public activity.
  • Supporting a controlled communication strategy.
  • Coordinating with solicitors and cyber-security specialists.
  • Preparing a chronology for police or legal advisers.
  • Monitoring for publication or further contact.

Private investigators cannot compel platforms, banks or telecommunications providers to disclose confidential subscriber information.

Technical examination may support an assessment of authenticity, but it cannot always establish exactly how the material was created or who created it.

For broader guidance on intimate-image threats, read What Is Sextortion and What Should You Do?.

Conflict International’s Blackmail and Extortion Resolution Services support individuals, families and organisations facing fabricated material, threatened disclosure and related financial demands.

Take the next step

The immediate priorities are:

  1. Preserving the threat and relevant source material.
  2. Avoiding further images, credentials or rushed payments.
  3. Securing affected accounts.
  4. Assessing whether the material may have been manipulated.
  5. Reporting urgent, criminal or safeguarding concerns.
  6. Considering legal and platform-removal options.
  7. Developing a proportionate response based on the evidence.

If you are facing a threat involving fabricated or manipulated intimate material, contact Conflict International in confidence to discuss the evidence, immediate risks and appropriate next steps.

Get a quote today!

Can we help you? Contact us in confidence. We are always happy to help and give you an indication of how we may be able to assist.

Please provide a summary of the situation. Why do you believe you are being targeted? Mention any specific events or data breaches that may have preceded the threat.

What does the perpetrator claim to possess? (e.g. Sensitive corporate data, private imagery/video, proprietary intellectual property, or confidential correspondence).

How was initial contact made, and which platforms are currently being used for demands? (e.g. WhatsApp, Telegram, LinkedIn, encrypted email, or social media). Please include any known usernames or handles used by the perpetrator.

What is the nature of the demand (financial, specific action, etc.)? Have any deadlines been set, or has any payment already been made?

Need our help?
Get a free consultation today.

Get started
© 2026 Conflict International · Privacy Policy · Cookie Policy · Website by ghostwhite