Adult content creator Laura Lux has been publishing pictures of herself online for almost two decades, primarily on OnlyFans. She says people have always tried to steal her content and "leak" it online—"It's an endless battle," she says. However, as the adult creator economy has boomed, individual OnlyFans models and other adult creators have joined the fight against pirated content by filing millions of DMCA takedown requests. But these requests have collided with one of the internet's long-standing problems: insecure government and university websites.
The Scale of the Problem
According to a new analysis from cybersecurity company UpGuard, shared with WIRED, more than 2,000 domains belonging to governments and education institutions, across 80 countries, have received copyright takedown requests linked to adult content creators over the past 15 years. The research indicates these sites may have been compromised, with many repeatedly hijacked in a "dramatic" increase since 2020, specifically related to individual adult creators and their "leaked" OnlyFans content.
For years, scammers have hijacked authoritative .gov and .edu domains—which often appear high in Google search results—to upload malicious pages and PDFs promising free movie downloads, iPhones, porn, and Fortnite skins. These pages then link to scams or malware. Increasingly, fraudsters have used names of adult content creators to draw victims to compromised pages.
How DMCA Requests Inadvertently Help
"The OnlyFans models are not setting out to help government websites, but in order for them to police their copyright ownership, they wind up sending a lot of notices to Google about those sites," says Greg Pollock, director of research at UpGuard. "In some ways, because of the way the attack works, having Google remove the search result is extremely effective, because there's no real visibility of the asset outside of Google."
"If you are not running a DMCA service, then you might as well probably not even be bothering doing the job, because it will be everywhere." — Laura Lux
Pollock's analysis documents 384,286 takedown requests covering 631,193 URLs from adult content creators to government and education websites since 2011, with the vast majority sent in the past few years. Of these, Google appears to have removed around 130,000 URLs.
Recent Examples
Some recent copyright takedown requests seen by WIRED include government and university websites in Bangladesh, Colombia, India, Nigeria, the United States, and Peru. The infected pages are common: search results show .gov and .edu domains with pages titled "biggest leak yet" and "leaked OnlyFans" videos alongside names of adult content creators with millions of followers.
If clicked, the URLs do not show leaked pictures or videos and often redirect visitors to scammy URLs that advertise online dating and other suspicious pages—potentially earning fraudsters money through complex advertising schemes. To upload the malicious content, scammers may exploit weaknesses or vulnerabilities in the publishing systems of websites.
Summary of UpGuard's Findings
| Metric | Value |
|---|---|
| Affected domains | >2,000 |
| Countries affected | 80 |
| Total takedown requests (since 2011) | 384,286 |
| URLs targeted | 631,193 |
| URLs removed by Google | ~130,000 |
| Time period covered | 15 years (since 2011) |
Implications for Cybersecurity
This phenomenon highlights a unique intersection of copyright enforcement and cybersecurity. While the DMCA is not a security tool, its use by content creators has inadvertently exposed the vulnerability of government and educational websites. For enterprise technology decision-makers, the lesson is clear: any public-facing domain, especially high-authority .gov and .edu sites, can be weaponized by attackers. The only reason these compromised pages were discovered is because adult content creators filed takedown requests; many other exploited sites may go unnoticed. The takedown process itself removes only the search listing, not the underlying vulnerability, meaning the sites remain compromised and could be used again.
For CTOs and procurement leaders managing supply chain or logistics portals, this case underscores the importance of regularly auditing third-party plugins, content management systems, and domain configurations. While the example involves adult content, the same technique could be used to host phishing pages or distribute malware targeting logistics partners. The proactive monitoring of search indexes for unauthorized pages can serve as an early warning system for compromised infrastructure.