iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Werner Enterprises Posts Highest Revenue Per Truck Growth in One-Way Segment in a Decade CMA CGM and Stonepeak Launch United Ports LLC in $2.4 Billion Terminal Joint Venture UPS shift away from Amazon shows bigger payoff Lanesurf: 62% of Loads Get Vetted Carrier Offers Before Brokers Arrive India-China Border Trade Via Lipulekh Resumes Aug 1; China Permits 20 Traders Geopolitics Drives CMA CGM Q2 Profit Surge of 42% as Volumes and Rates Climb Benchmark Diesel Price Rises Third Week as Futures Plunge; Spread Hits Record Indian Government Limits Sugar Dealers to 400 Tonnes Stock Until November to Curb Hoarding Tenants signing longer leases for larger warehouses as 3PLs lock in capacity US stock market flat as S&P 500 and Dow barely move, Nasdaq slides over 1% on chip rout Werner Enterprises Posts Highest Revenue Per Truck Growth in One-Way Segment in a Decade CMA CGM and Stonepeak Launch United Ports LLC in $2.4 Billion Terminal Joint Venture UPS shift away from Amazon shows bigger payoff Lanesurf: 62% of Loads Get Vetted Carrier Offers Before Brokers Arrive India-China Border Trade Via Lipulekh Resumes Aug 1; China Permits 20 Traders Geopolitics Drives CMA CGM Q2 Profit Surge of 42% as Volumes and Rates Climb Benchmark Diesel Price Rises Third Week as Futures Plunge; Spread Hits Record Indian Government Limits Sugar Dealers to 400 Tonnes Stock Until November to Curb Hoarding Tenants signing longer leases for larger warehouses as 3PLs lock in capacity US stock market flat as S&P 500 and Dow barely move, Nasdaq slides over 1% on chip rout
Home ›› Technology ›› Cybersecurity ›› OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear

OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear

A new UpGuard analysis reveals that DMCA takedown requests from adult content creators, including OnlyFans models, have accidentally removed over 130,000 URLs from compromised government and university websites. The requests target hacked pages that hosted leaked adult content, but by removing them from search results, creators are inadvertently taking down insecure sites.

iG
iGEN Editorial
July 8, 2026
OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear

Adult content creator Laura Lux has been publishing pictures of herself online for almost two decades, primarily on OnlyFans. She says people have always tried to steal her content and "leak" it online—"It's an endless battle," she says. However, as the adult creator economy has boomed, individual OnlyFans models and other adult creators have joined the fight against pirated content by filing millions of DMCA takedown requests. But these requests have collided with one of the internet's long-standing problems: insecure government and university websites.

The Scale of the Problem

According to a new analysis from cybersecurity company UpGuard, shared with WIRED, more than 2,000 domains belonging to governments and education institutions, across 80 countries, have received copyright takedown requests linked to adult content creators over the past 15 years. The research indicates these sites may have been compromised, with many repeatedly hijacked in a "dramatic" increase since 2020, specifically related to individual adult creators and their "leaked" OnlyFans content.

For years, scammers have hijacked authoritative .gov and .edu domains—which often appear high in Google search results—to upload malicious pages and PDFs promising free movie downloads, iPhones, porn, and Fortnite skins. These pages then link to scams or malware. Increasingly, fraudsters have used names of adult content creators to draw victims to compromised pages.

How DMCA Requests Inadvertently Help

"The OnlyFans models are not setting out to help government websites, but in order for them to police their copyright ownership, they wind up sending a lot of notices to Google about those sites," says Greg Pollock, director of research at UpGuard. "In some ways, because of the way the attack works, having Google remove the search result is extremely effective, because there's no real visibility of the asset outside of Google."

"If you are not running a DMCA service, then you might as well probably not even be bothering doing the job, because it will be everywhere." — Laura Lux

Pollock's analysis documents 384,286 takedown requests covering 631,193 URLs from adult content creators to government and education websites since 2011, with the vast majority sent in the past few years. Of these, Google appears to have removed around 130,000 URLs.

Recent Examples

Some recent copyright takedown requests seen by WIRED include government and university websites in Bangladesh, Colombia, India, Nigeria, the United States, and Peru. The infected pages are common: search results show .gov and .edu domains with pages titled "biggest leak yet" and "leaked OnlyFans" videos alongside names of adult content creators with millions of followers.

If clicked, the URLs do not show leaked pictures or videos and often redirect visitors to scammy URLs that advertise online dating and other suspicious pages—potentially earning fraudsters money through complex advertising schemes. To upload the malicious content, scammers may exploit weaknesses or vulnerabilities in the publishing systems of websites.

Summary of UpGuard's Findings

Metric Value
Affected domains >2,000
Countries affected 80
Total takedown requests (since 2011) 384,286
URLs targeted 631,193
URLs removed by Google ~130,000
Time period covered 15 years (since 2011)

Implications for Cybersecurity

This phenomenon highlights a unique intersection of copyright enforcement and cybersecurity. While the DMCA is not a security tool, its use by content creators has inadvertently exposed the vulnerability of government and educational websites. For enterprise technology decision-makers, the lesson is clear: any public-facing domain, especially high-authority .gov and .edu sites, can be weaponized by attackers. The only reason these compromised pages were discovered is because adult content creators filed takedown requests; many other exploited sites may go unnoticed. The takedown process itself removes only the search listing, not the underlying vulnerability, meaning the sites remain compromised and could be used again.

For CTOs and procurement leaders managing supply chain or logistics portals, this case underscores the importance of regularly auditing third-party plugins, content management systems, and domain configurations. While the example involves adult content, the same technique could be used to host phishing pages or distribute malware targeting logistics partners. The proactive monitoring of search indexes for unauthorized pages can serve as an early warning system for compromised infrastructure.


Sources:

Keep Reading

Recommended Stories

Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed Technology

Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed

Novo Nordisk, the maker of Ozempic and Wegovy, confirmed a cyberattack that breached pseudonymized clinical trial data, including patient IDs, biomarkers, and lifestyle factors. The company stated no personally identifiable information (PII) was exposed and core operations remain unaffected. Third-party cybersecurity experts are investigating.

June 15, 2026
How a Stealthy Worm Exploits AI Toolchains to Steal Credentials and Destroy Systems Technology

How a Stealthy Worm Exploits AI Toolchains to Steal Credentials and Destroy Systems

New research from Crowdstrike reveals a worm that targets AI software supply chains, stealing access tokens and deploying destructive capabilities. The malware exploits blind spots in AI coding environments, where its behavior mimics legitimate automation, making detection extremely difficult.

July 21, 2026
Hidden Car Alarm Device in Millions of US Vehicles Is a Hacking Risk – Patch Now Technology

Hidden Car Alarm Device in Millions of US Vehicles Is a Hacking Risk – Patch Now

UC San Diego researchers discovered a severe Bluetooth vulnerability in the KARR Security System aftermarket car alarm, installed by dealers in over 2 million vehicles across the US. The flaw allows attackers to unlock, track, or disable ignition from Bluetooth range. Acrisure Protection Group has released a firmware patch; owners must manually update via the KARR app.

July 21, 2026
Cyberattack on Refrigerated Warehouse Disrupts Glico, KFC Japan, and Sushi Deliveries Technology

Cyberattack on Refrigerated Warehouse Disrupts Glico, KFC Japan, and Sushi Deliveries

A cyberattack on Japan's largest refrigerated warehouse operator, Nichirei, has disrupted supplies for Ezaki Glico, KFC Japan, and Kura Sushi. The incident highlights critical vulnerabilities in food supply chain technology and logistics networks.

July 16, 2026