Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

An intimate image or deepfake was shared without consent. What to do next

You do not have to handle this alone. Learn how to preserve evidence, report the content and use StopNCII or Take It Down without sending the image.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
12 September 2026
READING TIME
10 min read
TOPIC
Human Security
An intimate image or deepfake was shared without consent. What to do next

Someone has posted an intimate image of you without consent. Perhaps it was once sent privately, stolen, or never genuine at all — somebody created a deepfake using your face. The first reaction may be shame, panic or a need to answer every person who has seen it immediately.

This is not your fault. Personal safety, support from another person and a few ordered actions matter most. You do not have to fix the whole internet in one hour.

Look after yourself first and do not negotiate alone

If the post comes with threats, blackmail or a demand for money, do not pay or send more material. Payment does not give you control of copies and can produce further demands. Do not meet the perpetrator or take a risk to seize their device.

Tell somebody you trust what happened. They can help file reports, record addresses and contact police while you take a break. If you face immediate danger, contacting emergency services and reaching a safe place takes priority.

Do not blame the person depicted — even if they once took or sent the photograph themselves. Consent to private sharing is not consent to publication.

Preserve evidence without expanding its reach

Record the page address, account name, date, time, threats and post identifier. Take screenshots that preserve context, but do not circulate them to relatives or colleagues “for confirmation”. Fewer new copies make harm easier to contain.

If the material depicts someone who was under 18 when it was taken, do not download, forward or ask somebody for a copy merely to report it. Take It Down explicitly instructs people to use only a file already present on the affected person’s device.

For a deepfake, also record evidence showing the fabrication: the originating account, caption, comments and, where possible, the first known post. You do not have to prove how the image was generated before reporting a policy violation.

Report the content directly to the platform

Use the menu beside the image, video or post and select the category for nudity, non-consensual intimate content, harassment or impersonation. If the in-post form does not fit, visit the platform’s help centre and find its dedicated non-consensual intimate image process.

Supply the exact URL and state plainly that the content depicts you and was shared without consent or digitally fabricated. Keep the case number and confirmation message. After the first copy is removed, search for the account name and a distinctive part of the caption to locate duplicates — without opening unknown files.

The FTC says platforms covered by the US TAKE IT DOWN Act must provide a reporting mechanism and remove intimate content and copies within 48 hours of a valid request. This includes deepfakes. It is a US legal deadline for covered services, not a universal guarantee for every site in Poland. When a covered platform fails to act, the FTC provides a reporting route at TakeItDown.ftc.gov.

StopNCII for material depicting adults

StopNCII.org is a free global tool for people who are currently at least 18 and were adults when the content was created. You must still possess the image or video on your device and be the person depicted.

The tool creates a hash, or digital fingerprint, directly on the device. StopNCII and participating platforms receive the hash, not the image itself. Platforms look for matching copies and may block or remove them under their policies.

There is an important limit: a hash helps find the same copy on participating platforms. It does not remove content from the whole internet and may not recognise a heavily altered version. Keep the case number and PIN because the service says lost access details cannot be recovered.

Take It Down for images created before age 18

Take It Down supports nude, partially nude or sexually explicit images and videos taken when the depicted person was under 18, regardless of their current age. NCMEC’s service is free and can be used anonymously.

Like StopNCII, it creates a hash on the device; the file is not uploaded and nobody has to view it. The hash joins a secure list used by participating public or unencrypted platforms.

Do not download the content from the internet to use the tool. If you no longer have it on your device, report it directly to the platform and use available support channels. In Poland, online content depicting child sexual abuse can be reported to Dyżurnet.pl, NASK’s reporting team.

Secure accounts and cut off the source

If the image may have come from email, cloud storage or a phone, change that account’s password through the official app or site, end other sessions and enable MFA. Review signed-in devices, shared albums, old folder links and applications with access to photographs.

Changing a password does not remove published content, but it may stop additional files from being taken. Avoid resetting a device before preserving relevant information when intrusion is suspected and analysis may be needed.

If the perpetrator knows a password reused elsewhere, replace it across services, beginning with email and the password manager. Do not follow a link to an “image removal panel” sent by an unknown person — it may be another attempt to steal the account.

When the material reaches work or school

Choose one point of contact: a manager, HR representative, counsellor or security lead. Explain that the content was shared without consent or is fabricated, and that reports are in progress. Ask them not to copy it into internal tickets; the URL, identifier and tightly controlled evidence are enough.

The organisation should protect the affected person, limit circulation and respond to harassment. Do not stage a public debate over whether the image is genuine. With a deepfake, the argument itself can amplify the harmful material.

What the sources say and what Breachroad recommends

On 10 September 2026, the US Federal Trade Commission explained how to report intimate images and deepfakes shared without consent. Its alert supports the information about covered platforms and the 48-hour deadline under US law. The official StopNCII and Take It Down sites describe hashing, eligibility and the participating-platform limitation. A NASK guide provides Polish context for support and reporting content to site administrators.

Breachroad recommends treating this as three separate objectives: preserve the minimum evidence, stop distribution and secure the source accounts. We do not promise complete removal from the internet — none of these tools provides that guarantee.

When a child or blackmail is involved, our guide to online abuse, grooming, sextortion and deepfakes offers further context. We help organisations build safe, non-blaming reporting procedures through cybersecurity training.

SHARE / COPY