Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Online child abuse: grooming, sextortion and deepfakes

A new Polish guide addresses grooming, sextortion and AI-generated abuse. We add a technical model for account protection, evidence and response.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
30 July 2026
READING TIME
16 min read
TOPIC
Human Security
Online child abuse: grooming, sextortion and deepfakes

On 30 July 2026, CyberDefence24 covered a Polish guide titled “Opowiem Ci o moim świecie” (“Let me tell you about my world”), designed to help parents and carers prevent and respond to the sexual exploitation of children online. The guide was presented during a Polish Senate debate on norms, law and prevention.

Its central point is simple: the internet is not a separate “virtual world” for a child. Relationships, pressure, humiliation and coercion beginning in a messenger have real consequences. At the same time, fluency with an application does not mean an ability to recognise manipulation, adult intent or the long-term impact of sharing material.

What was published on 30 July

CyberDefence24’s article presents the PKDP guide and themes from the Senate debate. Risks include:

  • grooming and gradual trust-building;
  • manipulation and pressure;
  • sexting and sexual extortion;
  • privacy violations;
  • distribution of intimate material;
  • creation of abusive material with AI;
  • impersonation of a peer;
  • victim discovery through social media, games and chat.

Poland’s Supreme Audit Office has separately highlighted ineffective institutional cooperation, system-level reform needs, age assurance and a shift from parents as controllers to parents as digital guides.

This is not news of one new attack or a CVE. It is an updated Polish policy and education resource around a persistent threat.

Grooming rarely starts with sexual content

An offender may first present as a peer or supportive friend. Conversation focuses on games, school, music, appearance or family difficulties. The aim is to establish a special relationship, move communication into a less supervised channel and shift boundaries gradually.

A high-level process model includes:

  1. discovery through a public profile, game server or group;
  2. identity adaptation around the child’s interests;
  3. trust building through attention and apparent support;
  4. isolation from parents or peers;
  5. normalisation of secrecy;
  6. pressure for material, a meeting or behaviour;
  7. control through shame, threat or coercion.

Not every new friendship follows this pattern. The stronger signal is a combination of rapid exclusivity, secrecy, platform migration, pressure and threatened consequences.

Sextortion turns material into control

Sextortion threatens publication of genuine or fabricated material to demand more content, money or action. A file sent once can be saved, copied and reused after a relationship ends.

A child may fear punishment for creating an image and remain silent. The adult’s first response is critical: responsibility for coercion belongs to the offender, and safety—not judgment of the child’s earlier decision—is the priority.

Payment does not guarantee deletion and can confirm that pressure works. Abrupt blocking without preserving basic identifiers can also complicate reporting. Follow a prepared procedure rather than attempting retaliation or private investigation.

AI-generated material still causes harm

An offender does not need a genuine intimate image. A generative model can combine a face or public photograph with a fabricated scene. Technical falsity does not remove social and psychological pressure.

Authenticity assessment is difficult, and AI detectors are not conclusive. Compression, screenshots, cropping and filters change their result. Support should not depend on quickly proving whether material is synthetic.

Useful case data includes:

  • source account or URL;
  • publication time;
  • message or post identifier;
  • platform name;
  • contact chronology;
  • the original file where already lawfully preserved by an appropriate person;
  • reporting history and platform responses.

Do not copy the material into private messengers “for consultation” or circulate it among school staff. Every additional copy increases harm and legal risk.

Preserve evidence without duplicating abusive content

Evidence preservation does not require many copies. Start with:

  • profile name and unique identifier;
  • complete URL;
  • date, time and time zone;
  • threat text;
  • message identifiers;
  • payment or wallet information;
  • accounts the offender threatens to contact;
  • platform report number.

If a screenshot is necessary, capture identifying context while avoiding re-exposure of intimate content unless required by appropriate authorities. Do not wipe a device before consultation; disappearing messages, cache and logs can matter.

Content can be reported through the platform, appropriate authorities and Poland’s official Dyżurnet.pl reporting point operated within NASK. Direct danger or a planned physical meeting requires immediate involvement of the appropriate emergency authorities.

Protect the child’s account

A compromised account lets an offender impersonate the child, read conversations, coerce contacts and regain access through old sessions. Technical response should include:

  1. changing the password from a clean device;
  2. signing out every session;
  3. removing unknown recovery methods;
  4. enabling MFA or a passkey;
  5. checking OAuth-connected applications;
  6. reviewing email forwarding;
  7. checking linked devices;
  8. updating the OS and applications;
  9. reviewing password-manager security;
  10. monitoring repeated access attempts.

Passwords should not be shared with friends or partners. A parent should not store them in a note or message either. Family password-manager features or a secure recovery process are safer emergency-access mechanisms.

Privacy settings that reduce exposure

Review together:

  • who can send private messages;
  • visibility of the friend list;
  • addition to groups without approval;
  • phone and email visibility;
  • location sharing;
  • photo geotags;
  • automatic gallery synchronisation;
  • camera, microphone and contact permissions;
  • public archives of old posts;
  • profile-image downloads;
  • account lookup by phone number.

Public defaults give an impersonator more material. Reduced visibility does not eliminate risk but limits information available at the start.

A digital guide, not a secret administrator

Covert monitoring of every private conversation can push a child to another application and suppress reporting. Protection depends on a relationship in which a mistake can be disclosed without automatic loss of the device and trust.

Make rules explicit:

  • which applications need approval;
  • when an adult may inspect a device;
  • what to do after a threat;
  • how to verify someone met online;
  • why intimate material should not be sent;
  • who else the child can approach if they fear a parent’s reaction;
  • when platform or authority reporting is necessary.

Technical controls work best when the child understands their purpose and can independently recognise manipulation.

A minimum process for schools and organisations

A school, club or employer supporting families should not improvise after the first disclosure. The process should define:

  • one safe reporting route;
  • authorised people for child contact;
  • data minimisation;
  • prohibition on staff forwarding material;
  • privacy safeguards;
  • contact with carers and appropriate institutions;
  • school-account response;
  • decision documentation;
  • psychological and legal support.

Educational material must not use genuine abusive imagery. Training scenarios should rely on descriptions and safe examples.

Age assurance and privacy

The Polish audit recommendation includes age assurance. Its technical design must avoid creating a central database of children’s identity documents and service activity.

A safer approach should aim for:

  • proving “above the relevant threshold” instead of disclosing full birth date;
  • data minimisation;
  • short retention;
  • separation of verification provider from service-use history;
  • identity-theft resistance;
  • an accessible route for children without standard documents;
  • auditable deletion;
  • clear accountability.

Age assurance does not replace moderation, safe defaults and education. An offender may use an adult account or move the conversation elsewhere.

How platforms can design safer products

Safety cannot depend only on the child. Platforms can reduce risk through:

  • private-by-default minor accounts;
  • limits on messages from strangers;
  • detection of rapid off-platform migration pressure;
  • location-sharing warnings;
  • restrictions on bulk image downloads;
  • rapid restriction after credible reports;
  • evidence preservation for lawful processes;
  • detection of repeated sextortion campaigns;
  • safe review without unnecessary moderator exposure;
  • search-engine indexing control.

Automated detection produces errors. High-impact decisions need an appeal path and human review.

The first 24 hours

After grooming or coercion is disclosed:

  1. ensure safety and respond calmly;
  2. establish whether a meeting or immediate danger is planned;
  3. do not negotiate with or provoke the offender;
  4. preserve identifiers, threats and chronology;
  5. do not redistribute the material;
  6. report the account and content through appropriate routes;
  7. secure the account and revoke sessions;
  8. check other platforms and devices;
  9. warn people who may receive impersonation messages;
  10. provide sustained support beyond technical containment.

Where content appears in many locations, maintain a table of URLs, report dates, case references and outcomes. This shows which copies are removed and where escalation is needed.

What employers can do

This is not exclusively a private matter. An employee responding to a child’s extortion may be under severe pressure, use a corporate device for reporting or become a secondary social-engineering target. Employers should offer a discreet help path without requesting copies of the material.

Training can cover:

  • safe account containment;
  • impersonation and deepfake recognition;
  • reporting family incidents touching corporate devices;
  • protection of children’s data in HR, benefits and insurance;
  • non-shaming help-desk response;
  • ticket-system data minimisation.

Organisational cybersecurity training can be adapted for employees, parents, education and help desks. Our broader online child-safety guide provides foundational material.

Sources versus Breachroad conclusions

CyberDefence24 confirms the guide’s presentation, debate and identified threat forms. PKDP publishes the carer resource, while Poland’s Supreme Audit Office describes system-level weaknesses and recommendations. The sources do not describe one new incident or a technical product that guarantees safety.

Our evidence, account, platform and privacy-preserving age-assurance procedures are Breachroad security recommendations. They do not replace individual legal or psychological support or the work of appropriate authorities.

Trust is the central control: a child must be able to report a problem without expecting punishment as the first response. Technology reduces exposure but cannot replace relationships, education and a rehearsed process. Families and employees can build further foundations through the Breachroad Academy and our identity-theft protection guide. Organisations using models for moderation, classification or age assurance should combine child protection with a secure AI implementation process.

SHARE / COPY