# DOJ Seizes Deepfake Pornography Sites in Historic First Enforcement Action Under TAKE IT DOWN Act


The U.S. Department of Justice has shut down CFAKE.com and SOCFAKE.com, marking the first major domain seizure under the newly enacted TAKE IT DOWN Act and signaling an aggressive new federal approach to nonconsensual deepfake imagery. The coordinated action, involving law enforcement from the United States, Italy, and France, removed websites that hosted thousands of AI-generated nude images of politicians, celebrities, athletes, and public figures without consent.


## The Threat


CFAKE and SOCFAKE operated as dedicated repositories for nonconsensual deepfake pornography, hosting sexually explicit AI-generated images depicting identifiable women including:


  • Political figures — national politicians and first ladies from multiple countries
  • Entertainment industry — actresses, musicians, television presenters
  • Sports figures — female athletes across multiple disciplines
  • Media personalities — journalists and television news anchors
  • Royalty — members of royal families from multiple nations

  • The sites functioned as straightforward platforms for harassment and abuse, allowing users to browse, download, and share fake explicit content depicting real women. There was no consent from subjects, no disclosure that images were artificial, and no mechanism for victims to request removal prior to this seizure action.


    ## Background and Context


    ### The TAKE IT DOWN Act


    The TAKE IT DOWN Act (Targeted Online Abuse Removal for Deepfake Non-Consensual Content Act), signed into law in May 2025, represents the first federal legislation specifically criminalizing nonconsensual intimate imagery and deepfake pornography. The bipartisan legislation was championed by First Lady Melania Trump as part of her "Be Best" initiative and establishes both criminal penalties and civil obligations:


    | Provision | Details |

    |-----------|---------|

    | Criminal Penalty | Federal crime to publish sexually explicit altered images of identifiable persons without consent |

    | Platform Requirements | Online platforms must remove reported intimate images and deepfakes within 48 hours of valid victim request |

    | Violations | Subject to fines, imprisonment, or both |


    Prior to this law, prosecutors lacked a direct federal statute targeting deepfake pornography, forcing them to rely on harassment, extortion, or defamation laws—a significant enforcement gap that the legislation closes.


    ### Investigation Timeline


    The international investigation unfolded over several months:


  • October 2025 — Italy's Postal and Cybersecurity Police received complaints about AI-generated sexually explicit images of Italian and international women, prompting inquiry
  • Early 2026 — Italian authorities obtained court orders blocking access within Italy while investigation continued
  • June 10, 2026 — French prosecutors arrested a suspect in Nice, France, following an investigation that led to seizure of cryptocurrency allegedly connected to site operations
  • June 12, 2026 — U.S. federal judge issued seizure warrants based on probable cause findings
  • June 13, 2026 — DOJ and Homeland Security Investigations (HSI) seized both domains; seizure notices now appear on both sites

  • ## Technical Details: How Deepfakes Work and Why They're Dangerous


    Deepfakes are synthetic media created using artificial intelligence—typically deep learning neural networks—to generate or manipulate images and videos depicting people saying, doing, or appearing in ways they never actually did. The creation process involves:


    1. Source material collection — Photos, videos, or audio recordings of the target individual

    2. Model training — AI systems trained on this source material to learn facial features, expressions, and voice patterns

    3. Synthesis — Generating new content (typically explicit in these cases) that realistically depicts the target person

    4. Distribution — Uploading to sites like CFAKE and SOCFAKE for public access


    The technology poses unique dangers because:


  • Realism — Modern deepfakes are difficult for untrained observers to distinguish from authentic media
  • Permanence — Once created, copies proliferate across the internet and are nearly impossible to fully remove
  • Non-technical barriers to creation — User-friendly tools now exist that require no machine learning expertise
  • Victim harm — Subjects face reputation damage, psychological trauma, harassment, and extortion regardless of consent or authenticity

  • ## International Cooperation and Enforcement Strategy


    The seizure of CFAKE and SOCFAKE represents a significant escalation in law enforcement's willingness to pursue deepfake operators across borders. The coordinated action involved:


  • Italy's Postal and Cybersecurity Police — Initial investigation and complaint intake
  • French National Police and Paris Prosecutor's Office — Secondary investigation leading to suspect arrest
  • U.S. Department of Homeland Security Investigations (HSI) — Domain seizure execution
  • DOJ Computer Crime and Intellectual Property Section — Federal prosecution coordination
  • U.S. Attorney's Office for the District of New Jersey — Local federal prosecution

  • This multi-nation coordination signals that law enforcement agencies are developing playbooks for international deepfake enforcement and may be building toward larger coordinated operations against other sites and platforms.


    ## Implications for Victims, Platforms, and Society


    ### For Victims


    Women depicted in nonconsensual deepfake imagery face concrete harms:


  • Harassment and targeting — Deepfakes are weaponized in coordinated harassment campaigns
  • Reputational damage — Images circulate on social media and messaging platforms, reaching personal and professional networks
  • Extortion — Criminals threaten to distribute images unless paid
  • Psychological trauma — Violation of privacy and bodily autonomy without consent
  • Career consequences — Professional opportunities may be damaged even after victims prove authenticity

  • The TAKE IT DOWN Act now gives victims a federal pathway for justice and platform accountability.


    ### For Online Platforms


    The 48-hour removal requirement places explicit legal liability on social media platforms, hosting providers, and search engines. Platforms must now:


  • Establish systems to receive and triage removal requests
  • Verify victim identity and consent claims
  • Remove or delist reported deepfakes within 48 hours or face penalties
  • Document compliance for legal defense

  • This differs sharply from the current patchwork of voluntary moderation policies and may require platforms to invest significantly in automation and human review.


    ### Broader Implications


    The seizure signals that the federal government will pursue deepfake operators both criminally (through prosecution) and civilly (through domain seizure), establishing enforcement precedent. Future targets may include:


  • Other dedicated deepfake pornography sites
  • Mainstream platforms that tolerate nonconsensual content in their terms of service
  • Tools and services that facilitate deepfake creation
  • Cryptocurrency wallets used to monetize deepfake distribution

  • ## Recommendations for Defenders and Organizations


    ### For Women in Public-Facing Roles


  • Monitor your digital footprint — Set up Google alerts for your name and image search alerts on major platforms
  • Document evidence — Screenshot and archive any deepfake content you discover, noting date, source, and platform
  • Report strategically — File reports with platforms (invoking TAKE IT DOWN Act), law enforcement, and the FBI's IC3 if extortion is involved
  • Seek legal counsel — Consult with attorneys experienced in image-based abuse and defamation

  • ### For Online Platforms


  • Implement automated detection — Deploy machine learning tools to identify deepfakes at scale
  • Create victim pathways — Establish clear, accessible processes for reporting and removal requests
  • Document compliance — Maintain detailed logs of removal requests and timelines for legal defense
  • Cooperate with law enforcement — Establish protocols for emergency requests and international investigations

  • ### For Organizations


  • Develop incident response plans — Prepare protocols for responding if executives or employees are targeted by deepfakes
  • Train staff on verification — Educate teams on identifying synthetic media and validating content authenticity
  • Update security policies — Address deepfakes in information security and brand protection strategies

  • ---


    ## HackWire Analysis


    This seizure matters because it establishes that federal law enforcement will actually enforce the TAKE IT DOWN Act—and do so aggressively and internationally. For nearly a year after the law passed, skeptics questioned whether the government had the technical capability and political will to pursue deepfake sites at scale. The CFAKE/SOCFAKE operation answers both questions affirmatively.


    The pattern here is worth noting: deepfake pornography follows the same enforcement trajectory as previous forms of online image abuse. When non-consensual intimate photos first exploded circa 2013-2014, law enforcement response was hesitant and fragmented. Within a decade, most states criminalized image-based abuse, major platforms implemented 24-48 hour removal policies, and the narrative shifted from "victims should just ignore it" to "platforms have legal obligations." Deepfakes are roughly 5-7 years behind that curve—which means we should expect rapid normalization of enforcement over the next few years.


    What other reporting is missing: the infrastructure angle. CFAKE and SOCFAKE weren't using Tor or bulletproof hosting. They registered domains through standard registrars, accepted cryptocurrency payments, and operated relatively openly. That suggests they weren't hidden from determined law enforcement—they were simply not prioritized until the TAKE IT DOWN Act created federal criminal liability. The lesson for defenders is that enforcement will accelerate fastest against the easiest targets (obvious sites, sloppy operational security), while sophisticated operators who use anonymous infrastructure may temporarily evade action. Organizations should assume that any site hosting nonconsensual content is now a law enforcement target and that victims have federal recourse.


    For defenders: if deepfake content depicting your organization's leadership or employees appears online, document it immediately and file concurrent reports with platforms and the FBI. Do not assume removal will be slow—the 48-hour rule is now federal law, and platforms violating it face liability.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)