FBI, French authorities seize deepfake CSAM-for-sale websites
FBI and French authorities seized two CSAM-for-sale sites and arrested a 25-year-old alleged administrator.
The FBI and French prosecutors shut down NudeLeaksTeens and NLTVIDS, sites that sold stolen and AI-generated child sexual abuse material. A 25-year-old French resident was arrested as the alleged primary administrator. Investigators say some material was taken from hacked Snapchat, TikTok, Instagram, and Facebook accounts, and one 189GB collection was priced at $64.90. The filings also cite the TAKE IT DOWN Act, which criminalizes nonconsensual intimate deepfakes.
- FBI seized NudeLeaksTeens and NLTVIDS domains through VeriSign
- French authorities arrested a 25-year-old alleged administrator
- Sites sold stolen and AI-generated CSAM, including a 189GB bundle
- Some material came from hacked Snapchat, TikTok, Instagram, and Facebook accounts
- Prosecutors cite the TAKE IT DOWN Act on nonconsensual deepfakes
Full article760 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Some of the material appeared to be recorded or stolen video of girls through interactions on social media sites like Snapchat, TikTok, Instagram and Facebook.
Listen to this article
0:00
Learn more.
The FBI and French authorities have arrested an individual and seized a pair of websites that were used to disseminate child sexual exploitation material, including AI generated deepfake media, according to court documents.
The websites, NudeLeaksTeens and NLTVIDS, were seized and shut down by the FBI this week. According to the Department of Justice, the cybercrime division of the French Paris Prosecutor’s Office has also arrested an unnamed 25-year-old French resident suspected of being the primary administrator for the sites.
According to a seizure warrant filed Oct. 2 in the Eastern District of Virginia by Arlington County police detective and FBI cybercrime task force member John Bamford, law enforcement first became aware of the websites in 2024, which advertised hacked, leaked and stolen CSAM of young girls.
FBI officials executed a search warrant on VeriSign, a Reston, Virginia-based U.S. domain registry that controls the seized website domains, taking servers, computers and other material.
Together the sites offered “a wide range of explicit content including CSAM and content that violates the TAKE IT DOWN Act, which prohibits the non-consensual sharing of intimate images,” Bamford wrote.
The TAKE IT DOWN Act, passed last year, makes it a crime to create or share nonconsensual “intimate” deepfake media of real people. The law also gives the Federal Trade Commission authority to enforce it and allows courts to order websites to remove such content.
The sites posted explicit disclaimers disavowing child pornography while simultaneously advertising and selling CSAM. At least one had its own form of currency used to buy images and videos individually or bundles organized by victim. One collection, containing 189GB of material on 315 different girls, sold for $64.90.
Some of the material came from victims’ social media accounts on Snapchat, TikTok, Instagram and Facebook, either recorded directly or stolen from their accounts. Several victims who appear on the site reported to law enforcement that their accounts were hacked.
Some of the advertised collections were compiled by individuals now serving prison sentences for their crimes. One individual, Andrew Venegas, pled guilty in a Texas federal court to sexual exploitation of children and receipt of CSAM as was sentenced to 30 years in prison in April 2026.
“In the investigation and prosecution of Venegas, law enforcement learned that Venegas obtained sexually explicit images and videos of his victims in various ways, including extortion and the unauthorized accessing of victim social media accounts,” wrote Bamford.
A separate collection available for sale on one of the sites in 2022 and 2023 was named after an individual, Reuben Oswaldo Yeverino Rosales, who was convicted and sentenced to more than 34 years in prison in 2022 for sexual exploitation of children and cyber stalking.
The websites put up disclaimers stating that they do not host or store any files or images on their servers, but rather link to “other non-affiliated sites” that do. Administrators would often encourage payments in cryptocurrency and urge individuals to reach out to them personally for some material, rather than posting them on the site.
Latest Podcasts
Government
Here’s how experts think CISA should tell agencies to protect OT
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
As AI world debates security, NVIDIA releases open source tools for agents
Technology
Threats
Policy
Wiretapping change sparks big privacy fight in the Golden State
Supreme Court permits states to use SAVE database for citizenship checks
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks