Full Report
An analysis of 160 deepfake websites reveals politicians in 22 countries appear on them. Nearly all of them are women.
Analysis Summary
# Incident Report: Global Non-Consensual AI Exploitation of Political Figures
## Executive Summary
A large-scale analysis has identified 160 deepfake websites hosting sexually explicit, AI-generated content featuring over 100 politicians across 22 countries. The incident highlights a systemic weaponization of generative AI targeting public figures, with an overwhelming majority of victims being women. The impact involves significant reputational harm and the potential for political destabilization through gender-based disinformation.
## Incident Details
- **Discovery Date:** September 14, 2026 (Public Reporting)
- **Incident Date:** Ongoing; accelerated with the proliferation of Generative AI
- **Affected Organization:** Multiple governmental bodies and political parties
- **Sector:** Government / Public Sector
- **Geography:** Global (22 countries identified, primarily in Europe)
## Timeline of Events
### Initial Access
- **Date/Time:** Undetermined; continuous scraping of public media.
- **Vector:** Open-source intelligence (OSINT) and public media harvesting.
- **Details:** Attackers gathered high-resolution images and videos of female politicians from official government websites, social media, and news broadcasts.
### Lateral Movement
- **Details:** Not applicable in a traditional network sense. The "movement" involves the cross-platform distribution of generated content from specialized deepfake forums to mainstream social media and 160 identified niche websites.
### Data Exfiltration/Impact
- **Impact:** Unauthorized synthesis of likeness. The "exfiltration" in this context is the misappropriation of a person's biometric identity to create non-consensual deepfake pornography (NCII - Non-Consensual Intimate Imagery).
### Detection & Response
- **How it was discovered:** Investigative journalism and analysis of 160 deepfake-specific domains.
- **Response actions taken:** Ad-hoc removals (e.g., Apple removing related apps from the App Store), public exposure by media outlets, and legislative discussions regarding AI regulation.
## Attack Methodology
- **Initial Access:** Collection of publicly available facial imagery.
- **Persistence:** Content is hosted on decentralized or offshore "deepfake" hosting providers to avoid takedowns.
- **Discovery:** Identifying high-profile targets through political prominence.
- **Collection:** Automated scraping of image databases.
- **Impact:** Reputational destruction, harassment, and psychological warfare.
## Impact Assessment
- **Financial:** Difficult to quantify; however, the deepfake industry generates revenue through subscription models and advertising on these 160 sites.
- **Data Breach:** Compromise of personal likeness and biometric integrity for >100 individuals.
- **Operational:** Potential interference with democratic processes and the discouragement of women from seeking public office.
- **Reputational:** High; weaponized disinformation designed to discredit officials.
## Indicators of Compromise
- **Network Indicators:** 160 identified domains (e.g., [hxxps]://deepfake-porn-site[.]com - *generic example*).
- **Behavioral Indicators:** Sudden influx of suspicious, high-quality intimate imagery of public figures appearing on fringe forums and social media.
## Response Actions
- **Containment:** Reporting content to hosting providers and search engines for de-indexing.
- **Eradication:** Platform-level bans on AI-generated non-consensual imagery.
- **Recovery:** Public statements from affected officials to clarify the fraudulent nature of the media.
## Lessons Learned
- **AI Accessibility:** The barrier to entry for creating high-quality, damaging deepfakes has reached a point where any public figure is at risk.
- **Gendered Targeting:** There is a clear, disproportionate focus on female politicians, indicating that deepfakes are being used as a tool for gender-based political harassment.
- **Regulatory Lag:** Existing laws are struggling to keep pace with the speed of AI generation and the infrastructure of the sites hosting this content.
## Recommendations
- **Legislative Action:** Implement federal and international laws specifically criminalizing the creation and distribution of non-consensual AI-generated intimate imagery.
- **Watermarking:** Encourage or mandate the use of digital signatures and C2PA standards for official government media to verify authenticity.
- **Platform Accountability:** Hold hosting providers and app stores accountable for the distribution of tools and content designed for non-consensual exploitation.