...
AI used to create abuse images
Georgia never clicked anything. No phishing link. No malware. No sketchy download, no reused password, no suspicious login. She did not make a single security mistake. She simply posted photos similar to those we all share on social media.

That’s why Georgia Horton was horrified to learn that dozens of photographs of her had been posted to an illicit forum where pornography was shared. Many of the images had been run through AI to make them pornographic. They were allegedly posted by Ethan Orchard, an old college friend she’d describe as “the most non-confrontational person you would ever meet.”

A few weeks ago, Orchard was jailed after he admitted to three counts of sharing intimate images. He was also handed a ten-year Sexual Harm Prevention Order and an indefinite restraining order. Two other women he knew from college were targeted alongside Georgia.

Your photo isn’t just a photo anymore

AI selfie photo dangers

We spend a lot of energy teaching people to spot the AI deepfake, including the glitchy mouth, the weird lighting, and a voice that’s a half-second off. That’s useful, and you should keep watching out for these things, but it assumes that you become a victim by being fooled. In Georgia’s case, some of the images posted to that forum had not been altered at all. They were her real photos of her everyday life. What made them weapons was the caption underneath and the audience they were served to.

So good security detection was never going to save Georgia. There was nothing for her to detect. By the time anyone spotted the AI deepfake of her, the fake had already been made, posted, and commented on by strangers.

For years, our advice has focused on guarding the obvious valuables targeted by scammers and attackers, such as passwords, your Social Security number, bank logins, and anything with a dollar figure attached. Vacation pictures and selfies were treated as fairly harmless, but generative AI has erased that line, and most people haven’t even thought about it. One clear picture of you is enough to make it look like you were at a place you never visited, with people you’ve never met, or in a situation you were never actually in.

We’ve said it here before about the viral AI caricature trend, you’re not just posting a cute picture, but a profile of your life that gives information unnecessarily to scammers and those with bad intentions. Your social media feed is full of information for them, including your job, your kids’ names, your gym, your dog, your favorite team. Individually this information is harmless, but assembled, it’s the raw material for social engineering that sounds like it’s coming from someone who knows you.

It’s not just your picture. Modern tools can build a workable clone of your voice from just a few seconds of audio. A single Instagram story where you’re talking to the camera can allow someone with the right AI tools to make you sound like you. It may not be perfect at that length, but it might be good enough to work on your grandma over a bad phone connection.

Unfortunately, even if you delete your feed and protect your image and voice, you may still not be protected. Just going out in public, there are cameras everywhere, including everyone pocket and even, on their faces. These are images you never agree to and maybe never see happening.

“I’ll just set my account to private”

setting social media access to private

Do it. Locking down your audience is the single highest-value thing you can do to help protect your identity. It shuts out the bulk scrapers, the bots, and the strangers. But be honest about what that does and doesn’t get you. In the case above, the perpetraitor wasn’t a stranger. He already had access to photos. He was a friend from college with a legitimate reason to be on her follower list, and no privacy setting on earth flags “person you’ve known for years who turns out to be doing this.”

As Georgia put it: “in this context, without my knowledge or consent, it’s infuriating. It’s a betrayal.” That’s the real lesson, and it’s uncomfortable: the risk isn’t only how many people can see your photos. It’s that “someone I know” and “someone I can trust with my face” stopped being the same category. Setting your account to private isn’t a wall, it only limits who has access, and it begs the question – who can you trust with your photos?

It didn’t stop with her

AI used to create abuse images

When police started their investigation, the case got much bigger, fast. Officers first became aware of the site in January 2024, after a different woman reported that her wedding photos had been doctored and uploaded. Detectives traced the site to Florida and alerted the FBI. US investigators seized the domain, and found it was being used to advertise child sexual abuse material and connect buyers with sellers. They recovered 1.1 million indecent images of children and identified more than 50 child victims across the US, Canada, Australia, and the UK. Ten suspects were identified. Proceedings in the United States are ongoing.

Georgia now understands what that means, “It is so easy nowadays for predators to pick up a picture online. Everyone — most of my friends — posts their kids on social media and it takes one photo to be put through AI and it’s limitless.” She’s right, and it’s worth sitting with, because not only are your child’s photos in danger of being used, but your child’s identity is already worth more to a criminal than yours is.

Unfortunately, this is not a one-off case. In a separate prosecution, a man in Essex was jailed for five years after targeting 20 women across 173 posts using the same playbook: pull images from social media, run them through AI, post them to a forum built for exactly this.

What can you do to protect your identity

what you can do to protect your identity

To protect your identity in cases like this, here’s what’s actually worth your time:

  • Shrink your audience, then audit it. Set profiles to private, then actually read your follower list. Remove people you wouldn’t hand your phone to. This is the boring one that matters most.
  • Cut the high-resolution, front-facing face shots. Especially the ones doing double duty as your LinkedIn photo, your work badge, and your profile picture everywhere.
  • Set a family safe word. A word only your household knows, used to verify your identity on any urgent call about money or trouble. This is the single best defense against scammers who call grandma and grandpa with a cloned voice. Voice and video can’t be trusted as proof of identity anymore. A shared secret still can.
  • Know your takedown rights. In the US, the TAKE IT DOWN Act became fully enforceable on May 19, 2026. Covered platforms, including social networks, image hosts, even dating apps, must remove non-consensual intimate imagery, including AI-generated fakes, within 48 hours of a valid request, and remove known copies. The FTC enforces it. You do not need a lawyer to file a request.
  • Use StopNCII.org. It creates a digital fingerprint of an image on your own device and shares only that hash with participating platforms so they can block matches. Your actual image never leaves your phone, and AI-generated fakes of you count. Be realistic about the limits: it only reaches partner platforms, including Google, Meta, TikTok, X, Bing and others, but not the whole internet.
  • Search for yourself occasionally. Run a reverse image search on your main profile photo. Google your own name. Look at your profile from a logged-out browser and see what a stranger sees.

If something has already happened to you: report it, save everything, and know that Georgia’s case only blew up because one woman reported one doctored photo. That report ended up dismantling a network across four countries.

The one thing to do today to protect yourself

what to do today to protect yourself

You can’t un-post a decade of photographs, and nobody’s asking you to delete your entire life from the internet. But you can shrink the pile of raw material sitting out there with your name and image on it. Unfortunately, that pile is bigger than you think, because most of it isn’t even on your social accounts. It’s on data broker sites you’ve never visited. Start there. Delete your personal data from the internet for free. It takes an afternoon, it costs nothing, and it makes you a meaningfully harder target than the person scrolling past this.

Georgia didn’t make a mistake. She just existed online, the way we all do. The least we can do is stop making it easy for people to steal our images and identity.

Defending your identity from AI

Leave a Reply

Seraphinite AcceleratorOptimized by Seraphinite Accelerator
Turns on site high speed to be attractive for people and search engines.