I’ve been deepfaked: What do I do?

Imported from official source

Cybersecurity Classified by Officially

Tackling deepfakes has become something of a common cause across the political spectrum, in America and elsewhere. That’s down in part to the fact these fabricated videos and images are becoming both more commonplace and realistic. Thanks to generative AI (GenAI) tools, it’s extremely quick, cheap and easy to make fake media impersonating a real person.

While some are sent as a joke, there’s a darker underside to deepfakes. Cybercriminals and fraudsters are increasingly using the technology in scams and extortion. Bullies use it to harass, humiliate and abuse their victims. Children are often targeted, and some victims have even taken their own lives as a result.

All of which explains the success of the TAKE IT DOWN Act, which recently became law in the US. But across the globe, policymakers and public opinion are forcing tech platforms to better police this content. That’s good news for anyone that finds themselves on the receiving end of a deepfake.

The frustrating answer is, it depends. In the US, the TAKE IT DOWN Act criminalizes the distribution of non-consensual intimate imagery (NCII), with online platforms required to provide clear reporting mechanisms and takedown legitimately reported images within 48 hours. In the UK, the Data Act and Online Safety Act make it a criminal offense to create NCII. The authorities have also imposed a 48-hour mandatory window for removal. The EU AI Act will shortly introduce a ban on systems specifically designed to create NCII. But individuals’ actions are governed by member states’ laws. However, if the image is of a child, it is illegal in most if not all jurisdictions.

Outside of NCII, it depends on what the deepfake was created for. If it was distributed without consent and/or used for malicious ends such as fraud, blackmail, defamation, harassment or impersonation, it could be illegal.

What should I do if I’ve been deepfaked?

This is an extract. The publication continues at the source.

Read the original at the source: https://www.welivesecurity.com/en/how-to/ive-been-deepfaked-what-do/

Officially imported this from ESET’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
ESET — imported from official source
Official source
https://www.welivesecurity.com/en/rss/feed/ RSS
Imported
September 18, 2026 11:35
Versions
1 recorded
Identity
https://www.welivesecurity.com/en/how-to/ive-been-deepfaked-what-do/

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.