Skip to main content
Emerging ThreatsData Breaches

FBI Disrupts Deepfake CSAM Market with Website Seizures

Law enforcement officer sits at desk with blank computer screen behind.

A collection, containing 189GB of material on 315 different girls, was offered for sale for $64.90.

The websites: NudeLeaksTeens and NLTVIDS

The FBI this week seized two websites—NudeLeaksTeens and NLTVIDS—that advertised, sold and linked to child sexual exploitation material (CSAM), according to court documents filed in the Eastern District of Virginia. The sites displayed explicit disclaimers disavowing child pornography even as they advertised and sold CSAM, and one site operated its own internal currency to purchase images and videos either individually or in bundles organized by victim.

Law enforcement action: FBI seizure and a French arrest

According to the Department of Justice, the cybercrime division of the French Paris Prosecutor’s Office arrested an unnamed 25-year-old French resident suspected of being the primary administrator for the sites. A seizure warrant filed Oct. 2 in the Eastern District of Virginia by Arlington County police detective and FBI cybercrime task force member John Bamford states that U.S. law enforcement executed a search warrant on VeriSign, a Reston, Virginia-based domain registry that controls the seized domains, taking servers, computers and other material.

Source material and criminal links: hacked social accounts, prison-connected collections

Law enforcement first became aware of the websites in 2024, Bamford wrote, and investigators found material drawn from victims’ social media accounts on Snapchat, TikTok, Instagram and Facebook—either recorded directly or stolen from their accounts. Several victims whose images and videos appear on the sites reported to law enforcement that their accounts had been hacked. Administrators often encouraged cryptocurrency payments and urged prospective buyers to contact them directly for certain material rather than posting it on-site; the sites also asserted that they did not host files but instead linked to “other non-affiliated sites.”

Some collections sold on the platforms were compiled by individuals who are now serving lengthy federal sentences. Bamford wrote that, in the course of investigating one such defendant, Andrew Venegas, law enforcement learned Venegas “obtained sexually explicit images and videos of his victims in various ways, including extortion and the unauthorized accessing of victim social media accounts.” Venegas pled guilty in a Texas federal court and was sentenced to 30 years in prison in April 2026. A separate collection offered on one of the sites in 2022 and 2023 bore the name of Reuben Oswaldo Yeverino Rosales, who was convicted and sentenced to more than 34 years in prison in 2022 for sexual exploitation of children and cyberstalking.

The TAKE IT DOWN Act: legal tools cited in court filings

Bamford’s filing said the sites offered “a wide range of explicit content including CSAM and content that violates the TAKE IT DOWN Act, which prohibits the non-consensual sharing of intimate images.” The seizure warrant cites the TAKE IT DOWN Act, passed last year, which makes it a crime to create or share nonconsensual “intimate” deepfake media of real people, gives the Federal Trade Commission authority to enforce the statute and allows courts to order websites to remove such content. The court documents state that the seized sites disseminated child sexual exploitation material, including AI-generated deepfake media.

What this means for technologists, policymakers, and victims

  • Technologists and security teams: The case documents link a blended model of abuse—hacked social media accounts, stolen files, bundles compiled by convicted offenders, and AI-generated deepfakes—underscoring the challenge of detecting and removing content that can be hosted, linked, or transacted around outside a single server. The FBI’s seizure of domain registry infrastructure at VeriSign indicates investigators followed domain-control and registry records as part of the takedown.
  • Policymakers and regulators: The seizure and the filings explicitly invoke the TAKE IT DOWN Act and the FTC’s enforcement authorities, demonstrating how recent statutory tools are being applied to online marketplaces that traffic in nonconsensual intimate imagery and CSAM. The Department of Justice and a foreign prosecutor’s office coordinated arrest and seizure activity across jurisdictions, showing cross-border investigation paths for sites hosted or administered abroad.
  • Victims and the general public: The court filings report material on the sites originated in part from Snapchat, TikTok, Instagram and Facebook accounts, with victims reporting unauthorized access. The presence of identifiable collections tied to previously prosecuted defendants highlights the persistent circulation and monetization of images long after original exploitation or account compromise.

This operation puts a spotlight on how online marketplaces for abuse can mix stolen original content with AI-generated deepfakes and virtual currencies, then hide behind disclaimers and links to “non-affiliated” hosts. The FBI’s seizure of domains and French investigators’ arrest of a suspected administrator place tangible pressure on two supply-side nodes in that chain, but the court records make clear the files themselves were sourced from multiple places and previously convicted offenders. Whether those pressures will choke the broader trade or merely complicate it remains a question the seized evidence—and subsequent prosecutions—will help answer.

Original reporting: https://cyberscoop.com/fbi-french-authorities-seize-deepfake-csam-websites/