On July 8, 2026, WIRED reported on new research from cybersecurity firm UpGuard showing that mass copyright takedown requests filed on behalf of OnlyFans creators have inadvertently become one of the internet's more effective tools for surfacing — and getting removed — hacked government and university websites. UpGuard director of research Greg Pollock analyzed Google's transparency reports and Harvard's Lumen Database and found more than 2,000 domains belonging to governments and educational institutions worldwide had been compromised by scammers who use the sites' authoritative .gov and .edu domains (which rank highly in search) to host fake "leaked OnlyFans content" pages. Those pages don't actually contain stolen content; instead they funnel visitors toward unrelated scam ads for dating sites and other schemes. Because adult-content creators and the firms that represent them — Pollock's analysis found one company, Estonia-based Rulta, behind roughly 90% of recent requests — routinely file Digital Millennium Copyright Act takedown notices against any page claiming to host their material, they've unintentionally been flagging compromised .gov and .edu domains to Google for removal at scale.

Why It Matters

For sex tech and the creator economy, this is a reminder that OnlyFans-scale platforms now generate enough downstream data — takedown requests, piracy patterns, scam-page fingerprints — to have measurable effects on unrelated sectors like government cybersecurity. It also highlights a persistent cost center for creators: piracy remains rampant enough that a single copyright-enforcement vendor can generate hundreds of thousands of takedown requests, and creators are losing meaningful revenue to content that's "a Google search away," in the words of one anonymous creator quoted in the piece. For platforms and creator-tooling companies, it's a signal that copyright enforcement infrastructure is maturing into something closer to threat intelligence — a capability that could eventually be licensed or repurposed rather than treated as pure loss-prevention overhead.

Pollock's dataset covers 384,286 DMCA takedown requests spanning 631,193 URLs sent by adult-content creators to government and education websites since 2011, the large majority filed within the past few years as the OnlyFans-driven creator economy has grown. Google has removed roughly 130,000 of the flagged URLs to date. Content-protection firms interviewed by WIRED, including Ceartas founder and CEO Dan Purcell, offered mixed reactions: some argue the DMCA is being used inappropriately against sites that never intentionally hosted infringing material, while others frame it as an accidental public service exposing security holes institutions haven't patched. A Google spokesperson told WIRED its anti-spam systems and Chrome warnings are "highly effective" at catching compromised pages, independent of the DMCA requests.

The dynamic underscores how much infrastructure now sits downstream of the creator economy's scale: adult-content piracy enforcement, originally built to protect individual creators' earnings, has become large enough in volume to function as an informal vulnerability-disclosure pipeline for public-sector cybersecurity — a byproduct nobody designed for and few institutions are aware of.

Sources


Update — 2026-07-09

Initial entry — story first created.