Deepfake Porn Site Targeted a Reporter, Then She Traced Its Payments to a Listed Tech Company
What happened
In January 2025, German investigative reporter Patrizia Schlosser discovered that explicit deepfake images depicting her had been posted to a pornographic platform without her knowledge or consent. The images were generated using AI tools capable of placing anyone's likeness into degrading scenarios from a single source photograph. Schlosser had reported extensively on sexualized violence against women, and the attack appeared connected to that work rather than being random.
Rather than absorb the incident quietly, Schlosser chose to investigate it. Working alongside investigative nonprofit Bellingcat and German YouTube channel STRG_F, she turned her attention to the platform hosting the content: MrDeepFakes. What they found was not a fringe operation. The site carried close to 650,000 registered members and had accumulated nearly two billion views across its AI-generated image and video library.
The investigation revealed that the site's administrators routed payments through cryptocurrency and PayPal, financial channels that preserve a degree of anonymity while still requiring functional payment infrastructure. More significantly, the reporting identified a possible corporate connection between the platform's operators and Shenzhen Xinguodu Technology, also known as Nexgo, a Chinese fintech company listed on the Hong Kong stock exchange. That connection, if accurate, places a publicly traded firm at least adjacent to a platform built around non-consensual explicit imagery generated at scale.
Schlosser's case was not isolated. Deepfake attacks against women who hold public roles or report on sensitive topics have become a documented pattern, and the technology has made them cheap and fast to produce. A single photograph is enough to generate material that would have required substantial resources a decade earlier. The platform's scale, with content viewed close to two billion times, indicates that what targeted Schlosser reflects routine use of the service rather than an edge case.
The deeper problem exposed here is not the technology itself but the absence of infrastructure for tracing conduct back to specific actors. The images targeting Schlosser could be generated, posted, and viewed by millions with no durable record connecting the act to the person who ordered it. Cryptocurrency payments and corporate intermediaries add further distance between harm and accountability. A provable record of what a system did, who authorized the upload, and which accounts processed the payments would have changed the picture entirely. Without that record, investigators are left reconstructing causation from fragments, and platforms can continue operating in the gap between what regulators can prove and what actually happened.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.