The unintended consequences of digital copyright enforcement have taken a surprising turn, as a new analysis reveals that DMCA takedown requests filed on behalf of OnlyFans models are inadvertently exposing and neutralizing compromised government and university websites across the globe. What began as an effort to protect pirated adult content has evolved into an unlikely but effective mechanism for identifying security failures in some of the internet’s most trusted domains.
The Collision of Copyright Enforcement and Website Security
Adult content creator Laura Lux, who has published images online for nearly two decades, describes the battle against content theft as an “endless battle.” Pirated material, often shared and traded in online communities, costs creators significant revenue. To combat this, creators and their representatives file millions of takedown requests under the Digital Millennium Copyright Act (DMCA), demanding that search engines remove links to stolen content. However, these requests have increasingly targeted domains ending in .gov and .edu — domains that should, in theory, be among the most secure on the internet.
According to research from cybersecurity company UpGuard, over 2,000 domains belonging to governments and educational institutions across 80 countries have received copyright takedown requests linked to adult content over the past 15 years. The reason is not that these sites are hosting adult material intentionally, but that they have been compromised by scammers who exploit security vulnerabilities to upload malicious pages.
How Scammers Hijack Trusted Domains
Fraudsters have long targeted authoritative .gov and .edu domains because they rank highly in search engine results, lending an appearance of legitimacy to any content hosted on them. Attackers upload pages and PDFs promoting fake offers — free movie downloads, iPhones, Fortnite skins, and explicit content — which then redirect visitors to scam websites or malware downloaders. The names of popular adult content creators are increasingly used as bait to draw victims to these compromised pages.
Greg Pollock, director of research at UpGuard, explains that while adult creators have no intention of policing government website security, their DMCA enforcement efforts produce that effect. “In some ways, because of the way the attack works, having Google remove the search result is extremely effective, because there’s no real visibility of the asset outside of Google,” Pollock says. The takedown requests effectively de-index the scam pages, cutting off the primary channel fraudsters rely on to reach victims.
The Scale of the Problem
UpGuard’s analysis documents 384,286 takedown requests covering 631,193 URLs sent from adult content creators targeting government and education websites since 2011. The vast majority of these requests have been filed since 2020, reflecting what the researchers describe as a “dramatic” increase in hijackings related to leaked OnlyFans content. Of those requests, Google has removed approximately 130,000 URLs, while over 460,000 remain indexed. Affected domains include government and university websites in Bangladesh, Colombia, India, Nigeria, the United States, and Peru.
How Do DMCA Takedowns Reveal Compromised Government Sites?
When a copyright holder submits a valid DMCA takedown request to Google for a URL hosted on a .gov or .edu domain, the process forces an examination of whether that domain has been hijacked. A legitimate government website would not host pirated adult content, so the presence of such material is a strong indicator that the site has been compromised. The takedown request effectively flags the domain for review, and Google’s removal of the URL from search results disrupts the scam’s primary distribution channel.
What Affected Users and Organizations Should Do Now
For individuals who suspect they may have encountered compromised government or educational websites, the immediate steps are straightforward. Avoid clicking on search results that promise leaked content, free downloads, or suspicious offers — even if the domain appears legitimate. Ensure that your browser, operating system, and security software are up to date, and consider using a reputable antivirus solution with real-time threat detection to block malicious redirects. For organizations managing .gov or .edu domains, regular security audits, vulnerability scanning, and prompt patching of content management systems are essential. Any unexplained pages or files appearing on the domain should be investigated immediately, and web application firewalls should be configured to block unauthorized file uploads. The unlikely partnership between adult content enforcement and website security serves as a reminder that threat detection can emerge from unexpected sources, but formal security practices remain the only reliable defense against compromise.