I've been deepfaked: What do I do?
- ESET Expert

- 29 minutes ago
- 6 min read
Don't panic if you spot an illegally created image or video of you online – there are ways to request its removal

Tackling deepfakes has become something of a common cause across the political spectrum, in America and elsewhere. That's down in part to the fact these fabricated videos and images are becoming both more commonplace and realistic. Thanks to generative AI (GenAI) tools, it's extremely quick, cheap and easy to make fake media impersonating a real person.
While some are sent as a joke, there's a darker underside to deepfakes. Cybercriminals and fraudsters are increasingly using the technology in scams and extortion. Bullies use it to harass, humiliate and abuse their victims. Children are often targeted, and some victims have even taken their own lives as a result.
All of which explains the success of the TAKE IT DOWN Act, which recently became law in the US. But across the globe, policymakers and public opinion are forcing tech platforms to better police this content. That's good news for anyone that finds themselves on the receiving end of a deepfake.
Are deepfakes illegal?
The frustrating answer is, it depends. In the US, the TAKE IT DOWN Act criminalizes the distribution of non-consensual intimate imagery (NCII), with online platforms required to provide clear reporting mechanisms and takedown legitimately reported images within 48 hours. In the UK, the Data Act and Online Safety Act make it a criminal offense to create NCII. The authorities have also imposed a 48-hour mandatory window for removal. The EU AI Act will shortly introduce a ban on systems specifically designed to create NCII. But individuals' actions are governed by member states' laws. However, if the image is of a child, it is illegal in most if not all jurisdictions.
Outside of NCII, it depends on what the deepfake was created for. If it was distributed without consent and/or used for malicious ends such as fraud, blackmail, defamation, harassment or impersonation, it could be illegal.
The Scale of the Problem: This Isn't a Rare Occurrence Anymore
It's worth understanding just how fast this problem has grown, because it changes how seriously it should be taken. The volume of deepfake content circulating online has climbed from an estimated 500,000 files in 2023 to roughly 8 million in 2025, according to research cited in Europol's Internet Organised Crime Threat Assessment, a sixteen-fold increase in just two years. Detection hasn't kept pace with creation, either: a 2024 study by biometrics firm iProov found that only 0.1% of people could reliably distinguish a deepfake from genuine footage across audio, image, and video formats combined.
This isn't a niche problem confined to obscure corners of the internet, either. Reported incidents in 2025 skewed heavily toward the platforms people use every day, with YouTube, Instagram, Facebook, and TikTok among the most common places deepfake content actually surfaces. In other words: the odds of encountering, or becoming the subject of, a deepfake aren't shrinking as the technology matures, they're growing, and mainstream social platforms are exactly where it's happening.
What should I do if I've been deepfaked?
If someone has made a deepfake of you that doesn't qualify as NCII, first save the evidence. That means screenshotting the page or account, saving the URL and making a note of the account or username, the date and time you found it, and any accompanying text. It makes sense not to engage with the person who posted it, or they may disseminate the content even further.
You'll need to follow the rules below to report the offending content, as well as any impersonation, fraud, extortion or additional threats that could be part of a broader crime. It goes without saying that if you feel physically threatened, report it to the police.
How do I report a deepfake photo/video of me?
Most online and social platforms now have a reporting mechanism for deepfakes, but they rarely have a single button to do so. You'll usually have to find the offense that the deepfake enabled (e.g., bullying, fraud) and then explain it.
Google: Try Google's "remove personal information" tool (or here) and the legal removal request form to remove non-NCII from search results. This will make it harder for people to find your deepfake. Note that this won't remove the underlying content.
Facebook: Open the post/video. Select ⋯ → Report post/video; Choose the category that best describes the issue, e.g. impersonation, harassment. Explain that the content is AI-generated and clarify what makes it deceptive or harmful.
Instagram: Click on the two lines in the top right, then Report, and choose the most appropriate reason.
TikTok: On the video: Share → Report → Misinformation → Deepfakes, synthetic media, and manipulated media → Submit.
YouTube: If someone uses AI to create or alter content that looks or sounds like you, you can ask for it to be removed via the Privacy Complaint Process for altered or synthetic content.
X: Report the individual post. Tap the three horizontal dots. Report post → follow the reporting flow. Explain that the content is AI-generated and why that's a problem.
How do I get an AI nude image of me removed?
NCII demands a rapid response, for obvious reasons. A good first bet is StopNCII.org, a resource operated by the Revenge Porn Helpline, which is part of international charity SWGfL. Select the offending image/video and StopNCII.org will create a hash of it on your device. If the report is successful, you will receive a case number. And most importantly, participating platforms will look for the same hash and remove any matching images on their systems if it violates their policy.
Partners include Meta, TikTok, Reddit and X. You'll also want to remove the deepfake from Google Search so it becomes harder for people to find.
TakeItDown.NCMEC.org operates a similar system for images/video of those under-18.
A website won't remove my photo, what next?
Google may have de-indexed the deepfake of you, but it may still be available on an underlying website. The first point of call is to contact the publisher to request removal. But if they refuse, work through the following steps:Preserve the evidence, including screenshots, URL, date and time you first spotted it, the website's response to your request, and the account/user that uploaded it.
Find the website's legal/privacy/copyright contact, and write telling them that the image/video depicts you and is being published without your consent. Request its removal under the appropriate website policy or local laws, and to confirm in writing when this has been done.
In the UK/EU you can do the above citing a GDPR, Article 17 right-to-erasure request. If they still refuse, or take no action, escalate to your local data protection regulator. In the US, your course of action will depend on individual state laws
The key when interacting with websites, social platforms, search engines, or regulators is not merely to state that the content is AI-generated, but specify exactly why it's problematic (e.g., fraud, harassment, impersonation etc). Be persistent and consider contacting the search engine, social site/website and regulator simultaneously to save time.
Reducing Your Risk Before It Happens
While there's no way to make yourself completely deepfake-proof, especially since these tools can now work from just a handful of public photos or a few seconds of audio, there are practical steps that meaningfully reduce your exposure. Consider tightening privacy settings on personal social accounts so photos and videos aren't fully public by default, being cautious about posting high-resolution, front-facing photos or voice clips in public forums, and periodically searching your own name and image online to catch misuse early, similar to the kind of digital footprint audit that's worth doing for personal data generally.
If you're a public figure, journalist, or someone whose voice or likeness is professionally valuable, it's also worth discussing watermarking or provenance-tagging options for official content with your organization's communications team, so genuine footage of you can be more easily distinguished from fabricated versions if a dispute ever arises.
How ESET Can Help You Take Back Control
Dealing with a deepfake is fundamentally a fight to reclaim control over your own identity, and that's exactly the kind of ongoing vigilance that's hard to maintain alone. ESET HOME Security Ultimate includes Identity Protection, which continuously monitors for signs that your personal information or identity is being misused online and alerts you early, before a situation has the chance to escalate.
Pairing that kind of ongoing monitoring with the reporting steps outlined above gives you two layers of defense: one that helps you catch misuse sooner, and one that helps you act on it decisively once you do. In a landscape where deepfake volume is growing faster than most people's awareness of it, having something watching on your behalf isn't overkill, it's simply keeping pace with how the threat itself has evolved.



Comments