NudeLeaksTeens sites seized by FBI and French police
The FBI and French law enforcement have taken down two websites that sold sexually explicit images and videos of young women and girls, much of it stolen from hacked social media accounts. The suspected administrator was arrested in northern France.
The domains belonged to NudeLeaksTeens (NLT). The seizure was announced on Wednesday by the U.S. Attorney's Office for the Eastern District of Virginia, the federal prosecutors for that region. The operation was carried out together with the FBI Washington Field Office and the cybercrime division of the Paris prosecutor's office, the French judicial authority that handles many of the country's major cybercrime cases.
According to French authorities, more than 17,000 women worldwide were victimized through the platform.
Albums, collections and personal data
The seizure warrant describes how NLT packaged its content. Material was sold as "albums" and "collections," which often bundled personal identifying information about the victims together with images showing them in various stages of undress or engaged in sexually explicit conduct.
One collection carried the site's own name. It was advertised as holding 6,200 private nude files of teenagers and adults, mostly American, taken from hacked Snapchat, Instagram, TikTok and Facebook accounts.
The site displayed warnings against child sexual abuse material (CSAM), but investigators found that it sold such material anyway. The collection named after the site was among the content that contained CSAM.
"Some of the victims have been identified and confirmed to be minors at the time the visual depictions were created," the Justice Department said.
Victims rated and indexed
The way the platform organized its victims made the abuse worse. Victims were indexed by age, place of residence, profession and physical appearance, and each was given a "beauty rating out of 10."
Users who supplied information about victims were paid in cryptocurrency. This turned the gathering of personal details into a crowdsourced business.
Two brothers arrested
French police arrested the suspected administrator, a 25-year-old man, along with his 21-year-old brother. Searches of the brothers' homes turned up about EUR 700,000 in Bitcoin, Litecoin, USDT and Ethereum, which investigators seized.
"The seizure of these domains represents a decisive step in dismantling the criminal networks that hide behind anonymous online platforms to exploit victims," said Darren B. Cox, assistant director in charge of the FBI Washington Field Office.
Cox said the agencies worked "shoulder to shoulder" with national, international and private sector partners to cut off the infrastructure used to distribute images and videos obtained by hacking victims' social media accounts, "striking directly at the core of this illicit online marketplace."
The FBI and French authorities have both asked victims of the platform to come forward.
Our Take
The NLT case shows how account takeover can do harm far beyond financial fraud. The stolen material came from mainstream platforms such as Snapchat, Instagram, TikTok and Facebook. This suggests that a compromised personal account can become the raw material for a commercial exploitation operation. For readers, the practical lesson is familiar but worth repeating: private content stored in social media accounts is only as safe as the login protecting it.
The structure of the site also stands out. Paying users in cryptocurrency for victim details is a pattern seen across underground marketplaces. The same goes for selling content in packaged bundles and attaching personal data to it. Seized crypto holdings have become a regular feature of such takedowns, as seen in the recent sentencing of an Empire Market co-creator.
The joint U.S.-French action fits a wider trend of cross-border cooperation against online criminals. Another recent example is the Qilin ransomware suspect arrested in Japan and handed over to Germany. It is worth watching how the case against the two brothers proceeds, including where they will be prosecuted. Another open question is whether investigators can trace the people who supplied victim information or carried out the account hacks. With more than 17,000 victims, the response to the call for victims to come forward could shape how much of the network is ultimately uncovered.
