Intelligence Library
AI-Enabled Crime

Deepfake Extortion: The New Frontier of Non-Consensual Image Abuse

AI-generated intimate imagery is now being used as a coercion instrument against individuals at every level of society. Organisations need clear policies and response protocols before the first incident.

Non-consensual intimate imagery has been a tool of coercion and harassment for as long as digital photography has existed. The introduction of AI image generation has changed the landscape in one fundamental respect: the imagery no longer needs to be genuine. A convincing synthetic intimate image can now be generated from publicly available photographs of the target, without any requirement that such imagery exist or ever have been created. The target's lack of involvement in the creation of the imagery is not a defence against its use as a coercion instrument, because the coercive power lies in the threat of publication, not in the underlying truth of the image.

Deepfake extortion operates on a simple mechanism. The attacker generates synthetic intimate imagery of the target using publicly available photographs. The target is then contacted with a demand: payment, or the imagery will be distributed to the target's professional or personal contacts. The threat is credible because even a demonstrably synthetic image, once distributed, creates a reputational and psychological harm that is difficult to reverse. Many targets pay to avoid that harm, even knowing that the imagery is fabricated.

The corporate dimension of deepfake extortion is significant and underappreciated. Senior leaders, public figures, and anyone with a high-profile professional presence are disproportionately targeted, precisely because their reputational exposure is high and their personal resources to pay are assumed to be substantial. When a senior executive, a politician, or a public official is targeted, the coercive leverage extends beyond personal embarrassment to professional consequence and, in some cases, national security implications.

Organisational response protocols for deepfake extortion need to be established before an incident occurs, not in response to one. The decisions that need to be made in the acute phase of an extortion attempt, involving legal, communications, HR, and security functions simultaneously, cannot be made well under duress without prior planning. Organisations that have no protocol will typically default to silence and payment, neither of which is the recommended response.

Custodia One's deepfake extortion advisory covers both the individual response and the organisational protocol layer, including legal strategy, law enforcement engagement, evidence preservation, and communications management across the incident lifecycle.

"The question is no longer whether the imagery is real. The question is whether the threat of distribution creates sufficient harm to extort compliance. For most targets, it does. Organisations need to be prepared for this before it happens."

Custodia One Advisory Perspective

What Your Organisation Should Do

  • Establish a deepfake extortion response protocol before an incident: this cannot be designed well under pressure

  • Brief senior leaders and high-profile staff on the threat: normalise the conversation so incidents are disclosed quickly

  • Build legal and law enforcement relationships in advance: the first hours of an extortion attempt are critical for evidence preservation

  • Address the payment decision explicitly in your protocol: payment does not reliably end the extortion and may escalate it

Advisory Enquiries

Facing this issue in your organisation?

Custodia One advises on all of the issues covered in our Intelligence Library. Contact us to discuss your specific situation in confidence.