Understanding Sextortion: Why Tech Giants Aren’t Doing Enough
On 13 July 2026, the eSafety Commissioner released its third periodic notice on child sexual exploitation and abuse material and activity. In a six-month period, the Commissioner received 2,206 complaints of sextortion. It identified tech giants, including Apple, Meta, Discord and Google, as significantly contributing to the growing problem.
Sexual extortion, abbreviated to sextortion, is a form of blackmail, where someone is coerced or deceived into sending sexual content of themselves. The perpetrators, often referred to as sextortionists, threaten to share the sexual content unless their demands are met. When this crime targets children, it is also a form of child sexual exploitation and abuse (CSEA).
Amongst the 2,206 complaints, young males were overrepresented. 85% of all complaints were by men, predominantly aged 18-24, followed by those aged 25-39.
Concerningly, hundreds of reports were made by children under the age of 18.
What does sextortion look like?
Thorn, a nonprofit aiming to combat child sexual abuse, describes sextortion as often being ‘formulaic… as if operating off a script’. This ‘script’ is most common when sextortion occurs for the purpose of financial gain.
Together with the NCMEC, Thorn examined a dataset of more than 15 million reports made over three years. The NCMEC alone receives hundreds of reports of sextortion per week.
Once a victim had shared sexual content, threats often involved ‘exaggerated impacts’, such as ‘ruining the victim’s life’.
Phrases including ‘I have ur nudes and everything needed to ruin your life’ and ‘u will be exempt from universities if u don’t cooperate’ are a few publicised examples. These specific examples occurred in at least four individual reports.
Countdown threats were also prevalent to create urgency, alongside constant communication, at the threat of exposing imagery.
In some reports, a victim would not share sexual content of themselves. Instead, content was generated about them. Whilst this occurred in only 11% of reports from 2020-2023, the growing prevalence of Artificial Intelligence may increase the incidence of this form of sextortion.
The platforms used in sextortion reports also varied. Many perpetrators would meet the victim on one platform before moving to a secondary platform, such as Snapchat or WhatsApp. The likelihood of young people sharing sexual content on these private messaging platforms has been found to be statistically higher, which may contribute to the reason perpetrators transition to them. Thorn’s report found that 65% of children had experienced an attempt by a perpetrator to move into a private conversation on a different platform.
Payments to perpetrators often rely on online payment platforms. The use of gift cards, Cash App, PayPal, and other services was found in reports.
Whilst perpetrators can be individuals, many operate in larger-scale organisations. An investigation in 2025 by the BBC led to Nigeria, where a group known as the ‘Yahoo Boys’ were found to be running many sextortion-like scams. Outside of the ‘Yahoo Boys’, many perpetrators operate transnationally from Nigeria and Côte d’Ivoire.
Other groups of offenders engage in sadistic sextortion, where extreme online communities target children for material so the children can gain acceptance into these communities. Sadistic sextortion groups have also been found to encourage animal cruelty and violent live acts.
Key Gaps
Within the tech giants, a few key gaps consistently appear.
Another significant issue is the barriers to end-to-end encryption. End-to-end encryption encrypts data on the sender’s device and then only decrypts it on the device of the recipient. This means data cannot be analysed for illegal content or abuse material while in transit. Whilst the Government has expressed an understanding for the role of encryption in privacy, intellectual property, trade and cyber security, they have also expressed concerns about how it can harm victims and public safety.
The eSafety Commissioner provides information on where specific service providers have both failed and succeeded.
Apple: iMessage is considered a ‘high-risk’ platform for sextortion as it is end-to-end encrypted. Apple does not use language analysis or other proactive detection tools for abusive material. However, it does have a Communication Safety feature for minors that detects nudity and blurs the image. This feature only applies if users accurately enter their age into the platform, and a report cannot be made if the content was obtained on another service.
Discord: Indicated to be a high-risk platform for sexual extortion. Discord does not use language analysis but has a Safety Alerts on senders feature that alerts children 13 to 17 when an unfamiliar user contacts them. Discord also has a model that detects and removes harmful communities.
Google: No language analysis technology or proactive detection on anything other than YouTube. Google recently implemented a ‘harmful content’ mechanism on some of its services; however, this consists of a lengthy web form.
Meta: Uses language analysis tools; however, these are not as strong on Facebook Messenger and Instagram Direct, as these services are end-to-end encrypted. As of May 2026, Instagram Direct is no longer end-to-end encrypted, but no proactive measures have been announced yet.
Microsoft: No language analysis technology or proactive measures are in place; users can report in-product. On Xbox, language analysis was used to detect extortion.
Snapchat: If content is reported, detection tools are used. Snapchat also sends warnings to children aged 13 to 17 about messages that may pose a risk of harm. Snapchat states that 99.64% of teenagers clicked through to see the message regardless.
WhatsApp uses language analysis on user reports and both language-based detection and signal-based detection in Channels and communities. WhatsApp also has an in-app reporting system, but it does not have specific categories like CSEA material.
Safeguarding Victims
Thorn and the NCMEC state that an effective approach to protecting children must extend beyond simply saying “just don’t share images”.
Platforms must improve their reporting mechanisms and implement both proactive and reactive solutions. The eSafety Commissioner suggests that platforms that are not end-to-end encrypted could implement language analysis technology to detect common scripts, which can then be flagged for human review.
A more layered approach must be taken for end-to-end encrypted services, as the Commissioner states that they remain a ‘serious safety gap’.
Despite growing reports, eSafety noted that from its previous report six months prior, some proactive and reactive improvements had been observed.
