My childhood was blissfully analogue. It was not until I went to university in the late 1990s that I got to experience the wonders of the world wide web. In the heady days when age verification meant clicking a box that said “I am over 18”, it was far easier to stumble across disturbing content. Having little interest in the celebrity autopsies, graphic images of gunshot wounds and animal porn which filled shock sites like the now defunct Rotten.com, my first visit to this corner of the web was also my last.
Back then, it was considered common sense to post anonymously, not share pictures of yourself with total strangers, and never trust anyone you didn’t know in real life. In the past 30 years, however, those unwritten rules have changed dramatically, not least as tech companies have realised that there are billions of dollars to be made from encouraging people to give up their privacy for likes, engagement and the promise of monetisation.
Keen to convince social media users that their products are still safe, platforms have developed lengthy safeguarding policies. Poor application of those policies has, however, created dangerous loopholes, as I discovered first-hand when investigating teen video trends on TikTok.
After three days of scrolling through reel after reel of “edgy” videos about urban legends of the dark web, the hidden internet not visible to search engines, the app began to recommend a different kind of content. Standing out from the dingy colour schemes and dramatic music of the other short videos in my feed, one clip caught my eye.
It seems to be a father and son playfighting in a bedroom. In the video, the boy, who looks around 12 years old, laughs and says, “I bet you couldn’t pick me up and throw me!” Roaring cartoonishly in response, his father grabs him by the ankle before faux body-slamming him onto the bed. Pulling himself back up, the boy cheerfully reassures the camera that “this is not WWE, even though the video is called WWE [World Wrestling Entertainment, the US professional wrestling company]” and his father agrees, pulling him close as the clip abruptly ends.
‘Who has the full vid?’ asked one anonymous user under the clip of the boy wrestling with his father
The TikTok account that had posted this clip when I came across it had an AI-generated profile picture of a red-haired man. The bio had a handle from the messaging app Telegram and the account had only posted five other videos. These included a different young boy dancing at a football game, alongside AI images of the red-haired man surrounded by babies.
Given that he had only 1,200 followers, this appeared to be just another odd corner of what TikTokers refer to as “the Farlands”, an umbrella term for weird, creepy, or frightening content, but comments posted by those followers revealed the account’s true purpose.
“Who has the full vid?” asked one anonymous user under the clip of the boy wrestling with his father.
“Trade?” posted another, to which more anonymous users replied with links to their own Telegram channels.
Visiting those channels, which were public, and going to the commenter’s TikTok profiles, revealed the original account to be a shop front for the exchange of child sexual abuse material (CSAM). This was only one of 176 TikTok accounts that I would eventually uncover. With more than two million followers between them (some of whom overlap) the 176 accounts have manipulated TikTok’s safeguarding system in order to either advertise Telegram channels where CSAM is traded and sold, or to create public meeting points for users seeking CSAM.
According to TikTok’s own terms and conditions, the company has a “zero-tolerance approach” to content that violates its youth safety policies, especially online child sexual exploitation and abuse (CSEA) and sharing CSAM. Should users encounter such material they can report it and, TikTok reassures them, it will be removed. In addition, the platform recently introduced measures that redirect users searching for CSAM to support groups which can help them stop seeking out this sort of material online.
So how are these TikTokers getting around the platform’s guardrails? The accounts I uncovered share four types of content as a sign to other users seeking CSAM. Aside from the misappropriation of photos or video featuring real children, such as the clip of the father and son playfighting, three types use AI-generated imagery. These include cartoonish AI-generated videos of children; realistic-looking AI videos of children; and AI-generated images of convicted child abusers, which are intended as signals for those likely to recognise them.
In total, I found 13 accounts actually posting the first two types of AI-generated content. Based in Russia, Spain and Australia they have more than 50,000 followers between them, and the boys who appear in their videos look to be around five to 15 years old.
Labelled with hashtags such as “Pride”, “Gayboys”, “MLM” (men loving men) and other phrases used by the LGBT community, the images appear to be wholly innocent depictions of friendships between boys. But digging deeper into the accounts I found posts advertising the Telegram handles of private channels, encouraging fans to contact them with their views about the content, and announcing that a “written story of Elias and Edwin” (two characters who appear to be about 10 years old) “consummating the act” is available on Telegram.
The 176 accounts I uncovered have manipulated TikTok’s safeguarding system to advertise Telegram channels where CSAM is traded and sold
Operating on messaging apps, such as WhatsApp, Zangi, Signal and Telegram, where censorship is far less of an issue, the channels, which essentially function as chat groups, have hundreds of members from all over the world. As some share their content publicly, I was able to confirm that they create and share sexual content featuring their favourite AI boys, most of whom are under 13 in appearance.
The 15 East Asian accounts I found on TikTok, with more than 50,000 followers between them, operate similarly but, instead of linking followers to AI-generated CSAM, creators use their videos to entice viewers onto often public Telegram channels where they sell CSAM of actual children. Following the links shared by the TikTok accounts revealed CSAM content without me having to join the Telegram channel.
In the UK, both types of CSAM—AI-generated and featuring real children—are illegal. TikTok gives UK users the option to report accounts which have broken their rules and the law. However, my reports, made via the platform, were returned with a message to say that they had violated neither. In response to some of my reports, TikTok said that it would “hide the content from UK users”. Left with the option of effectively closing my eyes and pretending all of this didn’t exist, I reported the accounts I uncovered to law enforcement in their respective countries, including the UK. I have yet to receive any responses.
The profile picture of the red-haired man that started me on this investigation epitomises the third category of AI imagery I uncovered: AI-generated pictures of child sex offenders.
Having come across the same AI-generated images of the man’s face in posts made by 35 separate accounts, I conducted an image search. It turned out that the character with the red hair was based on a 27-year-old man from Tennessee, Matthew Estes, who is currently serving a 60-year prison sentence for “production of child pornography”.
In 2015, the then 17-year-old Estes (himself a victim of severe childhood trauma) met an older man online who coerced and extorted him into recording himself raping a 16-month-old child and posting the videos on the dark web. Court documents from his sentencing revealed that the brutality of his actions have since led to the “Matt Estes Series” (as it is known) becoming something of a holy grail for paedophiles online.
While the full videos have, thankfully, not made it onto TikTok, images from them have been used as profile pictures and stickers (shareable thumbnail images) by many of the accounts uncovered in this investigation—another way of signalling a shared interest in CSAM to other users. Some of these accounts have also used Estes’s image as an AI prompt to create and share deepfake videos on TikTok of him interacting with other convicted paedophiles (identified via image searches) and “babysitting” AI-generated children.
Often shared by accounts whose usernames incorporate a pizza emoji (because “cheese pizza” and “child pornography” have the same first letters), or an American football emoji and the number 94 (Estes’s jersey number when he played high-school American football), every one of the accounts I identified which featured images and videos of Estes led to a Telegram channel where CSAM was offered for sale. When I reported them to TikTok, they were either suspended or hidden from view in the UK.
After two weeks of investigation, the algorithmic recommendations began to repeat themselves, creating a glimmer of hope that I may have reached the end of this CSAM network. Shortly afterwards, however, videos of real children replaced the AI imagery, and it became apparent that the issue was far more serious and widespread than I had ever imagined.
TikTok has always forbidden children under 13 from operating accounts, and in June the UK government confirmed that from spring 2027, under-16s will be banned from certain social media. But neither of these measures prevents parents from sharing content of their own children, regardless of their age.
Featuring cute child models, “sassy” tweens, and toddlers living their chaotic little lives, videos shared by parents on TikTok are posted for the benefit of family, friends, or in chasing that elusive viral hit. There is also the promise of profit; successful child-influencer accounts have millions of followers and can make hundreds of thousands of pounds through brand partnerships and monetisation.
Not everyone agrees with using children for clicks, however. A 2022 report from the then Department for Culture, Media and Sport on influencer culture highlighted increased concern for the welfare of the children involved, who often cannot consent to their images being shared publicly and have no option to opt out. Last year, researchers at Essex University developed the depressingly named “‘Children in Content’ Digital Safeguarding Toolkit”, which advises parents on the best way to safeguard their lucrative offspring. The toolkit makes only one reference to sexual exploitation, advising parents not to share images of their children dressed (or undressed) in ways which could be digitally manipulated.
AI-generated imagery is clearly popular with TikTok users seeking CSAM and the accounts sharing AI content have huge audiences, but the majority of the 176 accounts I uncovered also use images of real children. Downloading videos innocently shared to TikTok by parents, such users then clip them, recaption them to appeal to their audience (for instance, adding a hashtag like #fatherandson) and repost them on their own profiles.
The wrestling video which led me into this investigation is one of the most popular videos shared by these accounts. I identified the father featured in the footage through an image search and reached out to him by email.
The 47-year-old owner of a construction company in the United States did not respond to my request for an interview. Public records show, however, that he has never been charged with or accused of any child abuse offences. The content on the social media accounts of both him and his three children (now in their late teens) indicates a healthy, close relationship. The video appropriated by the CSAM TikToks is no longer visible on the man’s accounts.
It may well be that he removed the original video after it became something of a beacon for TikTok users seeking CSAM. Tracking followers of the accounts who shared this clip, I found that multiple users had located original videos used in other clips and descended upon their comment sections. The result was a deluge of disturbing interactions on various videos featuring real children and often posted innocently by kids themselves on their own accounts.
Tony (as I will refer to him) is a Mexican boy who appears to be about 11 years old. His TikTok account has just over 2,000 followers and his profile features more than 500 videos of him dancing, playing with younger siblings and other content typical for his age.
Most of his posts get between 200 and 600 views, but two videos which show him dancing shirtless have more than 20,000 views each, have been downloaded hundreds of times and received thousands of comments from users who appear to be adult men. Sharing heart emojis, referring to him as their “beautiful baby” and sharing their Telegram handles for “trades”, I found only one commenter noting (with concern) that the child was alone and unsupervised.
On a different account, a young Russian girl I’m calling Varya, who looks to be between 11 and 13 years old, shared a video of herself dancing in front of the mirror in a lift. Wearing a rolled-up vest top and jeans, even the filter she used could not hide her age. As with Tony, commenters paid little mind to her youth while remarking on her face and body.
“Hi beauty, show me more of you,” wrote one, while another posted “jolies pointes” (French for “pretty nipples”). Just like Tony’s videos, this clip had significantly more views than Varya’s other posts—almost 54,000. When I reported these comments to TikTok, the system told me that the commenters had not broken any rules. The children themselves did not respond to the comments, but this kind of online abuse can lead to what psychologists at the University of Edinburgh have termed “a prolonged cycle of anxiety, threat, and re-victimization”.
Given that the commenters were using private TikTok accounts and anonymous Telegram profiles, there was no way of identifying the people behind them. Commenters on other videos I came across were less careful however and, via open-source investigation and image searches, I was able to identify 45 men in 28 countries including the UK, Canada, France, Indonesia, Venezuela and the US who were commenting on children’s videos and engaging with TikTok accounts seemingly promoting CSAM Telegram channels.
Ranging in age from mid-twenties to mid-eighties, these commenters follow accounts posting a combination of AI-generated content, clipped videos of real children, and actual kidfluencer accounts. Their TikTok comments run the gamut from grandfatherly affection to declaring that videos of little girls with AI-generated orgasmic facial expressions, posted by some of the accounts I identified, are “beautiful”, and most of these 45 have posted comments which indicate that they are searching for CSAM.
It would be easy to assume that the sort of men who end up commenting inappropriately on underage TikToks are loners, whose entire lives are lived in the dark corners of the internet. The truth is more complex. Through open-source investigation techniques I was able to find out their full names, social media accounts and websites for the companies where they worked. They comprised a broad cross-section of society, from unemployed men with learning disabilities and mental health issues to middle-class professionals with families, and retirees.
Seventy-five-year-old JC is a retiree living on the US West Coast. He smiles in his TikTok profile photo, and another TikTok post shows a recent, blurred selfie from a webcam. A follower of multiple social media accounts that share videos of young boys (some of which belong to the boys themselves, and some of which are part of the CSAM network), he has referred to AI images on TikTok as “candy” and commented “spank me for loving this” on an AI video of a pre-pubescent boy walking in a stream. On Facebook he has commented on posts of real children, telling a mother who shared a video of her 15-year-old son: “I love your boy.” Videos posted to his own TikTok profile include blurry shots of his genitals and memes declaring him to be a “crotch sniffer”.
A search via the Megan’s Law website—a public database which provides information about sex offenders living in California—confirmed that JC has never been charged with offences against children. When I reported his accounts to TikTok, Facebook and Instagram, all insisted that he had not broken any rules or done anything inappropriate—a view which was not shared by multiple anonymous Instagram users.
But even reporting the accounts of the other men I identified who are convicted sex offenders, I received the same response from these platforms. RT and RM both live in the US Midwest and appear on their state’s sex offender registry. RT is in his early 50s, and a combination of image and records searches revealed him to be a habitual felon. First convicted in 2009 for third-degree sexual conduct with a child under 13, RT was given a prison sentence of six to 15 years. There is limited information on when he was released but, in 2023, he was back in court and pleaded guilty to a firearms offence committed in 2021.
RT’s TikTok account is private but his comments on other posts can still be seen. They include affectionate remarks and emoji hearts under videos of young boys, plus an interest in children wearing nappies. TikTok has not removed his account because the company says that it does not break any of its rules.
The same is true for RM, a well-presented man in his early thirties, whose TikTok account shares simple to-camera chats from his car. In 2008, he was convicted of attempted third-degree criminal sexual conduct but entered a guilty plea which meant that he avoided prison. But following one of the CSAM-related accounts I uncovered, I found comments by RM which show that he cannot join that account’s Telegram group because he is “banned from
the platform”.
As part of this investigation, I reported both men to local law enforcement. While it is illegal in both the UK and US to make sexual comments directly to children online, there is little to prevent these men from making such comments on videos of children that have been shared by adults. There are also no laws to stop any of the accounts in this investigation from following kidfluencers or, as one has, reposting numerous publicly shared videos featuring toddlers defecating in their nappies, essentially amassing a huge collection of such material.
Currently, the only way to prevent this from happening is for parents to block such users (a difficult task for popular accounts with thousands of new comments each day), or to set their accounts to private (which limits their reach and ability to monetise, hence disincentivising many).
None of the kidfluencer parents I contacted whose content had been misused by the CSAM accounts responded to my request for an interview, but some have made their profiles private since the start of this investigation.
A growing number of adults recognise the dangers of sharing their children’s lives in public. One such man is Sheridan, 47 years old and the father of two, who works in the media. He has forbidden his children, both under 10, from having iPads or other devices and he posts as few images of the children as possible on social media.
Over the phone, he explains that he was “terrified [his children] would see something violent or totally inappropriate” and would “rather give them a packet of cigarettes and a lighter and say ‘here, play with these’, than let them go online for 20 minutes unsupervised”. But he is also concerned about how unaware other adults can be about the internet: “Some [friends and family] who are slightly older than me habitually share pictures of their kids on Instagram”. These relatives were simply posting what they saw as cute or interesting images, oblivious to the ways in which content could be misused.
The network uncovered in this investigation “is part of a major threat that the NCA [National Crime Agency] is aware of and is working on,” Derek Perkins, a visiting professor of forensic psychology at Royal Holloway University of London, tells me over Zoom. The NCA’s major concern, he adds, is “the number of 14- to 20-year-old males who are getting drawn into these kinds of things, eg animal cruelty, self-harm, and CSAM”.
Research shows the harm done by CSAM is often greater than that done to victims of in-person sexual abuse. This is because once CSAM is out there, it is there forever
The NCA is working on ensuring the wider public know about these online harms, but the experts I spoke to agreed that the ultimate responsibility lies with the platforms. “It is deeply disturbing that photos innocently shared by families to celebrate key moments in a child’s life are being used for something so sinister,” Rani Govender, associate head of policy for child safety online at the National Society for the Prevention of Cruelty to Children, tells me. “Every image or video shared on social media contributes to a permanent digital footprint, so parents and carers should think carefully before publicly posting snapshots of their child’s life.”
Research shows the harm done by CSAM is often greater than that done to victims of in-person sexual abuse. This is because in-person abuse “is contained in time and place. Once CSAM is out there, it is there forever,” says Perkins. Some people dismiss CSAM as “only photographs”, but he challenges this idea. “As far as victims are concerned, this is a lifelong problem.”
The existing legislation against online harms—the Online Safety Act, the ban of under-16s from social media—is clearly insufficient to tackle the proliferation of CSAM on platforms like TikTok. Perkins suggests the solution should involve “a mixture of education, regulation and legislation”. This still leaves us in something of a quandary. For the government to legislate against parents sharing images of their children online would be overreach. Like it or not, we live in a digital society. For those living far from family and friends, online interactions can sometimes be the only way to keep in touch. And prosecuting parents for sharing images of their children online would be the ultimate form of victim-blaming. We cannot blame parents for being convinced by strategically developed algorithms that social platforms are safe.
The solution must, therefore, involve legislating against the platforms themselves. To create a law which prevents platforms from monetising content featuring under-18s would lessen the appeal of “children as content”, and would potentially limit the number of parents willing to post images of their children online. Platforms must also face sanctions when their safeguarding measures are easily bypassed, and their own automated systems are incapable of detecting a threat.
When I asked the Home Office about legislating in this manner, it said that, “child sexual abuse material is illegal, regardless of whether it is AI-generated or depicts a real child, and platforms must proactively identify and remove it under the Online Safety Act,” noting that Ofcom, the regulator, is already investigating Telegram. It added that “under the Crime and Policing Act, anyone who runs, administers or moderates websites dedicated to sharing this content faces up to 10 years in prison.” The Home Office said it is “committed to giving law enforcement the powers they need to keep pace with criminal use of emerging technologies”.
A spokesperson for TikTok said that: “TikTok has zero tolerance for this abhorrant [sic] content and when found, we remove it, ban the accounts, and report the cases to NCMEC [the US National Centre for Missing & Exploited Children]. We invest in advanced moderation technologies, which help us take down 99 per cent of violative videos before they are ever viewed, and deep partnerships with global safety experts.”
While my investigation dismantled one CSAM network, TikTokers upload thousands of new videos every day, showing millions of viewers their children at rest, at play and at their most vulnerable. Since approaching TikTok for comment, all of the accounts that its in-app system failed to recognise as problematic have been removed. But as parents immortalise precious memories, others may yet be misappropriating them.