Ethics
Guardian investigation identifies infrastructure behind ClothOff deepfake app
A second phase of reporting traces the networks, payment systems and hosting services enabling non-consensual sexual deepfakes. The investigation reveals enforcement gaps across platforms, payment processors and law enforcement.
By Michael C ·

The Guardian's continued investigation into ClothOff, an application used to create non-consensual sexual deepfakes, has traced the infrastructure and human networks sustaining the service despite growing legal challenges and public outcry. The second episode of the inquiry reveals how the app operates across jurisdictions through distributed hosting, multiple payment channels and minimal age verification, creating accountability gaps that allow creators and distributors to evade detection. The investigation documents how victims discover their images online often months after creation, with limited recourse from platform operators or hosting providers who claim limited responsibility for user-generated content.
The app's technical architecture distributes processing across multiple servers in countries with varying legal frameworks governing deepfakes and non-consensual imagery. According to the investigation, ClothOff's operators have shifted hosting locations multiple times following legal pressure, complicating efforts by law enforcement to serve notices or obtain cooperation. Payment processors have terminated relationships with associated accounts, but the investigation found evidence of alternative payment methods resuming service, suggesting operators adapted revenue streams rather than ceased operations. The mechanism for collecting fees from users remains obscured, with transactions routed through intermediaries that mask the ultimate recipient. The Guardian investigation documents the reporting behind this account.
A central question for platform accountability involves the responsibilities of hosting providers, payment networks and downstream services. The investigation examined whether these intermediaries conducted due diligence on customers or responded to reports of abuse. Most companies contacted declined to comment on specific incidents or stated that they rely on user reports and legal process to identify problematic content. Payment processors typically stated they terminate merchants upon discovering illegal activity, but the investigation found that re-registration under different business entities has allowed resumed transactions. Hosting providers similarly claimed they remove content upon receiving valid legal demands but often lack mechanisms for victims or researchers to report abuse directly.
Age verification and exploitation risks
The investigation identified minimal age safeguards within the app's user onboarding process. According to reporting, ClothOff collects no government-issued identification and relies on self-reported age declarations. This gap creates risk for the creation and distribution of deepfake imagery depicting minors, which constitutes child sexual abuse material under law in most jurisdictions. The National Center for Missing and Exploited Children has documented cases involving deepfakes, though the organization reports that many such cases go unreported by platforms or are reported too late to preserve evidence. Researchers and advocates have urged platforms and payment processors to implement stronger age verification systems, particularly for services that generate or distribute sexual content.

The Cyber Civil Rights Initiative and similar organizations have released resources documenting how victims can report non-consensual deepfakes and preserve evidence. StopNCII.org, operated with support from major platforms and payment companies, provides a database and reporting mechanism for non-consensual imagery. However, the investigation found that deepfake-specific reporting workflows remain inconsistent across platforms, and many victims report confusion about where to file complaints or whether their reports result in content removal. Law enforcement agencies contacted during the investigation indicated they receive reports but face challenges in identifying perpetrators across international jurisdictions and in securing cooperation from companies reluctant to preserve or hand over user data without formal legal process.
Enforcement gaps and policy considerations
The investigation reveals systemic enforcement gaps that ClothOff and similar services exploit. Payment processors operate detection systems designed primarily to identify fraud and sanctions violations rather than non-consensual sexual content. Hosting providers stated they rely on intellectual property claims, court orders or law enforcement requests to remove content, meaning that non-consensual deepfakes persist unless a victim or authorized party initiates a formal complaint. Multiple jurisdictions have introduced or proposed legislation criminalizing the creation and distribution of non-consensual deepfakes, but enforcement remains limited by investigative capacity, cross-border jurisdictional questions and the difficulty of attributing content creation to specific individuals when tools are widely distributed. For broader context, Cyber Civil Rights Initiative outlines the relevant standard or institution.
Experts consulted by the investigation noted that platform-based content moderation systems, including machine learning tools designed to detect non-consensual imagery, have achieved limited effectiveness with deepfakes because the images are computationally generated rather than photographs. The NIST AI Risk Management Framework and similar guidance documents have recommended that organizations deploying synthetic media technologies conduct impact assessments and implement safeguards against misuse, yet adoption remains uneven among commercial vendors. Some researchers argue that distributing deepfake-generation tools without built-in restrictions on sexual content creation represents a significant gap, as it places responsibility entirely on downstream platforms and enforcement rather than on tool developers themselves.

The investigation documents how victims experience compounding harm when their attempts to remove non-consensual deepfakes encounter bureaucratic obstacles or indifference from service operators. Multiple individuals interviewed reported discovering their images shared across multiple platforms and had to file separate reports to each site. Some stated that platform responses were delayed or that content reappeared after removal. One victim described the experience as dehumanizing and noted that the reputational harm extended to professional and personal relationships when others encountered the false imagery. These accounts underscore how enforcement and platform accountability directly affect individuals' ability to move beyond violations.
International coordination on deepfake regulation remains nascent. The OECD AI principles, adopted by member states and reflected in emerging regulatory frameworks like the EU AI Act, call for transparency, human agency and accountability in systems using artificial intelligence. However, most frameworks address AI systems deployed by organizations rather than tools distributed to millions of users. The investigation found that law enforcement agencies lack established protocols for investigating cross-border deepfake cases and that companies have no consistent obligation to preserve evidence pending investigation. Experts interviewed by the Guardian suggested that addressing the infrastructure enabling non-consensual deepfakes will require coordinated action from law enforcement, regulators, payment processors and hosting providers, combined with technology development to detect and prevent misuse at the point of tool creation rather than only at distribution stages.
Topics: deepfakes, sexual abuse, platform accountability, investigation, digital rights