Pan‑EU Deepfake Ecosystem Enables Three‑Click Attacks on Women MPs

“Three clicks” can be enough: how a pan‑EU deepfake ecosystem is targeting women politicians

According to Benjamin Shultz’s analysis, as summarized by WIRED (Matt Burgess, Sep 14, 2026), researchers examined around 160 domains that host or facilitate nonconsensual sexual content and deepfake tools. Shultz compiled more than 5, 800 national members of parliament from all 27 EU countries in July and reports that at least 138 women MPs from 22 EU countries “appear or are mentioned” on those sites, compared with nine male MPs. Shultz’s calculation, as reported by WIRED, finds women MPs are “33 times more likely” to be targeted by this deepfake ecosystem.

Those figures are alarming and they come with important limits. The dataset, the domain list, and the exact matching methods behind the 33× figure have not been published alongside the summary reporting. Treat the numbers as strong directional evidence of a systematic, gendered problem while we press for fuller methods and archived evidence.

How these sites actually work

Start with an official headshot and a short bio. Add links to social profiles or contact details. Many pages include a direct gateway to a “nudifier, ” a service that claims to generate synthetic nude images from supplied photos, or instructions for using such tools. Some domains host explicit images. Others act as SEO‑driven index pages that list names and photos and point users toward generation tools or paywalled markets.

“It has all the images, all the information, and a direct link to the tool, and in three clicks you can generate.”, Benjamin Shultz

The distinction matters. A gateway page that lists a target and links to a nudifier can enable repeated abuse without ever hosting the explicit file itself. As Shultz puts it, “That’s just as bad as actually hosting the content.” Henry Ajder, who has tracked deepfakes since 2018, describes the whole setup as business‑like, “These platforms are designed to run like businesses. The whole infrastructure is set up to do this at scale with ease.”

Why this is a political-security problem

The research summarized by WIRED aligns with longstanding evidence that nonconsensual sexual imagery and synthetic sexual content disproportionately harm women. Public women, including politicians, carry extra risk because their official portraits and biographies are already public and SEOable. Dutch MPs quoted in the coverage emphasize the emotional and career harms.

“Deepfake porn is part of a much bigger trend of online hate and intimidation against women and female politicians, ”, Suzanne Kröger, Dutch MP.

Researchers and MPs interviewed in the reporting point to two linked dangers: immediate psychological and reputational damage to a targeted person, and a longer‑term chilling effect that can discourage women from running for or remaining in public office. Platforms and law enforcement have taken down some sites, but removals without systemic fixes are often temporary.

What has been done so far, and what remains unsettled

WIRED’s piece places Shultz’s findings in a patchwork of responses: journalistic investigations that have unmasked some site operators; reported takedowns tied to U.S. measures (the “Take It Down Act” is cited in the coverage as having been used in reported takedowns of major deepfake websites); and policy moves in the UK and EU to limit “nudify” services. WIRED also notes that at least half a dozen of the domains in Shultz’s sample have recently been removed from the web.

Historical context: researchers trace the first widespread wave of AI‑created deepfakes to the end of 2017, when face‑swap porn began circulating widely online. Since then, tools and workflows have become easier to use and more accessible, which helps the ecosystem scale quickly.

Methodology gaps to verify

The headline numbers come from Shultz’s dataset as summarized by WIRED. Before treating the absolute counts and ratios as definitive, confirm the following with the researcher or publisher:

  • Full domain list (or archived screenshots) for the ≈160 domains cited.
  • Exact date range and the year for “compiled in July, ” and when the domain crawl(s) were run.
  • Source and construction of the “more than 5, 800 members of parliament” roster and how duplicate names/roles were handled.
  • Clear definition of “appear or are mentioned” (image match vs. name/biography mention vs. profile page) and the operational thresholds used.
  • Matching methodology: face‑match tools, confidence thresholds, human verification steps, and estimated false‑positive/false‑negative rates.
  • The math behind “33 times more likely”: numerator and denominator per gender, and whether the ratio adjusts for the gender balance across parliaments.
  • Evidence for the claim that “at least half a dozen” domains were recently removed (Wayback snapshots, WHOIS/registry records, or takedown notices).
  • Source documentation tying specific takedowns to particular laws or enforcement actions (for example, claims about the Take It Down Act).

What campaigns, platforms and security teams should do now

Treat these findings as an operational risk and add concrete steps to your security playbook. Focus on detection, rapid removal, support for victims, and pushing for structural fixes that reduce repeatable abuse.

  • Build a rapid‑response removal playbook. Define roles, escalation paths, legal contacts, and a short roster of platform notice channels (platform safety centers, expedited DSA notice channels where applicable). Maintain templates for takedown notices and preserve forensic evidence (screenshots, archived URLs, timestamps).
  • Order of operations for responses. Detect, document, notify platforms and web hosts, publish a concise factual statement if needed, pursue legal or forensic action. Keep public messaging calm and focused on support and facts; avoid amplifying the manipulated content.
  • Pre‑register and publish authoritative assets. Publish higher‑quality official portraits and metadata and register provenance when possible. Standards like C2PA allow originators to embed provenance metadata. That helps platforms prioritize originals, but it only works if originators opt in and platforms honor the metadata.
  • Monitor gateway pages and SEO listings. Scan for index pages that list names and link to generation tools. These pages act as accelerants even when explicit images aren’t hosted. Add a weekly check of indexed pages for senior staff and candidates.
  • Train spokespeople and staff. Prepare short, factual responses and Q&A that emphasize support, removal actions taken, and steps for the individual’s safety. That reduces the viral advantage attackers seek.
  • Support victims and document harms. Connect affected people to counseling, legal help, and civil‑society organizations that specialize in image‑based abuse. Detailed documentation helps with takedown processes and, if pursued, criminal or civil cases.
  • Push for targeted policy and platform accountability. Bans or restrictions on “nudify” services can help, but they must be paired with platform enforcement, cross‑border cooperation, and technical mitigations. Without that, operators frequently rehost or move to private channels.

What journalists and security teams should ask the researcher

  • Can you share the domain list or provide archived evidence for a representative sample?

    If public sharing risks exposing victims, ask for time‑stamped screenshots or aggregated tables that can be independently verified.

  • When exactly was the MP roster compiled and which source lists were used?

    Request the compilation date (month/year), the official sources used, and how duplicates or name variants were resolved.

  • How did you define and measure “appeared or are mentioned”?

    Get clarity on whether that includes image matches, name mentions, profile pages, or archived links to removed content, and which were counted as “targets.”

  • What face‑matching and verification processes were used, and what are the estimated error rates?

    Ask for tooling, confidence thresholds, and any human review protocols used to reduce false positives.

  • Show the math behind the “33×” figure.

    Request the numerator/denominator values, and whether the ratio adjusts for the underlying gender distribution among MPs.

Key questions, and short, honest answers

  • How many EU national MPs were affected?

    According to Benjamin Shultz’s analysis, as summarized by WIRED (Matt Burgess, Sep 14, 2026), at least 138 women MPs from 22 EU countries “appear or are mentioned” on a sampled set of around 160 domains; nine male MPs were referenced. Those figures come from Shultz’s dataset as reported by WIRED and should be verified against the underlying methods and domain list.

  • Are women targeted more than men?

    Shultz’s calculation, as reported by WIRED, finds women MPs are “33 times more likely” to be targeted in the sampled ecosystem. That headline ratio indicates a large gender skew in the sample, but the exact multiplier depends on the sample frame, matching rules, and denominators, so it needs independent verification.

  • Do these sites host explicit deepfakes or just link to tools?

    Both. The ecosystem includes hosted explicit content, archived/indexed pages for removed content, and database‑style gateway pages that link to nudifier tools, the last can enable new abuse even when explicit files aren’t directly hosted.

  • Have takedowns worked?

    Investigations and enforcement have removed some domains, WIRED reports at least half a dozen recent removals in Shultz’s sample, and earlier removals reportedly reduced depictions of some U.S. politicians. However, removals are often temporary unless paired with broader policy, technical and cross‑border enforcement efforts.

  • What policy levers exist?

    Platform enforcement, targeted legislation criminalizing nonconsensual image‑based abuse, and proposals to restrict “nudify” services are all in play (the EU and UK are cited as planning action, and U.S. measures like the Take It Down Act have been invoked in reported takedowns). Cross‑border enforcement and the ease of rehosting remain major challenges.

Final, practical observation

The ecosystem described by Shultz and reported by WIRED combines low‑cost synthetic‑image tools, indexing pages that make targets discoverable, and commercial‑style marketplaces. That mix makes reactive takedowns necessary but insufficient. Prevention, built on provenance, platform cooperation, faster notice‑and‑action, and victim support, is a better long‑term strategy. It requires investment and international coordination.

If you manage a campaign or defend reputations, treat this as an operational threat: verify whether your people appear on indexed gateway pages, add a weekly monitoring cadence, designate an escalation lead, and demand transparent methods and evidence from researchers who publish headline numbers. The infrastructure is already there; whether institutions finish the job of defending people is the next urgent question.