Feds Pull the Plug on CFAKE and SOCFAKE in First TAKE IT DOWN Act Domain Grab

DOJ seizes two deepfake nude sites that pulled tens of millions of visits a month, marking the first public test of the new federal statute.

ThreatVectr Newsdesk· 2 min read
Feds Pull the Plug on CFAKE and SOCFAKE in First TAKE IT DOWN Act Domain Grab
Share

The Justice Department seized CFAKE.com and SOCFAKE.com on Friday, the first publicly announced domain takedown under the TAKE IT DOWN Act signed in May.

Both sites hosted nonconsensual AI-generated nude imagery and video of women, including minors. Traffic was not small. CFAKE was pulling roughly 18 million visits a month and SOCFAKE around 9 million, according to figures cited by federal investigators. That is real-money traffic for ad networks and subscription processors, which is part of why these operations stick around.

Visitors now land on a federal seizure banner instead of the generator front end.

The TAKE IT DOWN Act criminalizes the knowing publication of nonconsensual intimate imagery, including synthetic content, and requires covered platforms to honor takedown requests within 48 hours. The 48-hour clock kicks in next May. The criminal provisions are live now, which is what gave DOJ the hook to move on domain registrars and hosting.

In practice, this is a registrar-and-DNS play, not a server raid. The sites themselves are almost certainly hosted offshore behind a CDN, and the operators are unnamed in the public filings. Expect mirror domains within days. That is the failure mode here: domain seizures are a speed bump unless they are paired with payment-rail and ad-network pressure, which is where these things actually die.

One thing the post-mortem will say is that the underlying generation stack is trivial to redeploy. Open-weight diffusion models, a scraped dataset of a target's social media, and a $200/month GPU box gets you back online. The economic moat for these sites is SEO and brand recognition, both of which the seizure does dent.

For platform and trust-and-safety teams, the practical read is this. If you operate a covered service — basically anything user-generated and public-facing — your notice-and-takedown pipeline needs to handle synthetic NCII claims by next spring, and the bar is 48 hours from a valid request. Your existing DMCA workflow is not it. DMCA assumes a copyright holder; TAKE IT DOWN assumes a depicted person, and the verification model is different.

The FBI's Washington Field Office ran the seizure. No indictments have been unsealed, which suggests the operator identification work is still in progress or the case is sealed pending arrests.

Worth watching: whether DOJ goes after the payment processors and ad networks that monetized this traffic, because that is where deterrence actually lives.

Operational takeaway: if your platform has any user-generated image surface, stand up a synthetic-NCII intake path now and document the 48-hour SLA before May, because the first enforcement actions will be precedent-setting.

© 2026 Threat Vectr