This text is the results of a collaboration with TjekDet, Denmark’s fact-checking media outlet, Danish newspaper Politiken, and the Canadian Broadcasting Company.
Warning: This text discusses non-consensual sexually specific content material from the beginning.
MrDeepFakes billed itself because the “largest and most user-friendly” platform for superstar deepfake pornography. The web site, which was visited hundreds of thousands of occasions each month, hosted virtually 70,000 specific and generally violent movies, which had collectively been considered greater than 2.2 billion occasions.
They present largely well-known girls whose faces have been inserted into hardcore porn with synthetic intelligence – and with out their consent.
Within the background, an energetic group of greater than 650,000 members shared recommendations on find out how to generate this content material, commissioned customized deepfakes, and posted misogynistic and derogatory feedback about their victims.
Supply: MrDeepFakes
For years, the web site has been shrouded in thriller, current in a authorized gray space and concealing the identification of those that management it. Till now.
Bellingcat, in collaboration with Danish shops Tjekdet, Politiken and the Canadian Broadcasting Company (CBC), has performed an investigation to disclose the identification of a key administrator behind MrDeepFakes.
David Do is a 36-year-old Canadian pharmacist who, primarily based on open supply info, lives an unassuming and respectable life within the suburbs outdoors of Toronto. Images and movies posted on-line present him with household, mates and colleagues. The college graduate has a well-paying job in a public hospital and drives a brand new Tesla.
However Do has been dwelling a double life: in secret, he’s probably the most distinguished determine recognized to have had management over the administration of MrDeepFakes. He was additionally an influential member of its rising on-line group, producing his personal deepfake porn and aiding customers who need to make their very own.
On-line posts present Do is a technically minded particular person with a long-standing curiosity in creating and distributing grownup content material, and supply an perception into efforts to obfuscate his identification.
We recognized Do by cross-referencing information from large credential leaks, that are publicly out there through breach databases. A sequence of burner emails, IP addresses, repeated usernames, and a novel password reveal a greater than decade-long digital path that allowed researchers to hyperlink him to MrDeepFakes.
Bellingcat, Tjekdet, Politiken and CBC have despatched Do a number of requests for remark since late March however didn’t obtain a response as of publication. Final month, the CBC hand-delivered correspondence to Do setting out the findings of this investigation, however he declined to remark.
Shortly after, Do’s Fb web page and the social media accounts of some members of the family have been deleted. Do then travelled to Portugal together with his household, in keeping with critiques posted on Airbnb, solely returning to Canada this week.
On Sunday, the MrDeepFakes website was shut down. “A essential service supplier has terminated service completely,” a discover on the platform says. “We is not going to be relaunching. Any web site claiming that is pretend.”
CBC approached David Do once more on Monday however he refused to reply questions on his involvement with MrDeepFakes. “I don’t need to be recorded please,” he stated. “I’ve to go. I’m busy proper now.”
What’s Deepfake Porn?
Deepfake pornography is using synthetic intelligence to create non-consensual, sexually specific photos and movies. Analysis exhibits that 99 per cent of victims are girls.
Actress Jenna Ortega, singer Taylor Swift and politician Alexandria Ocasio-Cortez are amongst a number of the high-profile victims whose faces have been superimposed into hardcore pornographic content material.
However the expertise can be getting used on people who find themselves not within the public eye.
A 2024 survey discovered that at the least one in 9 highschool college students knew of somebody who had used AI expertise to make deepfake pornography of a classmate and The New York Occasions has reported that colleges throughout the US have been coping with incidents of youngsters making deepfakes of their feminine classmates.
Adam Dodge, from EndTAB (Finish Know-how-Enabled Abuse), stated it was turning into simpler to weaponise expertise in opposition to victims. “Within the early days, despite the fact that AI created this chance for individuals with little-to-no technical talent to create these movies, you continue to wanted computing energy, time, supply materials and a few experience. And now you want little or no of these issues,” he stated.
“It’s actually point-and-click violence in opposition to girls. A few of these apps solely require one photograph of the goal, and also you, on the app, actually use your finger to tug the lady’s face right into a video after which simply launch it and AI does the remainder, enhancing that sufferer into the photograph. And you then press play and it now seems that the sufferer from the photograph is partaking in intercourse acts.”
Dodge stated the MrDeepFakes website had grown since 2008 and added options that have been sometimes utilized by common companies to advertise an air of legitimacy. “ It’s unimaginable and I’m incredulous that the positioning has been allowed to outlive this lengthy,” he instructed Bellingcat.
“That is sexual violence, and it’s as dangerous as every other type of sexual violence in our opinion. I’ve talked to psychological well being professionals who work with rape and trauma survivors, and so they analogise it to a lady who’s sexually assaulted whereas unconscious or drugged, and it’s filmed, after which they’ve to observe it later.
“They don’t have any reminiscence of this occurring to them. However the easy act of watching it’s deeply traumatic and that’s what this expertise manufactures. And the permanency and the general public nature of it are the 2, I might argue, most powerfully traumatic issues that victims typically expertise.”
Governments world wide are scrambling to sort out the scourge of deepfake pornography, which continues to flood the web as expertise advances. In Canada, the distribution of non-consensual intimate photos is unlawful, however this isn’t broadly utilized to deepfakes. Canadian. Prime Minister Mark Carney pledged to go a legislation criminalising the manufacturing and distribution of non-consensual deepfakes throughout his federal election marketing campaign.
Within the US, laws varies by state, with about half having legal guidelines in opposition to deepfake pornography. The US Congress final month handed the Take it Down Act, which criminalises the distribution of non-consensual deepfake pornography on the federal stage. President Donald Trump is anticipated to signal the invoice into legislation.
The EU doesn’t have particular legal guidelines prohibiting deepfakes however has introduced plans to name on member states to criminalise the “non-consensual sharing of intimate photos”, together with deepfakes. Member states is not going to enact these legal guidelines till 2027. Within the UK, it’s already an offence to share non-consensual sexually specific deepfakes, and the federal government has introduced its intention to criminalise the creation of those photos. Australia handed new legal guidelines to fight sexually specific deepfakes final 12 months.
‘Pretend It Until You Make It’
The identification of the individual or individuals answerable for MrDeepFakes has been the topic of media curiosity for the reason that web site emerged within the wake of a ban on the “deepfakes” Reddit group in early 2018.
However the porn website’s internet hosting suppliers have bounced across the globe and premium memberships may be purchased with cryptocurrency, which have made it nearly not possible to hint possession.
Supply: MrDeepFakes
Adam Dodge, the founding father of EndTAB (Finish Know-how-Enabled Abuse), stated MrDeepFakes was an “early adopter” of deepfake expertise that targets girls. He stated it had developed from a video sharing platform to a coaching floor and market for creating and buying and selling in AI-powered sexual abuse materials of each celebrities and personal people.
“Our digital world is admittedly good at empowering individuals who need to do hurt by permitting them to stay nameless whereas concurrently making it virtually not possible for victims to unmask them,” he stated.
In January, Bellingcat, in collaboration with the German YouTube channel STRG_F, examined the businesses behind two apps used for creating deepfakes that it marketed prominently on its homepage.
For this investigation, researchers performed a forensic evaluation of the boards on MrDeepFakes’ web site. The boards are a digital market the place members fee deepfakes and commerce recommendations on making movies with the identical expertise that’s used for creating revenge porn. Members referred to victims as “bitches”and “sluts”, and a few argued that the womens’ behaviour invited the distribution of sexual content material that includes them.
Movies posted to the positioning are described strictly as “superstar content material”, however discussion board posts included “nudified” photos of personal people. Members who request deepfakes of their “spouse” or “companion” have been directed to message creators privately and talk on different platforms, equivalent to Telegram.
A search of the boards returned two accounts for MrDeepFakes “employees members”. One joined in March 2019 and can be listed as a “moderator”. The opposite joined in February 2018 and can be listed as an “administrator” (two further administrator accounts, created in 2018 and 2021, weren’t listed as employees members, and one now-defunct account beforehand tagged as employees and moderator was created within the 12 months after the positioning was arrange).
Researchers started by analysing the profile. The dpfks bio contained little figuring out info, however an archive from 2021 exhibits the account had posted 161 movies which had amassed greater than 5 million views. It earned the badge of “Verified Video Creator”.
Posts on the boards doc dpfks’ involvement as a creator and chief in the neighborhood. Archives present dpfks posted an in-depth information to utilizing software program that creates deepfake porn, printed web site guidelines and content material tips, marketed for volunteers to work as moderators, and gave technical recommendation to customers.
Dpfks’ posts carried the tagline: “Pretend it until you make it.”
In a 2019 archive, in replies to customers on the positioning’s chatbox, dpfks stated they have been “devoted” to enhancing the platform. “There’s a cause why we’re the largest deepfake website. I care concerning the group and educating others.
“I don’t suppose different website homeowners care sufficient to make their very own deepfakes, and maintain uptodate [sic] with it. My first few deepfakes have been s**t too, the extra you make, the higher you get.”
David Do’s Hyperlinks to MrDeepFakes
Pirated Motion pictures to Deepfake Porn
David Do retains a low profile underneath his personal identify, however photographs of him have been printed on the social media accounts of his household and employer. He additionally seems in photographs and on the visitor checklist for a marriage in Ontario, and in a commencement video from college.
Do’s Airbnb profile displayed glowing critiques for journeys in Canada, the US and Europe (Do and his companion’s Airbnb accounts have been deleted after CBC approached him on Monday). His dwelling tackle, in addition to the tackle of his dad and mom’ home, have each been blurred on Google Road View, a privateness characteristic that’s out there on request.
Within the late 2000s, whereas learning at college, Do was concerned within the creation of Xinoa (xinoa.internet), a warez discussion board. Do’s private Hotmail tackle, which incorporates his full identify, is seen in supply code as an admin contact for the positioning, archives from 2008 present.
The profile web page “ddo” is tagged because the “Root Admin” and “Xinoa Proprietor”, and lists a date of delivery matching that of Do. The profile consists of obtain hyperlinks to tv exhibits, one in every of which was accompanied by a remark about “examination week” in 2009, when Do was learning at college. This username can be just like Do’s Instagram profile (“ddo.jpg”), a hyperlink to which was included within the bio part of his Fb account underneath the identify “Doh Dave”. Each social media accounts have been deleted.
An account on an web advertising and marketing discussion board was registered utilizing a Xinoa administrator e-mail tackle, breach information exhibits. That account was linked to an IP tackle owned by the College of Waterloo, the place Do earned levels in biomedical science in 2010 and pharmacy in 2014, in keeping with Rocketreach.
The 2015 Ashley Madison information breach exhibits person “ddo88” registered on the courting website with Do’s Hotmail tackle and was listed as an “hooked up male in search of females” in Toronto. They described themselves as being of Asian ethnicity, 173 cm tall and weighing 66 kg. The breached profile was linked to a Toronto-based tackle and in addition contained a date of delivery, which matches Do’s delivery date in public information.
Xinoa would develop into the springboard for a extra refined operation.
In February 2018, when Do was working as a pharmacist, Reddit banned its virtually 90,000-strong deepfakes group after introducing new guidelines prohibiting “involuntary pornography”. In the identical week, MrDeepFakes’ predecessor website dpfks.com was launched, in keeping with an archived changelog.
An evaluation of the now-defunct area exhibits the 2 websites share Google analytics tags and back-end software program – in addition to a discussion board admin who used the deal with “dpfks”. Archives from 2018 and 2019 present the 2 websites redirecting or linking to one another. In a since-deleted MrDeepFakes’ discussion board submit, dpfks confirms the hyperlink between the 2 websites and guarantees the brand new platform is “right here to remain”.
“MrDeepFakes.com was previously dpfks.com and we opened our doorways shortly after the Reddit ban,” the 2018 submit stated. “I do know becoming a member of a brand new discussion board or group appears like beginning contemporary, and beginning over, however the group is small, and all of the necessary gamers will stick collectively. I promise to maintain this group working so long as I can, in order that the deepfake group doesn’t need to scramble and relocate once more.”
Later in 2018, in a submit on Voat, a defunct on-line message board just like Reddit, dpfks stated they “personal and run” MrDeepFakes. In response to a different person, dpfks refers to their life outdoors of working a porn web site. “I simply acquired dwelling from my day job,” the submit stated, “now again to this!” A few of dpfks’ earliest posts on Voat have been deepfake movies of web personalities and actresses.
Certainly one of dpfks’ first posts on the MrDeepFakes’ boards was a hyperlink to a deepfake video of online game streamer Pokimane. “This was my first deepfake,” dfpks wrote. Different targets included the American politician Alexandria Ocasio-Cortez, for whom dpfks shared a folder containing greater than 6,000 photos that could possibly be used to create deepfake pornography. After discovering she had been transposed right into a deepfake porn video final 12 months, Ocasio-Cortez instructed Rolling Stone that “digitizing violent humiliation” was akin to bodily rape and sexual assault.
One other goal of dpfks was American YouTube character Gibi_ASMR, who gained reputation on-line together with her ASMR (Autonomous Sensory Meridian Response) movies. Dpfks created and shared pornographic deepfakes of the YouTuber on the MrDeepFakes boards. In a press release printed by EqualityNow in 2021, she stated: “They’re working this enterprise, profiting off my face doing one thing that I didn’t consent to, like my struggling is your livelihood. It made me actually mad, however once more, there was nothing I might accomplish that I simply needed to go away it.”
In 2018, dpfks posted a two minute deepfake video of an Academy Award-winning American actress with the outline: “[Name omitted] doesn’t do porn, however on this pretend video she is totally bare together with her legs unfold within the air. Watch her face … whereas she struggles to take it.”
Discussion board posts underneath varied aliases match these present in breaches linked to Do or the MrDeepFakes Gmail tackle. They present this person was troubleshooting platform points, recruiting designers, writers, builders and search engine optimisation specialists, and soliciting offshore providers.
The username “AznRico” was generally related to Do’s e-mail account and could possibly be discovered throughout a number of postings on-line. In 2009, years earlier than MrDeepFakes was launched, this now-banned person posted to an web advertising and marketing discussion board discussing on-line money-making methods, together with the monetisation of video visitors.
AznRico additionally posted on an auto lighting discussion board in 2009 to ask for recommendation about fixing headlights for a automobile in Canada – a 2006 Mitsubishi Lancer Ralliart. In one other thread on the identical discussion board, AznRico uploaded a number of photos of the automobile, one in every of which was archived and contained metadata indicating that it was captured on a Sony Ericsson K850i.
In 2009, on a separate discussion board, AznRico stated he had this mannequin telephone and posted about troubleshooting the machine (that discussion board was topic to an information breach exposing David Do’s private Hotmail tackle and distinctive password).
Public information obtained by CBC verify that Do’s father is the registered proprietor of a pink 2006 Mitsubishi Lancer Ralliart. Whereas Do’s dad and mom’ home is now blurred on Google Maps, the automobile is seen within the driveway in two photos from 2009, and in Apple Maps imagery from 2019. CBC confirmed the automobile was nonetheless on the home final week.
In 2011, on a freelance job board, AznRico requested for assist constructing a video streaming plugin. This profile additionally listed that the person was primarily based in the identical Ontario metropolis the place Do’s dad and mom’ house is positioned. In 2018 – the identical 12 months MrDeepFakes was launched – AznRico requested for recommendation to repair sluggish load occasions on their porn website, which they stated obtained about 15,000 to twenty,000 guests a day. Breach information exhibits this account was linked to Do’s private Hotmail tackle.
In a single discussion board submit from January 2020, person “dj01039” complains that PayPal had restricted their “stealth account”, which was used to “promote digital items” (PayPal was intermittently out there as a fee possibility on MrDeepFakes). The username dj01039 matches the abbreviation of an e-mail tackle (davidjames01039@gmail.com) that was linked to a PayPal donation button on MrDeepFakes in December 2019.
In June 2020, on one other discussion board, a person with the identical alias (who later modified it to “ac2124”) stated their stealth account had been completely closed and needed to learn about entrance firms that would settle for funds on their behalf. The person described themself because the “webmaster of an grownup tube website” who takes a lower from creators who submit authentic porn movies, and in addition earns income from working adverts. By December 2020, ac2124 stated their web site was incomes between $4,000 and $7,000 a month.
Breach information additionally hyperlinks the MrDeepFakes Gmail to an account on help boards for Kernel Video Sharing (KVS), a business content material administration system, the place person “mongoose657” (previously dj01039) sought assist managing a video tube website. The discussions, from 2021 to 2024, have been per backend points encountered when working a big web site: storage options, ticket system failures, and outsourcing growth work.
On the grownup webmaster discussion board GoFuckYourself.com in 2020, dpfks (subsequently modified to “mjmango”) enquired about nameless debit playing cards, which have been marketed as permitting customers to withdraw money or pay for purchases anonymously. In 2021, mjmango responded to a different person’s enquiry about find out how to monetise tube websites.
In one other discussion board, ac2124 enquired about international locations to kind an offshore firm and expressed concern about “know your buyer” checks, that are utilized by the banking sector to substantiate the identification of their prospects. In a 2020 submit, ac2124 stated that they had determined to make a “dummy website/entrance” for his or her grownup website and enquired about on-line fee processing and “protected funds storage”.
In 2022, ac2124 sought recommendation for a Canadian citizen who operates an “grownup area of interest web site” and requested about “an organization setup that focuses on privateness”. The submit stated: “At a naked minimal, this individual shouldn’t be listed on any public registrar (as director, shareholder, UBO, and many others). Open to utilizing nominees, opening trusts, and many others. What are some setups, or jurisdictions that ought to be appeared into?” This person additionally requested particularly about establishing an organization within the British Virgin Islands or Cayman Islands, each secrecy jurisdictions.
In late 2023, mjmango left constructive suggestions for an grownup graphic designer under a submit from the designer containing a MrDeepFakes emblem. “Bought one other emblem just lately. As all the time nice communication and allowed a number of re-edits,” the remark stated. In March 2024, ac2124 posted about delays accessing a service that creates a “proxy” for a “high-risk web site” so it will possibly course of transactions from the web fee processor, Stripe.
In April 2024, Dutch outlet Algemeen Dagblad (AD) reportedly made contact with the proprietor of MrDeepFakes, who was anonymised of their subsequent reporting. AD reported that this individual claimed to have offered the web site, however didn’t present any proof to help this declare. Our investigation couldn’t verify whether or not the positioning was ever offered, and if that’s the case when.
David Do didn’t reply to a number of requests for remark about his involvement with MrDeepFakes.
Ross Higgins, Connor Plunkett, Beau Donelly, George Katz, Kolina Koltai and Galen Reich contributed to this text.
Bellingcat is a non-profit and the power to hold out our work depends on the type help of particular person donors. If you need to help our work, you are able to do so right here. You can too subscribe to our Patreon channel right here. Subscribe to our Publication and comply with us on Bluesky right here and Mastodon right here.