Child sexual abuse is exploding online. Tech’s best defenses are no match.

A new report argues there's more tech companies can do to stop child sexual abuse material from spreading online without sacrificing privacy.

silhouette of hands

In many cases, company safeguards are failing to keep pace with the evolving threat of child sexual abuse material.

Photo: Catherine Falls Commercial/Getty Images

Online child sex abuse material has grown exponentially during the pandemic, and tech's best defenses are no match against it, according to a new report on the threat facing countries around the world.

The report, published last month, was developed by the WeProtect Global Alliance, an NGO that represents nearly 100 governments as well as dozens of companies including giants like Apple, Google, Facebook and Microsoft in their efforts to stop the spread of child sexual exploitation. The report, which also includes a survey of 32 member-companies, found that not only is the sheer volume of child sexual abuse material, or CSAM, increasing, but it's growing more complex and capitalizing on tech's blind spots.

"The scale and rate of change is unprecedented," the report reads.

During the pandemic, global reports of suspected sexual child exploitation to the National Center for Missing and Exploited Children increased 106%, according to the report. That's while troubling trends like online grooming and livestreaming child sexual abuse for pay have grown. At the same time, companies and law enforcement officials are grappling with a rapid increase in "self-generated" content from kids, who may be sending images of themselves consensually to peers only to have those images circulated without their consent later on.

The report finds that while tech companies have come a long way toward addressing this problem over the last decade, in many cases their safeguards are failing to keep pace with the evolving threat.

"The scale of child sexual exploitation and abuse online is increasing. This sustained growth is outstripping our global capacity to respond," the report reads.

A 'perfect storm'

The COVID-19 crisis created a "perfect storm" for CSAM to proliferate online, the report argues. Children spent more time online than ever and offenders had reduced opportunities to commit offline abuses, which increased online demand for imagery.

Increases in reporting don't necessarily equate to an increase in volume, the report's authors caution, but they point to other recent trends that have also exacerbated the problem.

WeProtect's report included research that analyzed conversations in offender forums on the dark web and found that offenders use these forums to exchange best practices. More than two-thirds of the discussions were about technical tools for messaging, exchanging funds or storing content in the cloud. "They're talking about which social media platforms to use, they're talking about communication tools, they're talking about storage facilities," said Iain Drennan, executive director of the WeProtect Global Alliance. "There's that kind of community — in inverted commas — but that kind of exchange of information," he said.

The report also emphasizes the challenges in policing this content on a global scale. The internet makes it easy for offenders to exploit vulnerabilities in whichever country has the weakest technical and regulatory defenses, because it's just as easy to access a site hosted in the US as it is in Europe, Asia or anywhere else in the world.

In developing countries, the dramatic uptick in online adoption has outpaced those countries' ability to protect against these kinds of abuses, Drennan said. "The focus has previously been to get people online, and there's been amazing progress in that," he said. "But you're getting a situation where you don't necessarily have those specialized capabilities."

This is further complicated by the inherently global nature of CSAM. "This is a crime fundamentally where the victim could be in the Philippines, the offender could be in the United States, and they're using a platform that's headquartered in Finland. It's that kind of international dimension," said Drennan. To truly collect evidence or prosecute offenders that are overseas requires careful coordination with international entities like Interpol and Europol, or bilateral collaboration with other countries.

The report also points to an increase in "self-generated" sexual material over the last year. That includes imagery and videos that young people capture themselves, either because they were coerced, or because they voluntarily shared it with someone their own age, who then shared it more broadly without their consent. According to the Internet Watch Foundation, a UK-based non-profit that also works to stop child abuse online, there was a 77% increase between 2019 and 2020 in reports of self-generated material, a category of content that can be particularly difficult to police. "You can have a perfectly healthy consenting relationship between two teens, the relationship breaks up, one of them starts sharing it, then that gets into the internet," said Drennan. "And you've gone from something that was not harmful and that we don't want to criminalize in any way into something that's more problematic. And that's a real challenge for policymakers to try [to] address."

Safety by design

In addition to outlining the scope of the problem, the report also takes stock of what the tech industry has done so far to address it. In February and March of this year, WeProtect and the Technology Coalition, a group of tech companies working to fight child sex abuse on their platforms, conducted a survey of 32 companies and found that 87% of them are already using image-specific hash-based detection tools to automatically block known child sexual abuse material from their platforms.

And yet, far fewer companies actually contribute new material to existing hash databases. Only 26% of tech companies make their content classifiers available to other companies, the survey found, indicating a major lack of collaboration.

Sean Litton, the executive director of the Technology Coalition, said tech companies have a responsibility to share "hard lessons learned, to share technology, to share best practices, to share insights." Even if one platform is impenetrable to abuse — and none are — "that leaves all the other platforms for bad actors to exploit," he said.

While companies may be making progress on removing static images, the survey found that only 30% of companies surveyed are using classifiers to detect CSAM in videos. Just 22% of them are detecting this behavior in livestreaming, even as that medium has become a popular new frontier for CSAM.

That needs to change, the report argues. The report also suggests tech companies use techniques such as deterrence messaging, age-estimation tools and digital literacy training. These interventions can include showing users a message when they attempt to make searches for CSAM or using AI to scan a user's face and check their age.

Some regions, including Australia, are also pursuing an approach known as "safety by design," creating toolkits that tech companies can use to ensure their platforms are considering safety from their inception. "It's creating the technology in such a way that it's child-friendly, and children can't be harmed using it," said Litton. "And it's designing it specifically for children."

Safety or surveillance

The authors of the report advocate for more regulation to protect against online harms to children, as well as new approaches to encryption that would protect users' privacy without making CSAM virtually invisible. But many of the techniques for detecting CSAM come with serious privacy concerns and have raised objections from some of WeProtect's own member-companies.

Privacy experts, like the ACLU's Daniel Kahn Gillmor, worry that features like Apple's proposed child safety features — which WeProtect publicly supports, but which the company has put on hold — can open gateways to infringements on privacy and security. Apple proposed scanning users' iCloud accounts for known CSAM and submitting a report to NCMEC if the volume of material passes a certain threshold. "You want your information being read by the folks that's intended to be read by," Gillmor said. "You don't want whoever is hanging on to your backup to be able to dig into that and find information that you don't like."

Another proposed feature would scan iMessages on devices of children under 13 and alert their parents if they send or receive sexually explicit imagery. But privacy advocates say that could put vulnerable kids, including most prominently LGBTQ+ youth, at unnecessary risk.

Another concern is miscategorization. In a world where tech platforms use metadata to detect adults who may be grooming young people, what would that mean for, say, a teacher who's regularly in contact with students, Gillmor asked.

There's also the risk of mass surveillance in the name of protection, he argued. "If what we say to kids is, 'Here's your safety tool, and it's safe because someone is surveilling you,' we shouldn't be surprised if those kids become adults who equate surveillance with safety," Gillmor said.

Gillmor is careful to frame the conversation as surveillance versus security rather than privacy versus child safety, because he doesn't see the latter as mutually exclusive. "I view working for people to have effective privacy as also being a child-safety concern," he said.

Tech companies have a long way to go in making sure prevention and detection methods are up to speed and that their platforms provide protections without sacrificing security. But there's no neat and easy solution to such a complicated, multidimensional threat.

Drennan likens it to counterterrorism: "You put the big concrete blocks in front of the stadium — you make it hard," he said. While some perpetrators may slip through, "you immediately lose all of those lower-threat actors, and you can focus law enforcement resources on the really dangerous and high-priority threats."


Google is wooing a coalition of civil rights allies. It’s working.

The tech giant is adept at winning friends even when it’s not trying to immediately influence people.

A map display of Washington lines the floor next to the elevators at the Google office in Washington, D.C.

Photo: Andrew Harrer/Bloomberg via Getty Images

As Google has faced intensifying pressure from policymakers in recent years, it’s founded trade associations, hired a roster of former top government officials and sometimes spent more than $20 million annually on federal lobbying.

But the company has also become famous in Washington for nurturing less clearly mercenary ties. It has long funded the work of laissez-faire economists who now defend it against antitrust charges, for instance. It’s making inroads with traditional business associations that once pummeled it on policy, and also supports think tanks and advocacy groups.

Keep Reading Show less
Ben Brody

Ben Brody (@ BenBrodyDC) is a senior reporter at Protocol focusing on how Congress, courts and agencies affect the online world we live in. He formerly covered tech policy and lobbying (including antitrust, Section 230 and privacy) at Bloomberg News, where he previously reported on the influence industry, government ethics and the 2016 presidential election. Before that, Ben covered business news at CNNMoney and AdAge, and all manner of stories in and around New York. He still loves appearing on the New York news radio he grew up with.

Sustainability. It can be a charged word in the context of blockchain and crypto – whether from outsiders with a limited view of the technology or from insiders using it for competitive advantage. But as a CEO in the industry, I don’t think either of those approaches helps us move forward. We should all be able to agree that using less energy to get a task done is a good thing and that there is room for improvement in the amount of energy that is consumed to power different blockchain technologies.

So, what if we put the enormous industry talent and minds that have created and developed blockchain to the task of building in a more energy-efficient manner? Can we not just solve the issues but also set the standard for other industries to develop technology in a future-proof way?

Keep Reading Show less
Denelle Dixon, CEO of SDF

Denelle Dixon is CEO and Executive Director of the Stellar Development Foundation, a non-profit using blockchain to unlock economic potential by making money more fluid, markets more open, and people more empowered. Previously, Dixon served as COO of Mozilla. Leading the business, revenue and policy teams, she fought for Net Neutrality and consumer privacy protections and was responsible for commercial partnerships. Denelle also served as general counsel and legal advisor in private equity and technology.


Everything you need to know about tech layoffs and hiring slowdowns

Will tech companies and startups continue to have layoffs?

It’s not just early-stage startups that are feeling the burn.

Photo: Kirsty O'Connor/PA Images via Getty Images

What goes up must come down.

High-flying startups with record valuations, huge hiring goals and ambitious expansion plans are now announcing hiring slowdowns, freezes and in some cases widespread layoffs. It’s the dot-com bust all over again — this time, without the cute sock puppet and in the midst of a global pandemic we just can’t seem to shake.

Keep Reading Show less
Nat Rubio-Licht

Nat Rubio-Licht is a Los Angeles-based news writer at Protocol. They graduated from Syracuse University with a degree in newspaper and online journalism in May 2020. Prior to joining the team, they worked at the Los Angeles Business Journal as a technology and aerospace reporter.


Sink into ‘Love, Death & Robots’ and more weekend recs

Don’t know what to do this weekend? We’ve got you covered.

Our favorite picks for your weekend pleasure.

Image: A24; 11 bit studios; Getty Images

We could all use a bit of a break. This weekend we’re diving into Netflix’s beautifully animated sci-fi “Love, Death & Robots,” losing ourselves in surreal “Men” and loving Zelda-like Moonlighter.

Keep Reading Show less
Nick Statt

Nick Statt is Protocol's video game reporter. Prior to joining Protocol, he was news editor at The Verge covering the gaming industry, mobile apps and antitrust out of San Francisco, in addition to managing coverage of Silicon Valley tech giants and startups. He now resides in Rochester, New York, home of the garbage plate and, completely coincidentally, the World Video Game Hall of Fame. He can be reached at nstatt@protocol.com.


This machine would like to interview you for a job

Companies are embracing automated video interviews to filter through floods of job applicants. But interviews with a computer screen raise big ethical questions and might scare off candidates.

Although automated interview companies claim to reduce bias in hiring, the researchers and advocates who study AI bias are these companies’ most frequent critics.

Photo: Johner Images via Getty Images

Applying for a job these days is starting to feel a lot like online dating. Job-seekers send their resume into portal after portal and a silent abyss waits on the other side.

That abyss is silent for a reason and it has little to do with the still-tight job market or the quality of your particular resume. On the other side of the portal, hiring managers watch the hundreds and even thousands of resumes pile up. It’s an infinite mountain of digital profiles, most of them from people completely unqualified. Going through them all would be a virtually fruitless task.

Keep Reading Show less
Anna Kramer

Anna Kramer is a reporter at Protocol (Twitter: @ anna_c_kramer, email: akramer@protocol.com), where she writes about labor and workplace issues. Prior to joining the team, she covered tech and small business for the San Francisco Chronicle and privacy for Bloomberg Law. She is a recent graduate of Brown University, where she studied International Relations and Arabic and wrote her senior thesis about surveillance tools and technological development in the Middle East.

Latest Stories