How Livestreamed Child Abuse Is Challenging How We Think About Online Privacy

July 20, 2026:

How Livestreamed Child Abuse Is Challenging How We Think About Online Privacy

—Photo-Illustration by TIME (Cavan Images/Getty Images; Yuliya Taba—Getty Images)

Content warning: This story contains descriptions of child sexual abuse, child sexual exploitation, and trafficking that some readers may find distressing.

Teresita was never a girly girl. Growing up in the choked urban sprawl north of Manila, she spent her childhood running wild with neighborhood kids, climbing trees, and shinnying around derelict lots. “I liked games that stretched my bones,” she tells TIME with a grin.

By the standards of blue-collar Philippine life, Teresita had a comfortable upbringing. But things got tricky after her adoptive father returned home from working in Saudi Arabia and could only find a low-paying job as a security guard. Before long, the family was struggling to pay food and rent. “It became more about surviving,” she recalls.

Teresita’s elder stepsister became the family’s chief breadwinner. In her late 30s, she started working online as a romantic companion, sending erotic pictures and videos to predominantly Western men she met via dating and pornography websites.

At first, Teresita would casually join these calls out of impish curiosity, but she soon grew her own clientele brokered by her stepsister. It started with pillow talk as a “fake girlfriend,” she says, though things escalated when the men started to offer more money for nude photos. 

Those transmissions all took place using regular chat apps you likely have on your phone right now but remained hidden from law enforcement due to end-to-end encryption (E2EE), a secure communication method that scrambles data on your device and only permits a designated recipient to decrypt it. Technology that was designed to protect privacy had turned into an enabler of horrific abuse.

By 2018, Teresita was being coerced by her stepsister into performing livestreamed sex acts on herself at least four times every day while her “customers” watched, directed her, and pleasured themselves. She was 13 years old.

“I was disgusted with myself,” Teresita recalls. “I would ask, ‘why would I do this?’ I had shivers on my spine, but I just remember having to swallow all of that because we needed the money.”

Teresita was eventually rescued from her stepsister in 2021 by a Philippine National Police (PNP) raid. Now 20 years old and studying to be a social worker, Teresita, whose name TIME has changed due to ongoing legal action against her abuser, agreed to speak about her ordeal to raise awareness and hopefully save other youngsters from falling into the same trap.

Many do. In 2022 alone, nearly half a million Filipino children were sexually exploited in livestreams, according to a study by the International Justice Mission (IJM) NGO and the University of Nottingham Rights Lab. That’s equivalent to one in every 100 children across the Southeast Asian nation. The average age of victims is just 8 years old and abuses frequently include torture and rape.

“It’s definitely increasing,” says Martin Conley, the national program manager for live streaming at Homeland Security Investigations (HSI), the primary criminal investigative arm of the U.S. Department of Homeland Security, which boasts some 10,000 staff spread across the U.S. and globe “From what we’re seeing, this is probably the largest emerging form of child abuse and exploitation.”

Contrary to popular perception, it doesn’t primarily unfold in the murkiest recesses of the dark web. Nearly all of it takes place on the services that regular, law-abiding people use every day—including WhatsApp, Zoom, Telegram, and many others—but it remains hidden from view owing to E2EE. 

Advocates for E2EE maintain that the technology is essential to protect vulnerable groups, such as journalists communicating with confidential sources, political dissidents under authoritarian regimes, or businesses sharing trade secrets. However, that same confidentiality also empowers terrorists and criminals to conceal their misdeeds—including the systemic abuse of millions of children.

There is hope, however. New AI tools can allow platforms to interrupt livestreamed abuse and alert law enforcement in real time while, advocates claim, preserving the privacy protections that E2EE provides for ordinary users.

However, these technological advances are not widely deployed due in part to concerns from privacy activists, who maintain they necessitate backdoors that could be exploited by governments and nefarious actors to enable wholesale spying. “Encryption is crucial to the way that everyone interacts with technology and lives their lives online,” notes a recent report by the Washington D.C.-based New America think tank.

The rise of livestreamed child sexual abuse material (CSAM) has intensified a broader debate over how much responsibility technology platforms bear for safeguarding users. The debate gained new urgency in March, when back-to-back verdicts in California and New Mexico found, for the first time, Facebook parent Meta liable for products that inflict harm on young people. As AI tools transform every industry, child-safety advocates are urging tech companies to consider whether they can be deployed more aggressively to protect children online. 

“What’s terrifying is not only the difficulty of detection but also the magnitude of abuse,” says Conley. “These kids are abused over and over again. And it’s worse than the worst horror movie.”

The question is how much privacy society is willing to trade for the protection of children. Supporters of stronger detection tools point to the limited intrusions people already accept in the name of public safety, from airport security searches to DUI checks. Privacy advocates argue that scanning private digital communications is different: a system built for one purpose can later be expanded for another.

But a shift already appears to be underway. Last June, the Senate Judiciary Committee unanimously passed the bipartisan STOP CSAM Act, which would empower victims of online child exploitation to sue the tech platforms and app stores that promote or aid and abet their abusers. It is currently awaiting a full Senate vote.

“Children are being exploited and abused because Big Tech consistently prioritizes profits over people,” legislation co-sponsor Senator Dick Durbin tells TIME. “Parents have been begging Congress to step in, and it’s time we do so.”

A spokesperson for Google denied the firm was failing to protect customers, highlighting its endorsement of anti-CSAM legislation around the globe and use of hash-matching technology on content stored on its cloud infrastructure, including meeting recordings.

“When detected, we report [CSAM] to [the National Center for Missing and Exploited Children (NCMEC], preserve evidence, remove access, and take appropriate enforcement action,” Google said. “And, together with others, we advocate for effective legislation to keep kids safe online.” 

Risa Hontiveros disagrees. The Philippine Senator has championed the fight against child exploitation in her homeland and warns that rising costs from global shocks may push more Filipinos toward producing and selling CSAM. “Sometimes, heartbreakingly, involving their own children,” she tells TIME.

“What we need from these tech giants is not just reactive takedowns after children have already been harmed,” says Hontiveros. “We need safety built into their platforms by design, like proactive detection, especially for live-streamed content. These companies earn far more than they are investing in child safety. That has to change.”


Martin Conley doesn’t look like someone who scares easily. Broad-shouldered with close-cropped hair, he spent seven years as a Secret Service special agent before joining HSI in 2011. But even Conley’s imposing frame can’t shield him from the sheer depravity he has encountered while going undercover to investigate livestreamed CSAM. 

“The youngest child that we rescued was two days old,” he says. “There was a newborn baby … and they were asking for the abuse of that child.”

How prevalent is livestreamed CSAM really? To answer, Conley fires up his dedicated undercover laptop. While we wait, he explains his grim baptism into this scourge back in November 2012, when a woman in the southern Philippine province of Cebu contacted him on the now-defunct Yahoo Messenger.

“She turned on her camera and I see six tiny little children laying on a dirt floor,” recalls Conley. “And she said, ‘I will do anything you want to them for $15. Are you interested?’”

From that initial interaction to those children’s rescue took 11 months. “A number I will remember for the rest of my life is 1,971,” says Conley. “That’s how many payments she received in that timeframe—so that many likely abuse events happened.”

Conley’s laptop pings. It’s been 14 minutes since it booted. “That is a person calling me right now to sell children,” he says. “I’m not even involved in [undercover] daily like I used to be.” During that time, he would typically receive messages every seven minutes, he says. “That gives some indication of how prevalent this is.”

Many factors make the Philippines ground zero for livestreamed CSAM: a young and social media-savvy populace; a normalized culture of sex work; and the prevalence of spoken English. However, live-streamed CSAM is a growing concern globally.

Given the clandestine nature of this crime, accurate global statistics are hard to find. But extrapolating from limited empirical studies paints a grim picture. In 2013, four researchers from Terre des Hommes Netherlands posed as pre-pubescent Filipino girls on 19 different online chat forums. Over a 10-week period, 20,172 people from 71 different countries asked them to perform a webcam sex show.

A report published last month by the IJM, Childlight East Asia, and the University of New South Wales surveyed 1,473 American men and found 4.1% admitted to engaging in sexually explicit webcam interactions with children and another 3.5% said they would if offered. That’s the equivalent of 1 in 13 respondents either having livestreamed sexually with a child or having such a desire.

The democratization of Internet access with cheap smartphones and 5G has also regrettably seeded a CSAM wild west, whereby anyone with access to a child and dire financial problems can instantly solve their money woes.

“We’ve seen it in Latin America, throughout Africa, other parts of Southeast Asia,” says Mike Tsittakalakis, the acting division chief at the Department of Homeland Security Cybercrime Center. “It’s a huge number just for the Philippines but we know it’s not just happening there.” The primary consumer base remains the U.S., though Australia, France, Germany, and the U.K. also rank highly, according to the IJM.

Livestreamed CSAM is especially pernicious because it gives abusers the thrill of directing and interacting with victims while leaving little chance of being caught. While static CSAM has circulated online for decades—allowing for the creation of digital markers, or “hashes,” that can flag existing files and lead to their removal—livestreamed abuse disappears the moment a call ends. “The abuse didn’t stop,” says John Shehan, vice president of the NCMEC. “The lights just went off.”

Each morning, Shehan arrives at NCMEC’s headquarters in Alexandria, Va., home to roughly 500 staff as well as two dozen permanently stationed officers from agencies including the FBI, Secret Service, U.S. Marshals, U.K. National Crime Agency, and U.S. Postal Inspection Service. It’s here that most initial CSAM reports arrive through NCMEC’s CyberTipline, which acts as a global clearinghouse that triages 80,000 to 100,000 daily. 

Investigators then cross-check incoming reports against previous cases, analyze patterns, and use open-source intelligence to tie online identities to real-world individuals. “We want to see if there’s a Facebook profile, or someone’s trying to sell a car, or post something about their favorite band, to link that online identifier to someone in the real world,” says Shehan.

AI tools donated by companies including Palantir help scan incoming reports for urgent leads, such as GPS coordinates or signs a child may be in immediate distress. “The AI systems elevate that to us, we look at it, and then we make sure it gets to law enforcement sooner than later,” says Shehan.

But AI is increasingly aiding abusers, too. It can subtly alter existing CSAM to evade hash detection and generate synthetic imagery altogether, complicating investigations already overwhelmed by sheer volume. According to Childlight, reports of synthetic CSAM surged 1,325% from 4,700 cases in 2023 to 67,000 in 2024. 

While synthetic CSAM may sound less harmful, fake videos are increasingly being used to “sextort” real children into degrading acts, leading some to take their own lives. AI also allows offenders in non-English-speaking countries to communicate seamlessly with customers around the planet.

Because livestreamed CSAM is shielded by E2EE, cases often surface only through indirect signals: suspicious financial transactions, user reports, or metadata. In Teresita’s case, investigators only identified her after one of the hundreds of men with whom she interacted was arrested in the U.S. with recordings of their calls. The FBI then traced his digital records back to Teresita’s stepsister and alerted the Philippine authorities. But this type of reactive investigation only scratches the surface of the problem, meaning most cases slip through the cracks.

“These live streaming cases are very unique as it is a one-on-one show where that buyer is directing the sexual abuse, the rape, and sometimes the torture of these children,” says Jake Marquis, a HSI special agent. “But with it being a private show, it’s not a group setting where someone could have an undercover infiltrate.”

Financial records are a key avenue for investigation but increasingly problematic with the sheer abundance of services available. The other day, the HSI team in the Philippines were told about three remittance services that had become most prominent in livestreaming cases. “All of us in the room look at each other as we’ve never heard of these companies,” says Corey, an HSI investigator in Manila, who asked TIME not to use his full name for fear of compromising undercover work. 


Rather than retroactive investigation, tools do exist to detect abuse during transmission. Meta has used systems to identify CSAM on Facebook and Instagram Live, while Google has deployed similar tools on YouTube. Meta has not extended these tools to Messenger, nor Google to Meet. Instead, Apple and Google have introduced on-device safety features for minors that detect nudity and blur images without automatically notifying the companies. Late last year, Microsoft rolled out an AI-powered CSAM detection bot for Teams—but only for users who have not enabled E2EE in security settings.

Asked by TIME why stronger technologies are not more widely deployed to combat live-streamed CSAM, most technology firms cited safety measures and privacy commitments, but offered little detail on specific product decisions.

Zoom stated it has “a zero-tolerance policy for child sexual exploitation and abuse” but remained committed to E2EE. Telegram said “the public spread of CSAM has been virtually eliminated from our platform” but declined to comment on private calls. Microsoft said it “is committed to combatting online child sexual exploitation and abuse across its services.” Google meanwhile said it uses “privacy-preserving hash matching and machine learning classifiers to identify both known and previously unidentified content,” but only on non-encrypted services. 

Meta pointed TIME to a 2021 paper by cybersecurity experts warning that client-side scanning “creates serious security and privacy risks for all society while the assistance it can provide for law enforcement is at best problematic.”

Others argue carefully designed and privacy-preserving scanning systems justify limited trade-offs. Thorn, a California nonprofit, provides AI-powered CSAM detection tools that are used by 1,046 law enforcement agencies across 40 countries. Thorn also has its Safer product that can be built into commercial systems that is used by 86 companies and last year discovered 1,369,024 instances of suspected child exploitation. Rather than monitoring entire calls, Thorn uses AI to check occasional frames of a video call. If one frame triggers concern, the system reviews additional frames before escalating the case for human review, blocking the content, or terminating the call, depending on the specific platform specifications.

“It doesn’t go from one false positive and there’s an arrest or a SWAT team,” explains David Rust-Smith, a senior staff data scientist at Thorn. “There’s a whole spectrum of how to operationalize these predictions.”

Thorn’s tools could potentially be embedded into operating systems like iOS. When asked whether Apple would consider client-side scanning livestreams for CSAM, the Cupertino firm referred TIME to a 2023 letter by Erik Neuenschwander, Apple’s director of user privacy and child safety, which states, “scanning for one type of content … opens the door for bulk surveillance and could create a desire to search other encrypted messaging systems.”

Another option would be for digital communication providers to use AI scanning tools within Trusted Execution Environments, which are essentially hardware “secure enclaves” that allow for limited analysis of encrypted data while keeping it invisible and inaccessible to anything outside—including the operating system itself. While this would no longer strictly be E2EE, advocates say privacy can be maintained as a form of “end-to-end-to-end encryption.” It is controversial, however. “It depends how pragmatic your approach is and where your real concerns and trust lie,” says Rust-Smith.

With E2EE in place, law enforcement is largely limited to what technology companies are prepared to detect and disclose. While all are statutorily required to report illicit content, there’s a huge disparity regarding the timeliness and actionability of that data. “Numerous times I would get a 1 a.m. call from a certain tech platform saying, ‘Hey, this kid is being sextorted and at very likely risk of harming themselves,’” says Corey. “Some companies do a lot. Some companies do the bare minimum.” 


A few years ago, Tsittakalakis was queuing at a coffee shop in New York City when he noticed the man in front had a picture of two nude children on his phone. “I just want to get my coffee,” he says. “But now I’m in this position where if I don’t pursue this, it’s going to keep me up at night.”

Tsittakalakis approached the man, identified himself, and asked about the images. “We had a very cordial conversation, and he agreed to show me his phone and it was his two children in the bathtub. It looked very bad but it turned out to be innocuous. He was shocked initially but then appreciative.”

While asking to inspect the phone breached the man’s privacy, it was also responsible and, many would argue, Tsittakalakis’s professional duty. Especially as the concern is not only what happens on screen. Another key takeaway from the 2025 IJM study was the link between livestreamed CSAM and realworld harm, with adult consumers six times more likely to have had sexual contact with a child.

“These people are some of the most dangerous in society,” says Conley of the abusers he investigates. “What one person would look at and be horrified and never forget for the rest of their life, they are getting gratification from watching and causing.”

While law enforcement can search your home or wiretap conventional phone calls with a court warrant, no U.S. government agency can compel digital communications providers to directly listen to E2EE voice or video calls in real-time or access recordings. The FBI can only use legal processes to obtain extensive metadata and, in some cases, content stored directly on a device.

Yet many digital communications are already monitored. Outlook or Gmail scans emails to filter spam and enable features like predictive reply. Even E2EE networks use limited client-side scanning to alert users about suspected malware. Consumers accept this because fraud is a $1 trillion global problem. CSAM, however, remains hidden.

“Why are privacy groups okay with protecting individuals from scams and malware and spam, but not protecting kids from the most gut-wrenching, horrific content?” asks Hany Farid, a professor of computer science and digital forensics at UC Berkeley, who partnered with Microsoft to create the PhotoDNA system of cataloguing known CSAM via a hash database used by NCMEC and others. 

Critics argue E2EE is often more about protecting companies from liability than safeguarding privacy. Processing government data requests requires extensive legal vetting and billable hours. But E2EE allows tech companies to issue a blanket denial. “It’s easier operational efficiency, because you basically ignore all of the societal problems you may or may not be creating,” says one former Apple executive who worked extensively on child safety, who requested anonymity because they were not authorized to speak publicly.

Increasingly, governments are stepping in. The U.K. and Australia have rolled out Online Safety Acts making platforms legally responsible for protecting users from harmful content. The E.U. is debating legislation that would require services to proactively detect CSAM and hold them accountable for breaches. “The civil liability component is what’s most potentially transformative,” says Nate King, director of U.S. Congressional Affairs at the IJM.

But with nearly all the main apps owned by American companies, U.S. government action is critical for meaningful enforcement. When the U.K. regulator Ofcom recently fined the American platform 4Chan $700,000 for failing to comply with its safety act, a lawyer for the company responded with an AI-generated image of a cartoon hamster. Unlike many other democracies including Australia and the U.K., the U.S. has no laws limiting the use of encryption. “The U.S. just happens to be at the center of this global issue,” King notes.

Activists say passing the STOP CSAM Act would be a start. It would then fall to the courts to decide whether the operating systems, communication services, or even the cloud networks that they all rely on should be held accountable. Or perhaps, just like physical safety, there should be multiple redundancies and all must play their part.

“We have lots of checks and balances when it comes to physical safety,” says Farid. “That’s the right way to think about it. Throwing our hands up and saying ‘nothing to do here’ is an unacceptable response given what we are talking about.”

For Senator Durbin, the mandate is clear: “Anyone who is intentionally, knowingly, or recklessly hosting CSAM should be held responsible.”

Teresita is under no illusions. Upon her initial rescue, she was angry and resistant, fearing for the breakup of her family. Today, she is thankful, cognizant of the severe danger she faced.

Many of her former clients would seek out a personal meeting in one of the swanky hotels in Manila’s well-heeled Makati neighborhood, though only her stepsister’s vigilance made sure that never happened. “Every time a man expressed a desire to come here and spend the night with me my stepsister would block them and would not engage further,” says Teresita. “That happened often.”

A judge is due to rule on sex trafficking charges against Teresita’s stepsister in the fall. But she has already pleaded guilty to attempted sex trafficking of a 9-year-old girl from the neighborhood and been sentenced to 13 years in prison. No matter what unfolds in her case, Teresita has made peace with what happened to her.

“I’m not being dragged back by my experience. It’s not my identity anymore. I can embrace it as something that the Lord has used me for,” she says. “I’ve also forgiven her. I am not feeling any anger, I feel pity, because knowing her situation, she was only doing this to provide for us. I’m not justifying what she did, but I never thought of my stepsister as a bad person, just somebody who did something wrong. But she is still someone who can change.”

For Teresita, that message of accountability extends to politicians and technology companies, raising a question at the heart of the debate: whether they are doing everything possible to protect children from online exploitation.

“The owners of these big companies should do everything they can to protect their users, especially children,” says Teresita. “It’s right to put pressure on these companies to find solutions.”

Source link