FRAUD CHECK — Squire It™
sharelivefraud.com/squire-it
LIVE FRAUD ALERT
LIVEFRAUD Check #79
FTC WARNS

The FTC says online platforms must remove non-consensual intimate images within 48 hours of a request, and it is asking people to report platforms that fail to do so.

MODERATE CONFIDENCEPublished 2026-09-18
S
Q
U
I
R
E
D
E
S
K
·
C
H
E
C
K
E
D
·
B
A
T
T
L
E
D
·
R
E
C
E
I
P
T
E
D
·
S

What we found

An FTC consumer alert published 17 September 2026 states that the law requires online platforms to give you an easy way to submit a takedown request for an intimate photo or video shared without your permission, and to take it down within 48 hours. According to that alert, a platform that does not remove the image within 48 hours of your request is violating the Take It Down Act, and so is a platform with no removal process or a broken one. The FTC says it enforces the law against platforms and that reports help it investigate, with a possible civil penalty of $53,088 per violation, and it directs reports to TakeItDown.ftc.gov. If a platform misses that 48-hour window, make your report at the FTC's own address, TakeItDown.ftc.gov, typed into your browser yourself rather than reached through a link someone sends you. The harvested alert does not describe any fraud scheme, any impersonation of the FTC or of a takedown service, and it names no platform, so we cannot say here whether anyone is charging fees for removal help. The alert also does not say how many reports the FTC has received, how many platforms it has acted against, or what happens after a report is filed. LIVEFRAUD ALERTS is independent and is not affiliated with the FTC or with any platform; this alert was written only from the harvested material cited above.
THE RULE
Low fraud signal, high personal harm: the harvested material is an official reporting instruction, not a scam report, but people in this situation are urgent and distressed and that is exactly the state bogus paid 'image removal' offers target.

What we don’t know

The bench — who voted

2 INDEPENDENT AI MODELS REVIEWED THIS. ALL 2: MODERATE RISK.

The card names a count. Here are the seats behind it, with what each one said.

ANTHROPICclaude-opus-5 · MODERATE
The finding asserts 'The FTC says it enforces the law against platforms and that reports help it investigate.' The evidence row states only that reports go to TakeItDown.ftc.gov and that a civil penalty of $53,088 per violation is possible; it does not attribute an enforcement or investigation-aid statement to the FTC. That sentence should be trimmed to what the row says or marked as inference.
DISSENT, PRESERVEDThe single most useful line here — type TakeItDown.ftc.gov yourself rather than following a link — is protective advice the source row does not itself contain. I am content to keep it because it reduces harm, but it should be labelled as the publisher's own guidance, not as something 'the FTC says'.
DISSENT, PRESERVEDPieces like this, telling distressed victims of intimate-image abuse where to report, are exactly the material lookalike domains and paid 'removal service' operators clone. I would grade the downstream risk moderate rather than low on that basis alone, even though the harvested alert documents no such scheme.
GROQopenai/gpt-oss-120b · MODERATE
The finding adds advice to manually type the TakeItDown.ftc.gov URL rather than clicking a link, which is not present in the cited FTC alert.

Reviewed by 2 independent models: 1 found it carried by the evidence, 1 did not.

▼ Protocol & challenge record
Objection (high): Internal contradiction between risk_line and the draft's own limitation. The limitation sentence says "we cannot say here whether anyone is charging fees for removal help," but risk_line asserts as fact that distress "is exactly the state bogus paid 'image removal' offers target." No harvested row mentions paid removal offers, impersonation, or any scam scheme. The risk line is an unsourced empirical claim about scammer behaviour smuggled in as editorial framing, and it is the single most scam-flavoured sentence in a package built on a non-scam advisory. Either source it or strip it to "no fraud signal in the harvested material; high personal harm topic."
Not resolved — preserved on the record.
Objection (medium): Entity/scope stretch on "online platforms." The claim and finding say flatly that "online platforms" must remove within 48 hours. The Take It Down Act applies to a statutorily defined class (covered platforms), and the harvested alert says only "platforms" without defining the term. The draft never flags that the alert does not say which services are covered, which services are excluded, or whether private messaging/hosting/ISP services fall inside. A reader with an image on a service outside the definition will be told they have a 48-hour right they may not have. This belongs in unknowns at minimum.
Not resolved — preserved on the record.
Objection (medium): Domain-confusability hazard is unaddressed while the draft simultaneously tells readers to type the address manually. There is a widely publicised, differently-operated service at takeitdown.ncmec.org (NCMEC), and the FTC address is TakeItDown.ftc.gov. Telling a distressed reader to "type it yourself" without flagging that the .ftc.gov suffix is the load-bearing part invites landing on a similarly named non-FTC destination or a squatted typo domain. If the draft is going to give anti-phishing advice at all, it has to name the discriminator.
Not resolved — preserved on the record.
Objection (medium): Date currency on the penalty figure. $53,088 is an inflation-adjusted FTC civil penalty maximum that is revised annually. The draft presents it with no as-of qualifier beyond the alert date (17 Sep 2026). If this alert is being republished any distance from that date, the figure is presented as current when it may not be. Attribute it as "the figure stated in the September 2026 alert."
Resolved: Partially self-mitigated: the finding already attributes the $53,088 figure to the alert ("The FTC says ... with a possible civil penalty of $53,088 per violation") and the alert's date is given in the first sentence. Residual risk is presentation, not sourcing.
Objection (medium): Malformed output leaking to the record. targeting_dropped contains the placeholder fragment "DIRECTIVE NOT IN EVIDENCE: waiting — no harvested source describes this group" (the group name appears to be the literal token "waiting"), and callout_options contains "ATTENTION: SCAMMEDS," which is not a word and not a group. "ATTENTION: PARENTS" is also unsupported — the only hook is the source's topic tag "Protecting Kids Online," which is FTC site taxonomy, not a statement that parents are affected. These are quality defects that undermine the package's claim to be evidence-disciplined.
Not resolved — preserved on the record.
Objection (low): Confidence "high" rests on a single row with no corroboration. The confidence_reasons concede this. That is defensible for a purely attributional claim ("the FTC says X"), but the claim line as written slides toward stating the legal obligation itself, and "high" on n=1 official row with no second source should be "high for what the alert states, not for the underlying legal position." The third confidence reason already says this; the confidence label should carry it.
Resolved: Substantially addressed by confidence_reasons[3], which explicitly limits confidence to what the advisory states and notes there is one row and no second source.
Objection (low): Unsourced advice presented adjacent to sourced claims. The "type it into your browser yourself rather than reached through a link someone sends you" sentence carries role "advice" and row_ids [], which is honest, but it implies an active link-based threat in this specific context that no row supports. It is defensible as generic hygiene; it is not defensible if read as "there are fake TakeItDown links circulating." Phrase it as general practice, not as a response to this situation.
Resolved: Partially addressed: the sentence is correctly tagged role=advice with empty row_ids, and the limitation sentence explicitly states no impersonation of the FTC or of a takedown service appears in the harvested material.
Objection (low): Alternative reading not considered: the 48-hour clock in the statute runs from receipt of a *valid* request (typically requiring identification and identifying the content/location). The alert omits this and the draft reproduces the omission as an unqualified "48 hours of your request." The unknowns list gestures at it ("How the 48-hour window is counted"), but the finding body states the unqualified version twice, so the caveat arrives too late to protect the reader.
Resolved: Partially addressed by unknowns[4] ("How the 48-hour window is counted or what evidence a reporter needs to supply").
Preserved dissent
ON THE RECORDI do not accept the risk_line as written. The draft explicitly states it cannot say whether anyone is charging fees for removal help, and then the risk_line tells the reader that this distress state "is exactly the state bogus paid 'image removal' offers target." That is a claim about the world, not a hedge, and nothing in the single harvested row supports it. If the Desk keeps it, the record should show that I consider it the one place in this package where the evidence discipline the rest of the draft observes is abandoned.
ON THE RECORDI think "Low fraud signal" is the wrong frame for this item entirely. This is not a fraud alert; it is a government reporting instruction republished by a fraud-alert outlet. Dressing it in ATTENTION callouts, watch icons and share directives borrows scam urgency for a non-scam document. The honest version says so in the first line rather than in a risk field the reader may never see.
ON THE RECORDI do not think confidence "high" should attach to a package whose headline claim states a legal obligation drawn from one consumer-facing FTC blog post that does not define its own key term ("platforms"). The attribution is sound; the legal generalisation is not, and the confidence label does not distinguish between them.

The sources

Official sourceDid an online platform fail to quickly take down your intimate images? Report it to the FTC2026-09-17
An FTC consumer alert published 17 September 2026 states that platforms must offer an easy takedown request route for non-consensual intimate images and remove them within 48 hours, that failing to do so or lacking a working removal process violates the Take It Down Act, and that reports go to TakeItDown.ftc.gov with a possible civil penalty of $53,088 per violation.
Authority: official. Retrieved 2026-09-18.
Limitation: A single official advisory; it describes the law and the reporting channel only, and identifies no platform, no enforcement action taken and no number of reports received.
Open the original source →

Other checks

Every check we have published →

Share this receipt
sharelivefraud.com/check/d_L55_w

Published under standing founder pass (A9) — every claim source-mapped by the machine.

▼ What the machine checked
  • ✓ Not a community submission.
  • ✓ No entity is named.
  • ✓ All 3 material sentence(s) map to FTC.
  • ✗ anthropic raised 4 objection(s); anthropic recorded dissent; groq returned "overstated" — published on the receipt, not blocking (A9 amendment).
  • ✓ No audience band is set.

No human affirmed these. They were verified by the classifier described in Amendment A9, on 2026-09-18.

Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.

Phishy? Send it → sharelivefraud.com/squire-it

Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.

Naming a source is not an endorsement, and being named here is not an accusation against any company.

Powered by SquireIt™

Verify this receipt at squireit.com

Join Squire’s First Watch

Alerts before the feed. Credit when your summons becomes a receipt. A vote on what we check next. Founding names are permanent.

Get the next one

We publish a receipt for every alert, including the ones we decide not to run.

We will ask you to confirm before anything is sent. Your address is used for this and nothing else, and is never shared.