As we covered in February's threat analysis, a growing share of sextortion threats are built on fabricated images โ€” AI-generated composites assembled from innocent public photos. This is the technical companion: how professionals assess whether an image is synthetic, the checks any victim can run, and why the discipline of confidence scoring matters more than any single detection trick.

Why Detection Changes Everything

A threat built on a fabrication is still extortion โ€” still a crime, still reportable, still prosecutable. But knowing the image is synthetic changes two things: your fear (the perpetrator has nothing real to leak) and your strategy (the bluff can be called with evidence). Detection is therefore not an academic exercise; it is leverage analysis.

Layer 1 โ€” Visual Artifact Analysis

Current image-generation systems remain statistically bad at specific anatomical and structural details. Examine these clusters at full zoom, comparing against any genuine reference photo of the same person:

No single artifact is proof. Clusters of them โ€” especially across different image regions โ€” are strong indicators.

Layer 2 โ€” Metadata Analysis

Every digital photo carries embedded metadata (EXIF) describing the capturing device, settings, and time. Generated images typically have stripped or absent camera metadata โ€” a file that claims to be a phone photo but carries no phone metadata is anomalous. Conceptually, investigators check: camera make/model fields, original timestamps versus claimed ones, editing-software signatures, and whether the file's structure matches its alleged origin. A real photograph of a real moment is dense with consistent provenance data; a fabrication usually isn't.

Layer 3 โ€” Reverse Image Search Methodology

This is the single most powerful technique available, because fabrications are built from source images:

Finding the source photo a deepfake was built from doesn't just disprove the image โ€” it proves intent to fabricate, which is itself evidence of the extortion attempt.

Layer 4 โ€” The Confidence-Scoring Mindset

Amateur analysis declares certainty; professional analysis grades it. In our reports, every finding carries a confidence rating โ€” high, medium, or low โ€” based on the number and independence of corroborating signals. A merged-finger artifact alone is medium confidence. The same artifact plus missing EXIF plus a located source photo is high confidence. This discipline matters because it keeps conclusions defensible when the report reaches an attorney or an IC3 analyst. It is also, honestly, the discipline that keeps victims from either false panic or false comfort.

What to Do With a Debunk

Document it โ€” screenshot the artifacts, save the reverse-search results, log the missing metadata โ€” then report the extortion anyway at IC3.gov, and to NCMEC's CyberTipline if a minor is depicted (fabricated depictions of minors are treated as CSAM under federal law). Then stop negotiating with a bluff. If you want the assessment done for you โ€” artifact review, multi-engine reverse search, and a confidence-graded finding you can hand to law enforcement โ€” that is precisely what our engagement process produces, and the FAQ covers what we can and cannot honestly promise.

If you or someone you know is being sextorted:

Don't pay. Don't panic. Document everything. A senior OSINT specialist reviews every confidential intake within 4 hours โ€” and the consultation is free.

help@smishguard.bond