Safety

How to Document and Report an OnlyFans Impersonation

A documentation-first workflow for fake profiles, fake subscription accounts, copied media, payment fraud, and search-result copies.

SirenCY

SirenCY Editorial Team

Safety Research

July 27, 2026
12 min read

Direct answer: before filing reports, create one dated record for every fake account, URL, payment request, and search result. Capture the address, account handle, profile link, time found, the identity being copied, and the harm you can actually see. Then report each item through the route that matches it: the relevant platform for impersonation, the host for copied media, eSafety when the Australian image-based-abuse facts fit, and fraud or cybercrime channels when money, credentials, or identity details are involved. A report can be important, but it does not guarantee removal, an account ban, a refund, or identification of the person behind it.

“OnlyFans impersonation” can describe several different incidents. Someone may use your public photos on a fake social profile, open a subscription account that claims to be you, repost a file, solicit payments using your name, or leave a stale copy visible in a search engine after the original page changes. Treating all five as one complaint makes the evidence less useful. The aim is to show the destination, the false identity claim, and the appropriate reporting basis without sending more personal information than necessary.

1. Stabilise the situation before collecting more

Start with immediate safety. If the impersonator is threatening you, publishing an address, demanding money, pressuring you to send content, or creating a risk of physical harm, use a safe device and seek urgent help through Australian emergency or police channels. Do not bargain with a blackmailer, send additional material, or pay to make the account disappear. Preserve the threat, account details, and payment instructions first, then stop contact where that is safe.

If you suspect an account takeover, secure the email account that receives password resets before changing every other password. The Australian Cyber Security Centre recommends multi-factor authentication where available, unique passphrases, official-app or website sign-in rather than a link sent in a message, and review of unfamiliar third-party access. An unknown login is evidence of possible compromise; it does not by itself prove that the same person made every copied post.

Ask one trusted person to help if viewing the material or collecting records feels unsafe. Their role can be limited to recording URLs and report numbers. Do not ask them to download, forward, or store sexual material involving anyone under 18 or other illegal or restricted content. eSafety specifically says that URLs, account identifiers, dates, and surrounding context can be recorded without saving or sharing that material.

2. Use the impersonation identity map before choosing a report

The useful question is not only “is this fake?” It is “what identity is being copied, what destination is being misused, and what harm is visible?” The map below keeps five situations separate. One case may occupy more than one row; for example, a fake Instagram profile may send people to a payment scam and reuse copied images.

Identity-map categoryWhat to proveFirst report destinationOutcome to log
Fake social profileReal profile and fake handle/profile URL; copied name, image, bio, or linkThe social platform's impersonation or abuse reportProfile action, restriction, removal, or no action
Fake OnlyFans accountClaimed creator identity, account URL, public-facing identifiers, and genuine-account comparisonOnlyFans' live support, terms, or reporting pathCase reference and what the service says it reviewed
Stolen mediaExact hosting URL, original or authorised publication, and ownership or authority recordsHost or platform abuse/copyright channelHost removal, restriction, refusal, or moved copy
Payment fraudPayment handle, wallet/address or invoice, messages, amounts, and the false identity claimPayment provider and relevant scam/cybercrime routeProvider reference, payment status, and fraud-report reference
Search-result copySearch query, result URL, cached/preview text, and underlying host URLUnderlying host first; search-engine removal route where eligibleHost status and separate delisting status

This distinction matters in Australia. eSafety has described a pattern where a fake Instagram profile uses a person's non-intimate images and links to a supposed intimate-content subscription account. Its guidance explains that the image-based-abuse scheme may apply when intimate material purports to be the person, but a fake account using only non-intimate images may require a direct platform complaint instead. Report the facts and links; do not decide the legal category for the investigator.

3. Build one URL and account evidence tracker

Use a private spreadsheet, case note, or folder with one row per location. A screenshot alone is often not enough because it may omit the URL, account name, date, or surrounding claim. Conversely, a folder full of copied files may create more exposure without making a report easier to assess. Keep the tracker concise and repeatable.

URL/account evidence tracker

  1. Record ID: use a neutral ID such as IMP-01; do not put a legal name in the filename.
  2. Discovery: record date, time, time zone, who found it, and the search query or referral that led there.
  3. Location: copy the full URL, platform or host, account handle, account/profile URL, post ID, and any payment destination.
  4. False identity signal: state exactly what is claimed or copied: name, username, face, watermark, bio, link, email, or payment identity.
  5. Comparison: save the real account or authorised publication URL and a short factual note explaining the match. Label an unverified suspicion as a suspicion.
  6. Harm and category: mark impersonation, copied media, fraud, threat, possible compromise, image-based abuse, or search visibility. More than one may apply.
  7. Report log: destination, submission time, report/reference number, material supplied, response deadline if the recipient states one, and result.

Capture the profile or page in context before reporting it, because a report may alter what is visible. Keep the original capture separate from any redacted working copy. Avoid putting a home address, full identity document, bank details, or unnecessary intimate images into a routine support ticket. eSafety advises protecting personally identifiable information and suggests a new email address for removal requests where appropriate.

Do not accuse a named person in the tracker unless you have evidence that identifies them. “Account uses the same watermark and a similar handle” is a recordable observation. “This person stole it” is a conclusion that may not be established. That distinction helps when a platform, payment provider, police officer, or adviser needs to understand what is known and what remains unknown.

4. Report the account and the destination separately

File the account-level report where the account exists. For a fake social profile, use that platform's impersonation or abuse tool and provide the genuine profile and the specific copied identifiers. For a fake subscription account, use OnlyFans' current official support or reporting material and check the live OnlyFans terms and DMCA policy before sending a notice. Forms, categories, evidence fields, and privacy requirements can change, so do not rely on a third-party turnaround estimate or an old support address.

Report the destination separately when the fake account links elsewhere. A social profile that directs people to a payment page is not solved merely because the social profile disappears; the payment provider or host may need its own report. A copied file hosted outside the profile needs a host or platform report for that exact URL. A search result is not the same as the source page. eSafety explains that search-engine removal can make material harder to find, but it does not remove the material from the host website.

Use a copyright route only if you are the rights holder or authorised to act and can accurately explain the work and the relevant URLs. Being depicted in an image does not automatically establish copyright ownership in every situation. Authorship, contracts, commissions, employment, co-creation, assignments, and licences can matter. If ownership is unclear or a notice is contested, obtain qualified advice instead of making a broad ownership assertion.

5. Choose the Australian escalation that matches the harm

A platform report is usually the starting point for a straightforward fake profile. The route changes when the impersonation includes intimate images, a threat, identity misuse, account compromise, or fraud. The following sequence is a routing aid, not a substitute for an agency's or platform's assessment.

  • Image-based abuse: eSafety's reporting guidance says a person in Australia, or a person whose alleged sharer or threat-maker ordinarily lives in Australia, may be able to report when its other conditions are met. It also says a direct platform report is not a prerequisite. Give eSafety the account, URL, time, report history, and consent facts rather than assuming eligibility.
  • Cybercrime or online identity misuse: if credentials, an account takeover, phishing, payment fraud, or identity theft with an online component is involved, preserve the technical and payment records. IDCARE's reporting guide explains that ReportCyber can issue a reference number but is not a formal police statement and not every report is investigated.
  • Immediate danger, threats, stalking, or coercion: contact emergency services or police through the appropriate official channel. Ask how they want evidence preserved before you delete, alter, or publicly circulate anything.
  • Fraud against followers or customers: report the impersonating account and payment destination, then warn affected people only with verified details and an official contact method. Do not repost the fake links in a way that promotes them.

A single incident can require more than one report. An eSafety report may concern image-based abuse, a platform report may concern the fake account, and a ReportCyber reference may document the credential or fraud dimension. Keep their report numbers in separate tracker fields. Do not treat a reference number as proof that another organisation has removed content or opened an investigation.

6. Secure the real identity chain without destroying evidence

Check the accounts that control recovery and payments: primary email, social accounts, OnlyFans, cloud storage, payment services, domain accounts, and shared drives. From a trusted device, change reused credentials, enable multi-factor authentication where available, revoke unfamiliar sessions and third-party app access, and review recovery addresses, forwarding rules, linked payment details, and access permissions. Record the before-and-after state when possible rather than relying on memory.

The Australian Cyber Security Centre advises people to block and report fake accounts through the platform and notes that fake accounts can impersonate a person or brand to obtain identity information or money. It also cautions people to sign in through the official website or app if a message contains a link. That supports a containment step, not a conclusion that an impersonator necessarily breached the genuine account.

Avoid deleting the account, wiping a device, or changing every record before you decide what a platform, payment provider, insurer, eSafety, or police contact needs preserved. Containment and preservation can occur together: take a screenshot or export a security log if available, note the time, then revoke access. If another person previously had authorised access, retain the agreement and access history while removing access that is no longer required.

For prevention after containment, see the OnlyFans safety, security, and privacy guide and the anonymous creator privacy guide. Those pages address ongoing account and identity separation; this article is focused on documenting a suspected impersonation incident.

7. Verify each outcome and monitor without amplifying the scam

Mark each record with the precise outcome: removed by host, account restricted, profile still live, search result delisted, payment report acknowledged, URL moved, or no response. A missing Google or Bing result is not proof that the source page was removed. Likewise, the removal of one profile does not show that a payment page, copied video, or new handle has disappeared. Verify the exact URL in a signed-out browser or have a trusted person check it if you do not want to reopen harmful material.

Use a defined review cadence, such as checking the tracker and report replies at set intervals, instead of repeatedly searching your name or clicking through scam links. Search only enough to identify a new location, add it once, and send it down the appropriate lane. Do not join leak groups, share screenshots through ordinary team chat, or post an unverified public accusation. Public warnings should point people to a confirmed real account or official contact channel, not reproduce the scammer's payment details or links.

If copied intimate material is the main problem rather than identity fraud, the Australian leaked-content response plan covers the separate evidence and removal sequence. Keep that incident record distinct from the identity map: one tracks copies of material, while this workflow tracks who or what is falsely claiming to be the creator and where that claim directs people.

Source notes, scope and limitations

Primary and official sources accessed 27 July 2026 include OnlyFans' Terms of Service and DMCA policy (date not displayed in the accessible research surface); the eSafety Commissioner's Report image-based abuse guidance; eSafety's 16 April 2021 impersonation guidance; the Australian Cyber Security Centre's Secure your social media page, first published and last updated 29 July 2024; and IDCARE's Reporting Cyber and Identity Crimes in Australia fact sheet (date not displayed).

The documented facts above are attributed to those sources. The identity map and tracker are an organisational method, not a legal or platform-administration rule. This is general educational information for adults in Australia, not legal advice, police direction, a copyright opinion, or a determination that a particular eSafety report qualifies. State and territory law, evidence needs, cross-border hosts, payment-provider rules, and platform interfaces differ and can change. A platform report, host removal, search delisting, cybercrime report, and police report are distinct outcomes; none guarantees a takedown, refund, account action, or identification of the person behind an account.

Continue Reading