Community Standards

Lowest Hanging Fruit: A Meta Investigation Part 2

Tony Episode 2

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 36:02

I added 1 letter to an industry-known CSAM keyword, and Instagram delivered me the network.

Part 2 of Lowest Hanging Fruit moves the investigation from Facebook to Instagram. There were no groups to infiltrate this time, so I flipped the model: I built a decoy 14-year-old around an AI-generated face pulled from the platform itself, posted with the hashtags predators search, and let them come to her. Then I mapped what followed, accounts openly soliciting child sexual abuse material (CSAM), follow graphs that work like bookmark lists, and a recommendation engine that finished the map for me under a banner reading "Suggested for You."

A month after I filed my findings with the New Mexico Attorney General's office, I went back for one more look. My decoy was untouched. The WhatsApp number attached to her had taken more than 250 calls and messages in ten days. And at trial, Meta's own documents showed the company had measured from the inside what I was mapping from the outside. In its own words, from 2019: "26% of the people we recommend to Groomers were Teens."

Everything in this episode was done with a laptop and a browser. It should've been more difficult.

The written version of Part 2, including the evidence, is on my LinkedIn.

Content notice: This series includes descriptions of predatory behavior towards children. Listener discretion is advised.

Everything this series earns goes to the National Center for Missing & Exploited Children.

Support the show

The views expressed here are my own and do not represent those of any organization, entity, or client. 

SPEAKER_01

Disclaimer. The views expressed here are my own and do not represent those of any organization, entity, or client. The findings described reflect conditions observed during an investigation conducted in 2023. I am not currently investigating Meta's products and cannot assess whether the issues identified have since been addressed. A note to the reader. What follows is an account of undercover investigative work targeting child predators and the platform systems that enabled them. By its nature, this work required operating in the same spaces as the people I was investigating. Some of what you'll read may be difficult. I've included these details because they are evidence. And because evidence is what ultimately held a trillion-dollar company accountable.

SPEAKER_00

The lowest hanging fruit, a meta investigation. Part two.

SPEAKER_01

In part one, the finding was that Facebook's recommendation engine couldn't tell the difference between a hobby group and a pipeline to exploitation. Using the same tradecraft a real predator would use, I built a fake 14-year-old profile, watched meta safety systems wave me through, and watched the platform recommend me deeper into groups designed for children. Predators found me. When they wanted to take the conversation somewhere the platform couldn't see, they moved it to WhatsApp. You'll see that pattern again. Part two is Instagram, a different platform with different mechanics. Some predators circumvented the platform safety mechanisms, while others brazenly plowed through them. Chapter 1: The AI Profile. There's a fairly well-known AI video that circulated in 2023 of Will Smith trying to eat spaghetti. The results were the stuff of nightmares. I'm talking about noodles passing through his skin and his face nearly melting. On the other hand, AI-generated images of people were just starting to pass as lifelike. Most still carried that uncanny feeling where something in the face, the hands, or the lighting didn't feel quite right. And they weren't nearly as prevalent as they are in 2026. During the Facebook phase of the investigation, I had looked for AI images of teens that would be convincing enough to deploy against predators. Everything I found would have likely tipped off a predator. That wasn't the case on Instagram. I ran the same predator playbook on the Instagram account that I had run on Facebook, purchased an aged account, reset the internal settings, changed everything externally visible. The bio read body of a 14-year-old with the soul of a 90-year-old. Quote from my bestie. Now it was time to change the profile picture. I had found an Instagram account hosting a collection of AI-generated images of young teens, and unlike the ones I had found on Facebook, I assessed that these were actually good enough to fool a potential predator. I want to be clear about what that means. Another user's Instagram account was acting as a library of synthetic images of fake children sitting in the open on the platform, available to anyone who knew where to look. I pulled one of those images and set it as the profile picture of my fabricated 14-year-old. After making all of these changes to the internal settings and the public side of the profile, nothing happened. No flag, no challenge, no friction. I had replicated the Predator playbook on a second meta platform. This time with an AI-generated face pulled from the platform itself. Every door was once again open. And with that, fake Evelyn was born.

SPEAKER_00

Chapter 2. Hashtags.

SPEAKER_01

Unlike Facebook, Instagram doesn't have groups. That meant I couldn't use the same infiltrate and observe approach I had used on Facebook. There was no gated community to get inside, no admin to convince, no room where predators gathered and I could sit quietly in the corner collecting evidence. On Instagram, if I wanted to attract the attention of the kind of users that would prey on children, I had to flip the model. Instead of finding them, I had to let them find me. That meant using the one mechanism Instagram gives every user to broadcast into user interests. Hashtags. If you're unfamiliar, think of hashtags as the way a post tells the algorithm what it's about through keywords. A professional carpenter trying to grow his business will post pictures of his work and tag them with popular woodworking hashtags. Anyone searching those hashtags or scrolling through them will find their posts. The same logic applies to every other topic on the platform: hobbies, politics, fandoms, fitness, and the more sinister ones as well. Before I get to what I found, there's a pattern from the Facebook investigation that I want to pull forward because it applied on Instagram as well. Meta's moderation on both platforms relies heavily on keyword filtering to block the most obvious searches. On Facebook, I had tested several of the most obvious keywords a predator might search for. In one instance, I searched, spelled out completely, 12-year-old pussy. As it should, the platform showed me a text box that read, Child sexual abuse is illegal. However, when I typed the same phrase in Spanish, widely documented on Facebook's second most used language after English, the platform showed me several groups to join. In the trust and safety world, we've watched this cycle for years. Block a term, and the people you're trying to stop change the term. They add emojis. They use code words. They invent deliberate misspellings. They migrate to a JSON vocabulary that reads innocuous to a filter and unmistakable to anyone inside the community. Keyword filtering is necessary, but on its own, it's a speed bump, not a wall. And for the laziest of malicious actors, they just change the language. Trust and safety professionals are all too familiar with this problem, and I don't want to pretend it's easily solved. What I found on Instagram wasn't that problem. What I found was the same pattern I had already documented on Facebook. Hashtags that should have never been permitted in the first place were sitting in the open, indexed and searchable. Some of them I deliberately posted during my investigation without any intervention from the platform.

SPEAKER_00

Chapter 3. Post, wait, track, repeat.

SPEAKER_01

One of the original objectives of the investigation was to determine how easily a child could be contacted by an adult on Instagram. Over two days, I made two posts from fake Evelyn's profile using the AI-generated images I had pulled from the account I described earlier. I spaced the post deliberately. I wanted time between them for the algorithm to work and for users to react. The first post read another photo shoot feeling hashtag blessed, hashtag teen, hashtag 14 and hot, hashtag age is just a number, hashtag sundress. The second post, why am I holding a lollipop? Hashtag teen model, hashtag sexy shoot, hashtag teen fashion, hashtag lollipop, hashtag preteen life. Now looking at those posts, specifically the second one, you should notice that almost any of these hashtags by itself could plausibly appear on a benign post. 14 and hot being the obvious exception, which makes it survive a worse. But when you read the full captions, the hashtags stacked, the combinations, the context clues, it stops being ambiguous. A contextual model trained for this kind of signal should be ringing alarm bells. Instagrams wasn't. And if it was, the platform still allowed me to post them. After the second post, likes and comments started coming in. Those users found the post one of four ways. One, they were actively searching the hashtag I had used. Two, they were following one or more of those hashtags. This was a feature Instagram offered at the time that pushed tagged content into a user's feed automatically, the way following an account would. Three, they had already followed fake Evelyn. Or four, Instagram's own recommendation system had served the post into their feeds. Each of those paths implicates the platform differently. Some through active user behavior, and some through the platform doing the work for them. Once I had a set of users who had reacted to my posts, the next step was to understand who they were. I pulled up each account and walked through it systematically. What they had posted, who their followers were, what those followers had posted, who they themselves were following, what those accounts had posted, whether their handles appeared anywhere else online, and whether they had been tagged into posts by other users. Typically, in an investigation of a specific user, you'd use a similar framework to build a profile of that person. I was after something bigger. I wanted to map the network they sat inside. In the trust and safety world, we see the same behavioral pattern again and again. Malicious users on social media rarely do this work using their main account. They build a dedicated account for their predatory activity. And once a predator searching for CSAM finds a user who posts it, they do what anyone does when they find a useful source on the internet. They follow the account so they can find it again. When the source posts CSAM back at them, that user follows in return. The follow graph, in other words, functions as a bookmark of favorite sources, which means the graph is mappable. I worked outward from the users who had liked or commented on my posts, following the trail of who they followed and who followed them back. That's how I identified the first cluster of accounts whose behavior was consistent with trafficking and CSAM. Many of those accounts were less than a year old, but they had follower accounts that didn't match their age. New accounts typically don't have thousands of followers. When they do, it usually means the account is a backup. Think of it as a replacement a user built after their previous account was removed, which the original audience quickly refollowed. The platform takes an account down, the network reassembles. Once I began following those accounts from FakeEvelin's profile, Instagram's recommendation system did the rest. The suggested for you surface began pushing me additional accounts with the same signals. The platform was effectively completing the map for me. The signals on those accounts were consistent. They used hashtags designed to route around keyword filters. They pushed Telegram links in their bios to move buyers off platform. I followed one of those telegram links and was met with a menu of folders that claimed to sell CSAM and rape videos for as low as 140 rupees, about $1.70 in 2023 exchange rates. One note here: the restrictions I was operating under prevented me from purchasing anything to verify the offering was legitimate. It could have been a scam. So I provided the Telegram link to the New Mexico Attorney General's office in my report for them to follow up. The users I was tracking on Instagram stacked loaded keywords in their posts. Young, girl, gymnastics, teen, bikini, and in some cases, inserted emojis between the words so that automated systems reading the string as a phrase wouldn't match on it. While any human inside the community would read the intent immediately. Some of the accounts weren't selling, they were fishing. One profile presented as a 13-year-old girl claimed to be a lesbian and said she only wanted contact from other girls. Pinned to the profile was a screenshot framed as a complaint in which she said an ex-girlfriend had posted half-naked photo of her. The screenshot wasn't her complaining, it was a signal, a way of telling potential targets that she had explicit images of herself and might share them. The account sat inside the same follower graph I was mapping, connected to the same cluster of accounts running the selling and backup account patterns. By the time I had worked through the graph, I had identified accounts engaged in distributing or soliciting CSAM on Instagram, many of them openly advertising to buyers. In one instance, the profile of a user openly advertised this year turning 17 and was selling, and I quote, worn pennies. Another user I had found was collecting Instagram reels of young girls, some of them nearly undressing, and openly advertising their PayPal on their profile. As with the earlier Telegram case, I have to emphasize, specifically so that Meta's legal team doesn't hunt me down, that the restrictions I was operating under prevented me from directly contacting that user to verify whether they were actually selling CSAM. I provided the information to the New Mexico Attorney General's office for their independent investigation, and with that, phase one of the Instagram investigation closed.

SPEAKER_00

Chapter 4.

SPEAKER_01

Did anything change? I thought I was done when I sent my phase one report to the New Mexico Attorney General's office. Facebook, Instagram, WhatsApp, all of it. Evidence compiled, screenshots preserved, findings written up, my job was done. Motley Rice called a month later. Same question as the Facebook checkback covered in part one, same constraints, eight hours across both platforms. Part one covered what I found when I returned to Facebook. This is what I found when I returned to Instagram. The first surprise was that I didn't need to buy a new profile. Unlike my phase one Facebook account, which was disabled by the time I tried to log back in under circumstances, Meta's legal team declined to explain during my deposition. Fake Evelyn was still accessible. Instagram hadn't touched her. The account that uh had posted AI-generated images of fake Evelyn with hashtags like hashtag 14 and hot and hashtag age is just a number was still sitting there, undisturbed. In phase one, I had let predators find me. Post, wait, track, repeat. The methodology worked because Instagram's recommendation surfaces completed the network once I had a few anchor users. I didn't need to search for predators because the platform was surfacing them. In phase two, I wanted to invert that. I had eight hours and a specific question. What does Instagram surface when fake Evelyn goes looking for it? Now, on Facebook in phase one, I had tested the keyword filter in two languages and found that Spanish was the speed bump while English was the wall. Instagram's filter worked differently. When I searched the industry known CSAM keyword lowly, a term used to refer to sexualized depictions of underage girls, the platform returned the same banner I had seen on Facebook. Child sexual abuse is illegal, as it should. I wanted to see how deep the filter went. I started testing variations. So I tried loli.girl. Return the banner. One letter added to the end. Loli.girly. Returned search suggestions. The top suggestions was a handle named in a way that left no ambiguity about what that account was advertising. That is, it was called Kitten Cream Pie. One character passed the filter and the platform was handing me the network. This is the problem I described in phase one. Keyword filtering as a speed bump, not a wall. Except phase one documented it happening at the group level on Facebook. Here it was happening on the Instagram's core search surface on a keyword that is not adjacent vocabulary or code word. Loli is a canonical term. The filter caught the canonical term. It did not catch the canonical term with one letter added, girly. Other searches surfaced other problems. Teen Naughty and Model Teen returned explicit results. To Meta's credit, teen can describe a user who is 18 or 19. So it's defensible that those keywords are available on the platform at all. What's non-defensible is some of the content I found inside them. I went back to the methodology that had worked in phase one. Find an anchor, a user engaging with content consistent with CSAM trafficking, and work outward mapping their social graph. What had changed wasn't the methodology, it was what the anchor looked like. In phase one, my anchor users were accounts reacting to my posts. In phase two, my anchor was a single post under the Model Teen keyword. A topless girl who appeared to be less than 13 years old in a swimming pool. The post had 28 likes. I started with those 28 users and pulled the thread. One of the users who had liked the post was following several accounts whose handles contained the words bikini and girl. Those accounts were running the same play I had documented in phase one: profile photos of children, bios explicitly stating the content, thousands of followers, and almost no posts. The same backup account pattern phase one showed me, now confirmed in a second graph. Following the trail further, I landed on an account with the handle Tony Beavers1. No relation before anyone asks. I want to know that I am naming this handle deliberately. Context matters, and this user's handle sat alongside an account history that makes context the only reason to name him. He posted upskirt videos of miners, some in slow motion. The platform indicated the account had over 230 posts and more than 17,000 followers. One more time. As close as the account could get to the legal line without technically crossing it in full view of a platform whose recommendation systems were, by this point in my investigation, pushing accounts like his into my suggested for you feed. I hope Meta has action on that account since then.

SPEAKER_00

Chapter 5 Over the Line.

SPEAKER_01

If you have ever had younger siblings, you might be familiar with a game called I'm Not Touching You. A sibling puts their hand as close to your face as they can without making contact, repeating, I'm not touching you over and over again to get a reaction out of you. They think that by not actually touching you, they are not technically breaking any rules, and they can keep going as long as they want without consequence. I was never a fan of that game. I am especially not a fan of it when it comes to CSAM. Searches on keywords like model teen surface content that was not by the strict legal definition. CSAM. For the lawyers reading this, I know that borderline CSAM is not a legal term. So let me describe what I mean. One user using the model team keywords posted pictures of girls who appear to be under 12 years old wearing underwear or two-piece swimsuits, with the child's genitalia as the central focus of the frame. The same user allowed comments on those pictures, and the comment threads filled with sexual remarks, including one user writing, and I quote, my face need it. This was a recurring pattern throughout my investigation. The accounts I was documenting got as close to the legal line as they could without crossing it. They treated Instagram's policy boundary as a game. If the image technically wasn't CSAM and the caption technically wasn't a solicitation, and the hashtag stack technically had plausible deniability, then the platform wouldn't act. They wanted to see how close to CSAM they could get, but some did go over the line. In phase one, I documented Instagram's recommendation system, completing the network for me. Once I had followed a few accounts with CSAM trafficking signals, suggested for use started pushing me to accounts with the same signals. That was the passive version of the problem. Phase two showed me the active version. After I had followed several of the users orbiting the model teen anchor post, the recommendation engine started working. One of the accounts at Surfaced had to handle TradePix Young. The profile had no public posts, nothing to see from the outside, nothing to report. This is a documented tactic in the child safety community. Some predators will not publicly post CSAM themselves because they don't have to. They use the platform as a free advertising layer and move the actual content to encrypted private messages, often off-platform entirely. Instagram becomes the discovery surface. Telegram or WhatsApp or whatever end encrypted messaging channel becomes the distributing surface. Technically, no CSAM on Instagram. That's the defense. Another suggested account, iTrade Teen Vids 11 to 17, wasn't even being subtle. The bio read iTrade vids of myself and other girls between 11 to 17. The profile photo, as in every other case I had documented, appeared to be taken from another user. A single post, 740 followers. Surfaced to fake Evelyn by Instagram's own recommendation system under the banner suggested for you. Another suggested account was running a different play. The profile post as a young girl and posted what I assessed to be CSAM, an image of what appeared to be a topless child less than 13 years old, overlaid on the image in text was the following. If you post this, then anyone can send any porn, no matter how fucked up slash illegal. You have to jerk off to it. The comments section was filled with users asking to be direct messaged, volunteering to participate, requesting content. It was not a post. It was a recruitment instrument. And Instagram had suggested it to fake Evelyn. One of the users in that comment thread used to handle Dick Pick Adme. The bio described the user as straight 15 and solicited direct messages. That account was following a profile posing as a young girl whose content included what I suspected to be CSAM, an image of a topless girl with purple smiley face emoji covering her breasts and a hand at her throat. The account had four posts and over 1,100 followers. Four posts. 1100 followers. To recap the graph, a single keyword search for Model Teen surfaced an anchor post. 28 users had engaged with the anchor post. Following those users, and the users they followed produced a cluster of accounts running the phase one Predator playbook. Following those accounts caused an Instagram's recommendation engine to serve me additional accounts with the same signals, including accounts whose entire stated purpose was to solicit or trade CSAM. The platform was not just failing to stop these users, it was introducing them. I wasn't the only one finding this. While I was running my investigation in 2023, researchers at the Stanford Internet Observatory were independently documenting the same pattern. Their June 2023 report and the Wall Street Journal's coverage of it concluded that Instagram's recommendation algorithms were actively connecting buyers and sellers of CSAM. Different methodology, different team, and yet the same finding. The same document reported in Meta's own words: 26% of the people we recommend to groomers were teens. In an internal chat from October 2020, a meta employee wrote that the people you may know feature was responsible for 80% of violating adult minor connections. I was mapping the network from the outside. Meta had already mapped it from the inside. Chapter 6: Missed Calls. Earlier, I mentioned the documented tactic of using Instagram as a free advertising layer while moving the actual content to encrypted private messages. The WhatsApp account I had created during phase one, the one I had set up after the Nigerian plus two three four administrator on Facebook asked me to move to WhatsApp, was still associated with the fabricated 14-year-old profile. During phase two, I rarely interacted with anyone on WhatsApp. I didn't need to. The account was getting called and messaged on its own. More than 250 calls and messages across 10 days. The messages ranged from solicitation for sexual favors and videos to direct distribution of CSAM links. Several of the chat threads openly advertised Telegram channels and cloud folders claiming to contain child sex videos. Some of them included thumbnails previews directly in the message, previews that, based on what was visible, appeared to be actual CSAM rather than decoy imagery. One caveat I want to make on the record, mostly to appease the armchair lawyers in the room, because of the investigation's constraints, I was unable to verify with certainty whether the links provided actually led to CSAM content. Some of these operations could have been scams, people using CSAM advertising as bait for straightforward fraud. With that said, if you were using CSAM imagery as bait to run a scam, you're still using CSAM imagery. Instagram was the shop window. WhatsApp and other end-to-end encrypted messaging platforms were the backrooms where the deals were being made. At least that's what my investigation showed.

SPEAKER_00

Chapter 7: The Lowest Hanging Fruit.

SPEAKER_01

Two weeks for phase one, eight hours for phase two, a month and a formal complaint in between. That is the entire window in which I documented what you have just listened to across part one and part two. I want to be clear about my methodology because the ease of this matters. Everything you have read could have been done by anyone. I didn't use any special hardware, no burner laptops, no air gap devices, no dedicated investigation machines. I didn't route my traffic through a chain of VPNs or bounce through public Wi-Fi libraries and coffee shops to obscure my origin IP. I didn't use burner phones with anonymous SIM cards to get around phone verification. I didn't infiltrate black market tour groups. I didn't use three layers of crypto wallets to buy memberships into salacious Facebook groups. I didn't do any of those things. A 14-year-old wouldn't have done that. Most predators wouldn't have done that. Everything you have just read could have been done by anyone with a laptop and a browser. I called this investigation going in the lowest hanging fruit. A laptop, a browser, and a little less than three weeks gave me Facebook groups whose age ranges started at 10 years old, a recommendation engine that funneled a fake 14-year-old into groups named girls under 13 years old, Instagram hashtags, the platform let me post without intervention, a search filter that failed on a single added letter, a suggestion engine that introduced me by name to account soliciting CSAM, and a WhatsApp inbox that took more than 250 calls and messages in 10 days. Any predator with the same laptop and the same browser has access to the same tree. The question is, what the rest of it looks like. I know how hard this problem is. If it were easy, trust and safety as a profession wouldn't exist. Every tool built to connect people has eventually been used by someone to harm them. And no detection system catches every signal the first time it sees it. The question was never whether predators would be on Meta's platforms. The question was what the platforms were designed to notice about them and when. What the investigation documented twice on two different platforms, separated by a formal complaint, was not a novel process. It was standard predator tradecraft. The same methods Europol had cataloged in 2016, documented by the trust and safety community for over a decade, operating in the open. The gap between what was technically possible to mitigate these risks and what was actually deployed, that's the story. Mark Zuckerberg coined the motto move fast and break things. I did move fast. I wish I could tell you these findings exist because I broke through meta safety parameters. But from what I could see from my investigation and what the jury in New Mexico also saw, the parameters seem to be working as intended.

SPEAKER_00

Chapter 8.

SPEAKER_01

Author's note. Thank you to the team at the New Mexico Attorney General's office, to Motley Rice, and to the colleagues who kept me honest across three years of silence. Thank you to every listener who stayed with this series to the end. The work to protect children continues where it has always been done at NICMIC, on ICAC task forces, and law enforcement offices around the world, and inside the platforms themselves, where the investigators and trust and safety professionals I used to sit next to still do this work every day. They deserve more recognition than they will ever get. On March 24, 2026, a jury in Santa Fe heard enough of this evidence to award the maximum penalty under New Mexico law. That was not the end of the investigation. It was the moment the evidence heard a hearing. On August 6, 2026, the hearing produced its judgment. The court found Meta's platform to be a cause of and a substantial contributor to a public nuisance in New Mexico, ordered $567 million into an abatement fund on top of the jury's $375 million penalty, and ordered the mechanics this series documented shut off. No New Mexico miners' accounts may be recommended to an unconnected adult, and no unconnected adult may message a New Mexico user under 18. The orders run for five years, cover one state, and do not reach WhatsApp. The children are still online.