Pornhub ransom and Discord ID leaks prove the UK’s Online Safety Act is a privacy death trap
The reported extortion of Pornhub by the "ShinyHunters" hacking group is the final nail in the coffin for the argument that "safety" requires surveillance. This breach, combined with the catastrophic Discord leak earlier this year, creates an undeniable pattern: if you build databases of user identities, they will be stolen.
The UK’s Online Safety Act—fully enforceable as of July 2025—mandates that platforms collect "highly effective" age assurance. In plain English, this forces sites to hoard government IDs or sensitive biometric data. We were promised this data would be "blind," "secure," and handled by trusted third parties.
That promise is now a lie.
The situation with Pornhub is a chaotic warning of what’s to come. ShinyHunters told Reuters the data was connected to a recent incident at Mixpanel, a third-party analytics provider. Mixpanel has denied this claim, stating they conducted a thorough investigation and found no indication the data came from them.
This very confusion is the point. We are watching a "he said, she said" battle over where the leak came from while user data is held for ransom. It highlights the terrifying opacity of the digital supply chain. It doesn't matter if the platform itself is secure if the "trusted partners"—or the partners of those partners—are vulnerable.
Add to this the Discord breach, where a third-party support partner exposed government IDs users had uploaded for age verification. We are not just dealing with theoretical risks; we are seeing the real-time collapse of the security infrastructure the UK government is forcing on every adult platform.
We are mandating the creation of the world’s most valuable blackmail databases. When the Online Safety Act forces a smaller, less secure platform to hold your passport data to let you view legal content, who is liable when that database hits the dark web? The government who mandated it, or the user who just wanted privacy?
We’d like your views:
- With the confusion over the Mixpanel connection, how can the government mandate age verification when platforms cannot even guarantee the security or origin of a breach?
- Does the ShinyHunters extortion attempt prove that any link between real-world identity and adult content is a target too lucrative for hackers to ignore?
- If a site is legally forced to collect ID data and then gets breached (or their third-party vendor does), should the government be held liable for the resulting identity theft?
- Given that major tech platforms have already lost government IDs uploaded for age checks, is it negligent for the UK government to force smaller sites to hold this toxic data?
- Are we accepting a "privacy recession" where handing over a digital passport is the mandatory entry fee for the open internet?
Source 1: The Verge report on Discord government IDs leaked in data breach. https://www.theverge.com/news/797051/discord-government-ids-leaked-data-breach
Source 2: Reuters report on ShinyHunters claiming theft of Pornhub user data. https://www.reuters.com/world/americas/hacking-group-shinyhunters-claims-theft-data-users-leading-sex-site-pornhub-2025-12-16/




