Copy article

Pornhub ransom and Discord ID leaks prove the UK’s Online Safety Act is a privacy death trap

ended 18. December 2025

The reported extortion of Pornhub by the "ShinyHunters" hacking group is the final nail in the coffin for the argument that "safety" requires surveillance. This breach, combined with the catastrophic Discord leak earlier this year, creates an undeniable pattern: if you build databases of user identities, they will be stolen.

The UK’s Online Safety Act—fully enforceable as of July 2025—mandates that platforms collect "highly effective" age assurance. In plain English, this forces sites to hoard government IDs or sensitive biometric data. We were promised this data would be "blind," "secure," and handled by trusted third parties.

That promise is now a lie.

The situation with Pornhub is a chaotic warning of what’s to come. ShinyHunters told Reuters the data was connected to a recent incident at Mixpanel, a third-party analytics provider. Mixpanel has denied this claim, stating they conducted a thorough investigation and found no indication the data came from them.

This very confusion is the point. We are watching a "he said, she said" battle over where the leak came from while user data is held for ransom. It highlights the terrifying opacity of the digital supply chain. It doesn't matter if the platform itself is secure if the "trusted partners"—or the partners of those partners—are vulnerable.

Add to this the Discord breach, where a third-party support partner exposed government IDs users had uploaded for age verification. We are not just dealing with theoretical risks; we are seeing the real-time collapse of the security infrastructure the UK government is forcing on every adult platform.

We are mandating the creation of the world’s most valuable blackmail databases. When the Online Safety Act forces a smaller, less secure platform to hold your passport data to let you view legal content, who is liable when that database hits the dark web? The government who mandated it, or the user who just wanted privacy?

We’d like your views:

  • With the confusion over the Mixpanel connection, how can the government mandate age verification when platforms cannot even guarantee the security or origin of a breach?
  • Does the ShinyHunters extortion attempt prove that any link between real-world identity and adult content is a target too lucrative for hackers to ignore?
  • If a site is legally forced to collect ID data and then gets breached (or their third-party vendor does), should the government be held liable for the resulting identity theft?
  • Given that major tech platforms have already lost government IDs uploaded for age checks, is it negligent for the UK government to force smaller sites to hold this toxic data?
  • Are we accepting a "privacy recession" where handing over a digital passport is the mandatory entry fee for the open internet?

Source 1: The Verge report on Discord government IDs leaked in data breach. https://www.theverge.com/news/797051/discord-government-ids-leaked-data-breach

Source 2: Reuters report on ShinyHunters claiming theft of Pornhub user data. https://www.reuters.com/world/americas/hacking-group-shinyhunters-claims-theft-data-users-leading-sex-site-pornhub-2025-12-16/

4 responses from the Newspage community

Copy all

Star Quote
Copy

We are watching the inevitable collision between political wishful thinking and cybersecurity reality. I’ve spent a decade in tech implementation, and the first rule is simple: if you build a centralised database of high-value data, it will be breached.

The ShinyHunters ransom isn't a glitch; it’s the direct result of forcing platforms to hoard toxic data. The government’s reliance on "trusted third parties" is a fantasy. As the Pornhub/Mixpanel confusion proves, digital supply chains are terrifyingly opaque. You don't just trust the platform; you trust their vendors, and their vendors’ vendors.

By enforcing age verification via ID, the UK is compelling companies to build the world’s most lucrative blackmail archives. When Discord leaks IDs and adult sites are ransomed, it proves digital age checks are a security catastrophe. If the government mandates the collection of this data, they must accept liability when, not if, it hits the dark web.
Copy

We’re about to make Brits show a digital passport to watch legal content, then act shocked when it gets stolen. The Online Safety Act pushes “highly effective” age checks. In real life that means passports, selfies, maybe biometrics, held somewhere by someone. That is not safety. That is a data honeypot. Pornhub being extorted and Discord leaking uploaded IDs are not freak accidents. They’re the business model of modern hacking. Link a real name to adult behaviour, and you’ve created premium blackmail material. Of course, criminals will chase it. And the Mixpanel “was it, wasn’t it” noise proves the bigger problem. Nobody really knows where data flows once vendors and sub-vendors get involved. Your platform can be solid and still get burned by a supplier with sloppy access. Small sites will be forced to do what big tech can’t do safely. That’s not protecting people. That’s outsourcing risk to the public and calling it policy.
Copy

The government is forcing everyone to hand over their passport to criminals in the name of child protection. Without a shadow of doubt, mandatory age verification creates irresistible honeypot targets for hackers who know your real identity is worth thousands on dark web markets. Right now, many platforms are stockpiling government IDs because the Online Safety Act demands it, building what amounts to Britain's largest blackmail database with your personal documents.

Here is what you should do immediately. Never upload government identification to any platform unless absolutely essential, regardless of what the law requires. Use virtual private networks (VPN) to access content from jurisdictions without these checks. Do consider whether any online service is worth surrendering documents that could destroy your reputation or career if they got leaked.
Copy

This extortion proves what security experts already knew: you cannot make adult content databases safe enough. The economics are too brutal. Every government ID uploaded creates a permanent hostage file worth thousands in blackmail leverage. Sophisticated attackers will always find the weakest link in the supply chain, whether that's Pornhub, Mixpanel, or the provider nobody's heard of yet.

This isn't a security failure, but rather predictable market dynamics. The Online Safety Act has legislated the existence of databases that are more valuable to criminals than the youngsters it's meant to protect.

We've made extortion scalable and blackmail inevitable by mandating the one thing security professionals never recommend: concentrating sensitive identity data with stigmatised behaviour records.

When the reward for breach is this high, no third-party vendor can be "secure enough." The government didn't create age-based gating. They created a honeypot, and adults are the bait.