Editors Note: This piece is the practical, step-by-step follow-up to my last article, Your Face Is No Longer Yours (And Meta Doesn’t Care). While that article explained why and how tech platforms fail us, this playbook is all about action. Below, you will find concrete tools, survivor-led tactics, and alternative security steps to protect human rights defenders, journalists, and everyday citizens when big tech monopolies choose to look away.
The most dangerous thing about a deepfake is not always that people believe it. Sometimes the damage is already done before anyone figures out it is fake.
A manipulated video can travel across Instagram, Facebook, WhatsApp, X, TikTok and private group chats in hours. It can be downloaded and copied instantly, reuploaded across accounts, burner profiles, stripped of its original context, and weaponized into targeted harassment, impersonation, sexual violence, political disinformation or reputational assault. It hijacks a target’s likeness to inflict severe psychological and real-world harm before they even know it exists. And once the weaponized content enters algorithmic circulation, the target is often left alone to clean up the wreckage.
That is one of the clearest lessons from recent Meta Oversight Board cases: platform safety architectures are still fundamentally reactive, highly fragmented, and structurally designed to shift the burden of proof and policing onto the victim. Last week, I provided a full diagnostic autopsy of this structural failure, mapping its fallout across two women from entirely different worlds.
We saw Dorothy McHugh, a 77-year-old Scottish local councillor, whose likeness was hijacked by a deepfake video ahead of an election. Meta hid behind a legacy “public figure” loophole, allowing the video to circulate for ten months while automated systems blocked her from reaching a human reviewer.
Alongside her stood a young Muslim health advocate in Europe whose television interview was altered by generative AI into a series of humiliating videos. Meta’s algorithms summarily rejected her reports because of a hyper-narrow policy gap: since the video fabricated her conduct rather than altering her physical anatomy, the platform ruled it did not count as a violation.
When tech giants apply these rigid, checklist-driven policies to complex human realities, they create dangerous gray areas that bad actors systematically exploit. And the human toll is immediate: severe character defamation, targeted xenophobic and misogynistic harassment, and prolonged psychological re-traumatization.
In this playbook, we pivot from diagnosis to design: what should you actually do if this happens to you, a colleague, or a community you are defending?
1. Preserve First. Report Second.
Before reporting a harmful deepfake, document and preserve evidence first, then report. This may feel counterintuitive. When confronted with a digital attack, our immediate visceral instinct is to “get this down immediately” and hit that report button. This is a trap. In the rush to erase the harm, users often delete the very proof required to stop it. Posts disappear, accounts get suspended, captions change, and copies move elsewhere. Once content is scrubbed by the platform, the evidence you need for an appeal, legal recourse, journalism, or advocacy vanishes with it.
Before you touch a platform’s reporting forms, you must document the pattern. Capture transient information that is at risk of being moved, altered, or lost completely.
Record raw video screen recordings and capture screenshots of the deepfake playing in real time, capturing how it renders on screen.
Log the exact account names and handles, and copy the full URLs of the source profiles.
Document the temporal context: record the precise date, time, and timezone of your capture.
Capture the surrounding engagement and context: document captions, comment sections, reposts, trackbacks, and visible engagement metrics.
If the content is spreading across multiple accounts or platforms, track them in a central place too. Document the pattern (coordinated ecosystem) rather than treating each upload as an isolated incident.
The rule is absolute: Capture essential, high-risk data at its point of origin before platform intervention makes it disappear.
Tools & Resources
Hunchly (Desktop Software): A professional-grade digital investigation tool that runs silently in your browser background. It automatically records, logs, and timestamps every URL, webpage, and image you visit, creating an unalterable history built to serve as valid legal evidence.
Internet Archive’s Way Back Machine or Archive.today (Web Tool): A free, instant way to take a permanent text and graphic snapshot of a specific URL. Even if the perpetrator deletes the post or gets suspended, the archived snapshot remains public and unchangeable.
Starling Lab for Data Integrity: A highly innovative project by Stanford and USC utilizing decentralized web protocols and cryptographic hashing to create immutable, tamper-proof ledgers of visual evidence, ensuring digital chains of custody that withstand corporate deletion.
OSINT Framework: The primary web-based directory that organizes open-source intelligence tools into a structured, browsable tree. It is maintained by the OSINT community to pivot through data categories (usernames, emails, maps, etc.) without relying on commercial software dashboards.
2. Report the Underlying Violation (the Harm), Not the Technology
This is where people lose critical time. A deepfake is a mechanism; the specific abuse it produces it executes is the actual policy infraction and violation.
One of the biggest structural mistakes of tech platforms’ trust and safety teams is their obsession with authenticity over intent—treating synthetic media as a technical box to check. But the critical question is never, “Is this file fake?” It is “What is this fake being weaponized to achieve?”
If someone uses a manipulated video to humiliate a woman, impersonate a public figure, spread hate, distribute non-consensual sexual content, or incite harassment, report the underlying policy violation rather than generic AI labels. Report it as:
Harassment, stalking, or bullying
Wholesale impersonation
Hate speech or incitement to violence
Non-consensual intimate imagery (NCII) or sextortion
Deception, fraud, or identity theft
The rule is absolute: The synthetic media is simply the vehicle; report the real-world harm as the policy violation.
Tools & Resources
Take It Down (by NCMEC) (Under 18): A free, anonymous tool operated by the National Center for Missing & Exploited Children explicitly designed to stop the online spread of non-consensual explicit images or deepfakes of individuals under 18.
StopNCII.org (for adults, global coverage): The gold standard for intimate deepfake removal worldwide. Operated by the Revenge Porn Helpline in partnership with a global council of international NGOs, this platform uses secure, on-device hashing technology. The multi-language interface allows global victims to generate security hashes to stop sharing across networks (including Meta) without their media files ever leaving their devices.
Chayn: A phenomenal, independent survivor-led global majority movement that builds open-source, multilingual digital safety resources and trauma-informed reporting pathways for gender-based violence, completely outside corporate templates.
Platform Direct Reporting: Skip generic “AI” forms and automated generic feedback loops. Use Meta’s direct dedicated reporting channels for Harassment/Bullying, Impersonation (Facebook Form or Instagram and Threads), or Hate Speech, or sextortion, to trigger stricter policy enforcement and a more stringent review.
3. Record and Appeal Every Automated Rejection
Never assume that a rejected report means the content complies with platform and community guidelines. Automated moderation systems handle the vast majority of first-line platform triage, and they routinely mistake and misread context, subtext, and localized language.
If the platform gives you an option to appeal, use it immediately. Keep a meticulous log of the corporate response: screenshot your original report submission, the automated rejection notification, and the subsequent appeal confirmation.
This matters because while your single failed report is a frustrating administrative hurdle, it can also become evidence of a broader systemic enforcement failure, especially if multiple people report the same content and Meta repeatedly declines to act (part of a logged trail). And this can be be escalated to regulatory authorities.
The rule is absolute: Treat every automated rejection as an appealable technical error rather than a definitive corporate ruling.
Tools & Resources
Oversight Board Appeals Portal: If you exhaust Meta’s internal appeal options and severe, high-stakes content remains online, check your eligibility to submit your case directly to the independent Oversight Board for binding evaluation.
Digital Rights Foundation (DRF) Cyber Harassment Helpline: A pioneering grassroots initiative in South Asia that offers specialized support tracking, documenting, and contesting automated platform rejections for regional language users facing weaponized online harassment.
Moderation Evidentiary Tracker (Template): Create and maintain a simple spreadsheet logging: Platform Reference ID #, Source URL, Date Reported, Initial Automated Decision, Date Appealed, and Final Enforcement Outcome. Attach timestamped screenshots to keep your paper trail intact.’
4. Don’t Accidentally Make the Deepfake More Viral.
Say it with me: debunking should not become amplification.
This is a common trap and one of the hardest psychological parts of responding to manipulated media. When targeted by a malicious campaign, people understandably want to publicly expose the lie. However, quoting, embedding, or reposting the full original deepfake video—even to condemn it—feeds the platform’s algorithms recommendation engines, distributes the media to new audiences, and scales the original harm.
The objective is to provide enough baseline context to to explain the abuse (neutralize the deception) without becoming another free distribution channel for the perpetrator. Implement defensive communication tactics. Consider using:
Utilize static, flat screenshots rather than moving video files.
Apply heavy pixelation, crops, or blurs to sensitive visual elements.
Isolate short, specific audio/visual fragments rather than whole files.
Superimpose aggressive text watermarks directly over the graphic.
Rely on precise, purely text-based descriptions of the manipulation.
The rule is absolute: Isolate and describe the deception; never hand the original file a second algorithmic lifecycle.
Tools & Resources
Redacted App (or Signal Media Editor): Free tools to quickly blur faces, crop out identifying details, or place heavy text watermarks (e.g., “MUTILATED/ DECEPTIVE MEDIA”) across a screenshot before sharing it for awareness.
Canva (Text Overlay): If you must share a frame to debunk it, use Canva or similar editing tool, to slap a bright, unmissable banner over the image so it can never be screenshotted and reused maliciously out of context.
WITNESS "Prepare, Don't Amplify" Guide: An invaluable methodology developed by my team at the global human rights organization WITNESS, showing grassroots advocates how to expose synthetic deception safely without inadvertently triggering algorithm-driven viral loops.
5. Play Whack-a-Mole Strategically
Deepfake harm rarely stays confined to a single upload. Once a video begins circulating, people can download it, crop and re-edit it, add new captions, change the audio or cross-post it to entirely different platforms and accounts. Removing the initial post often does very little to stop the momentum. To track copies, you must search laterally:
Monitor highly distinctive phrasing, syntax patterns, or specific typos from the original caption.
Track the accounts and network profiles driving high engagement volumes in the original comment sections.
Audit variants of the subject’s name across secondary platforms and alternative networks.
Maintain a centralized tracking log of new instances, duplicates, noting when they appeared and which accounts are posting them and driving the engagement.
This is an area where platforms must do far more. Once a piece of manipulated media is determined to violate platform rules, the target should not have to spend weeks chasing down identical variations, playing whack-a-mole with hundreds of copies.
The rule is absolute: Look for copies, not just the original. Do not treat lateral copies as isolated anomalies; track them as interconnected nodes of a single distribution campaign.
Tools & Resources
Google Reverse Image Search & TinEye: Upload a clean screenshot or still frame from the deepfake to run a reverse-image lookup, tracing where else the file or its direct visual variations have been hosted across the web.
Google Alerts & Talkwalker: Set up real-time keyword alerts for the specific phrase, hashtag, or target victim’s name used in the deepfake caption to catch new uploads instantly.
Bellingcat Digital Toolkit: A community-driven, public-interest collection of open-source methodology tools designed by independent researchers to trace media footprints, cross-reference metadata, and map coordinated distribution networks without corporate assistance.
6. Escalate Outside the Corporate Ecosystem
Meta and Silicon Valley executives cannot be the ultimate arbiters of human safety. Depending on the situation and jurisdiction, a weaponized deepfake routinely crosses the threshold into explicit criminal or civil violations, including stalking, extortion, character defamation, identity theft, fraud, civil rights violations, and coordinated election interference.
When an attack escalates and the harm becomes more serious, look past corporate chat bots and broken platform reporting forms. Connect early with journalists legal counsel, independent digital rights organizations and coalitions, civil society groups, investigative journalists, and relevant regional regulatory watchdogs. A glitchy or unresponsive platform reporting form or chatbot is never your only avenue of recourse.
The rule is absolute: Bypass corporate dead-ends by establishing external, legally sound points of legal and civil escalation early.
Tools & Resources
Cyber Civil Rights Initiative (CCRI): Offers a 24/7 crisis helpline (1-866-411-5237) providing legal resources, safety planning, and emotional support for victims of non-consensual intimate imagery.
Local Cybercrime Reporting: File a formal report with federal cybercrime divisions (like the FBI’s IC3 in the US, or your regional equivalent) to build a legal paper trail. Here is a list of cybercrime agencies by country.
European Digital Rights (EDRi) & Electronic Frontier Foundation (EFF): Powerful, independent civil-society networks in Europe and the US that bypass corporate channels to monitor structural policy failures, leverage regulatory frameworks (like the EU’s Digital Services Act), and advocate for systemic, non-corporate platform accountability.
Access Now Digital Security Helpline: A global non-profit rapid-response emergency helpline offering 24/7 digital security and legal support in 9 languages (including Arabic, Spanish, French, Portuguese, Russian, Tagalog, Ukrainian, and Chinese) to help secure accounts, mitigate active digital attacks, and bypass broken algorithmic forms.
Digital Rights Networks: Best for region-specific legal and localized civil society escalations. In regions where English-centric reporting forms fail, look to localized digital defense groups (like Luminate and Global Voices , Hiperderecho and TEDIC in Latin America, SMEX (Social Media Exchange) in the Arabic-speaking region, 7amleh the Arab Center for Social Media Advancement (focus on Palestine and Israel), or Digital Rights Foundation in South Asia) that maintain direct, high-priority escalation channels with Meta.
7. Journalists: Verify the Process, Don’t Just Declare the Result
Newsrooms carry an acute ethical and public responsibility. A manipulated asset does not become responsible reporting simply because a headline asserts that it is fake. Before embedding, linking to, or broadcasting deceptive media, journalists must evaluate whether exposing the material is fundamentally required to serve the public interest.
Rigorous journalistic verification demands identifying the earliest known upload node, auditing whether the audio track and visual layers originated together, forensically reverse-searching individual keyframes, testing for physical or lighting anomalies, and directly contacting the person depicted.
When digital manipulation itself becomes the news event, expose the forensic workflow—how you know it is false. Institutional trust is built and strengthened by showing your verification methodology and process, not simply by stating your conclusion.
The rule is absolute: Demystify the manipulation by turning your verification workflow into a transparent public masterclass.
Tools & Resources
InVID / WeVerify Verification Plugin: The global standard tool used by the International Fact-Checking Network (IFCN) . This essential browser extension allows journalists to perform reverse image searches on video frames, analyze metadata, and parse localized contexts or regional video formats across cross-platform chats like WhatsApp and Telegram.
Amnesty International YouTube Data Viewer: Paste any YouTube URL to extract hidden upload times and track down the original, earliest version of a piece of video evidence.
Meedan (Check Platform): An innovative tech non-profit building open-source, multilingual, and highly collaborative workflows for global newsrooms and fact-checking collectives to verify media and track narrative warfare outside Western markets.
8. Pressure Platforms to Stop Making Victims Police the Network
Ultimately, none of these tips and survival strategies should obscure the structural reality: individuals and organizations targeted by synthetic abuse should not be responsible for discovering every copy, deciphering opaque corporate policy frameworks, filing repetitive forms, and persuading a trillion-dollar technology company to protect human life, and that the harm being experienced deserves human review. Platforms can, and must, intervene earlier.
True intervention must occur upstream. Platforms possess the technical capacity, and must be pressured, to identify violating content at the point of ingest, preventing near-identical copies from spreading. They must prioritize reports involving synthetic impersonation, non-consensual manipulation, and coordinated harassment. They must route high-risk cases to qualified human reviewers instead of closing support tickets automatically. Crucially, reporting systems must be designed around the operational reality that deepfake abuse is often a coordinated campaign, not an isolated post. That distinction matters.
And it must impose stronger penalties on repeat distributors.
The rule is absolute: Refuse corporate transparency tags that merely label violence; demand automated, upstream intervention that fundamentally de-platforms it.
Tools & Resources
The Sovereign Tech Fund & Prototype Fund: Independent, public-interest funding bodies that finance decentralized, community-driven alternative technologies, open-source protocols, and privacy infrastructure to reduce global civil society’s reliance on corporate monopolies.
AlgorithmWatch & European Center for Not-for-Profit Law (ECNL): Independent watchdog institutions leveraging public accountability mechanisms—like the EU Digital Services Act (DSA) and the AI Act—to legally pressure tech companies to audit their algorithmic recommendation engines and halt the monetization of coordinated harm.
Civil Society Coalitions: Join and support campaigns led by digital transparency organizations like the Global Tech Justice Coalition or Mozilla Foundation that coordinate open letters, policy advocacy, and shareholder pressure targeting safety accountability at Meta.
We have spent years discussing deepfakes as though the central danger were that people might mistake something fake for something real. Unfortunately, that is only part of the problem. It is the wrong way to look at it, and definitely the wrong way to address it. It is a framing we were fed, and it is a deeply misleading one.
A deepfake causes enormous harm even when everyone eventually learns it is fake. The humiliation happened. The harassment happened. The lies circulated. The screenshots and search results remain indexed for the world to access today, tomorrow, and decades from now. Long after a public retraction is issued, the target is still forced to defend their human dignity against actions they never took, words they never uttered, and content to which they never consented.
Which is why our response cannot stop at labeling manipulated media. A digital sticker is a corporate smoke screen. The real policy question is not simply whether Meta can tell us that something is fake; it is whether platforms can intervene before deception becomes distribution, distribution becomes harassment, and harassment becomes irreversible real-world harm.
This narrow, technical obsession with authenticity rather than systemic harm isn’t new. We have seen this exact structural failure before in other catastrophic platform crises. And this isn’t a theoretical critique; it is an operational reality I have spent nearly two decades navigating on the front lines around the world.
Throughout my career leading global crisis response, documentation, and verification initiatives, I have worked directly alongside multilateral institutions, informal networks, and an incredible ecosystem of global majority and global north practitioners, advocates, and innovators. Together, we have built the workflows, toolkits, policies, and defensive strategies needed when tech platforms and regulatory actors choose to look away. Many of the operational methodologies and tactical resources I have detailed here—and continue to analyze—are shared directly on this Unembedded Substack platform to build our collective security.
What this global network has proven is that digital violence is defined by a dangerous convergence phenomenon. Modern media manipulation does not exist in a silo. We are witnessing the fusion of identity theft, gender-based violence, localized information warfare, and algorithmic amplification. This convergence creates unprecedented risk regulation challenges; it moves too fast for traditional, localized legal systems, and slips directly through the fragmented corporate policy departments of Silicon Valley.
Yet, within this convergence lies an opportunity for true safety and security. By shifting away from isolated, siloed reactions—where platforms only address a crisis when it impacts Western markets while ignoring what happens elsewhere—we can build cross-border, systemic advocacy. The technical mechanism of automated apathy that allows a deepfake to target a local councillor in the UK is the exact same architecture that leaves human rights defenders in active conflict zones completely exposed, and killed in masses by tech supported and driven systems like Israel’s Lavender system. The infrastructure is identical; the only difference is the extension and severity of the real-world consequences.
Those who suffer first, and the most, are always the most marginalized communities—women, religious minorities, migrants, and independent journalists operating under hostile regimes and even in our very own so-called “democratic” states. But this lawlessness is catching up with us all. A system that automates indifference in one region will inevitably deploy that same indifference against you. And it already is.
Until tech platforms design their systems around preventing rapid distribution and protecting human safety rather than merely labeling data, we are all left to fend for ourselves. This is why we must master how to preserve evidence, report strategically, limit amplification, and escalate when corporate channels collapse.
But let us be clear: those are survival tools. They are tactical stopgaps. They are not a substitute for true platform accountability, policy, and structural change.
Let’s Build Your Defense Strategy
Operating in modern media systems means facing rapidly shifting technological risks, information warfare, and institutional vulnerabilities.
If your organization, media team, board, or leadership circle needs specialized guidance to adapt to emerging online harms, navigate digital evidence, mitigate deepfake threats, or implement rigorous international information integrity strategies, let’s talk. Learn more about my practice, training programs, and bespoke advisory services or schedule a direct consultation at Raja Althaibani Strategic Advisory or email me directly at inquiries@rajaalthaibani.com
MASTER RESOURCE DIRECTORY
If you need to remove intimate images/deepfakes: StopNCII.org (Global Adults) | Take It Down (Under 18) | Chayn (Multilingual Survivor Support).
If you need 24/7 localized crisis escalation or security support: Access Now Helpline (24/7 in 9 languages) | SMEX (MENA Region) | 7amleh the Arab Center for Social Media Advancement (focus on Palestine and Israel) | Digital Rights Foundation (South Asia) | Hiperderecho (Latin America).
If you need independent metadata verification & investigative archives: InVID / WeVerify Plugin | Meedan Check | Bellingcat Toolkit | Starling Lab.
If you need legal advocacy, rights defense, & policy intervention: Cyber Civil Rights Initiative (CCRI) | EDRi (European Digital Rights) | EFF (Electronic Frontier Foundation) | AlgorithmWatch.
This is a non-exhaustive list.
About the Author
Raja Althaibani works at the intersection of media, harm, technology, and accountability—advising, training, investigating, and building infrastructure for practitioners navigating an information landscape that moves faster than most frameworks can follow. Her background spans human rights, journalism, international law, and open-source digital documentation.
She writes Unembedded—long-form analysis, reported essays, and field frameworks on media, power, harm, and who controls the story. It includes two ongoing series: The Safari Is Over, on how media covers harm and what better practice looks like, and The Field Dispatch, the intelligence arm of The Field—a community of practice she founded.
Work with Raja: inquiries@rajaalthaibani.com · contact form · www.rajaalthaibani.com · Linkedin




