Whitepapers

The Lowest Hanging Fruit: A Meta Investigation Part 2

Instagram doesn't have groups, so the Facebook playbook from Part 1 wouldn't work. There was no gated community to get inside, no admin to convince. I had to flip the model: build the fake 14-year-old again, this time with an AI-generated face pulled from an account on the platform itself, post into the open, and let the predators find me. They did. Part 2 is what Instagram's own systems did next: a search filter that failed on a single added letter, a recommendation engine serving accounts that solicited CSAM under the banner "Suggested for you," and a WhatsApp number that took more than 250 calls and messages in ten days. The platform wasn't just failing to stop these users. It was introducing them to me. On August 6, 2026, a court in Santa Fe reached the same finding, and put it in an order.

Disclaimer: The views expressed here are my own and do not represent those of any organization, entity, or client. The findings described reflect conditions observed during an investigation conducted in 2023. I am not currently investigating Meta’s products and cannot assess whether the issues identified have since been addressed.

A note to the reader: What follows is an account of undercover investigative work targeting child predators and the platform systems that enabled them. By its nature, this work required operating in the same spaces as the people I was investigating. Some of what you’ll read may be difficult. I’ve included these details because they are evidence, and because evidence is what ultimately held a trillion-dollar company accountable.

Audiobook version can be found on: Spotify, Apple Podcasts, Amazon Music, iHeartRadio.

Prologue

In Part 1, the finding was that Facebook's recommendation engine couldn't tell the difference between a hobby group and a pipeline to exploitation. Using the same tradecraft a real predator would use, I built a fake 14-year-old profile, watched Meta's safety systems wave me through, and watched the platform recommend me deeper into groups designed for children. Predators found me. When they wanted to take the conversation somewhere the platform couldn't see, they moved it to WhatsApp. You'll see that pattern again.

Part 2 is Instagram, a different platform with different mechanics. Some predators circumvented the platform's safety mechanisms. Others brazenly plowed through them.

The AI Profile

There's a fairly well-known AI video that circulated in 2023 of Will Smith trying to eat spaghetti. The results were the stuff of nightmares. I'm talking about noodles passing through his skin, and his face nearly melting. On the other hand, AI-generated images of people were just starting to pass as lifelike. Most still carried that uncanny feeling where something in the face, the hands, or the lighting didn't feel quite "right," and they weren't nearly as prevalent as they are in 2026. During the Facebook phase of the investigation, I had looked for AI images of teens that would be convincing enough to deploy against predators. Everything I found would have likely tipped off a predator. That wasn't the case on Instagram.

I ran the same predator playbook on the Instagram account that I had run on Facebook, purchased an aged account, reset the internal settings, changed everything externally visible. The bio read, "Body of a 14 year old with the soul of a 90 year old - Quote from my bestie 😂😂😂."

Now it was time to change the profile picture. I had found an Instagram account hosting a collection of AI-generated images of young teens, and unlike the ones I had found on Facebook, I assessed that these were actually good enough to fool a potential predator. I want to be clear about what that means: another user's Instagram account was acting as a library of synthetic images of fake children, sitting in the open on the platform, available to anyone who knew where to look. I pulled one of those images and set it as the profile picture of my fabricated 14-year-old.

After making all of these changes to the internal settings and the public side of the profile, nothing happened. No flag, no challenge, no friction. I had replicated the predator playbook on a second Meta platform, this time with an AI-generated face pulled from the platform itself. Every door was once again open. And with that, fake-Evelyn was born.

Hashtags: The Groups of Instagram

Warning: The following chapter contains disturbing language.

Unlike Facebook, Instagram doesn't have groups. That meant I couldn't use the same infiltrate-and-observe approach I had used on Facebook. There was no gated community to get inside, no admin to convince, no room where predators gathered and I could sit quietly in the corner collecting evidence. On Instagram, if I wanted to attract the attention of the kind of users that would prey on children, I had to flip the model. Instead of finding them, I had to let them find me. That meant using the one mechanism Instagram gives every user to broadcast into user interests: hashtags.

If you're unfamiliar, think of hashtags as the way a post tells the algorithm what it's about through keywords. A professional carpenter trying to grow his business will post pictures of his work and tag them with popular woodworking hashtags. Anyone searching those hashtags, or scrolling through them, will find their posts. The same logic applies to every other topic on the platform, hobbies, politics, fandoms, fitness, and the more sinister ones as well.

Before I get to what I found, there's a pattern from the Facebook investigation worth pulling forward, because it applied on Instagram as well. Meta's moderation on both platforms relies heavily on keyword filtering to block the most obvious searches. On Facebook, I had tested several of the most obvious keywords a predator might search for. In one instance I searched, spelled out completely, "12 year old p****y." As it should, the platform showed me a text box that read, "Child Sexual Abuse is Illegal." However, when I typed the same phrase in Spanish (widely documented as Facebook's second most used language after English) the platform showed me several groups to join.

English Search

Spanish Search

In the Trust & Safety world, we've watched this cycle for years: block a term, and the people you're trying to stop change the term. They add emojis. They use codewords. They invent deliberate misspellings. They migrate to adjacent vocabulary that reads innocuous to a filter and unmistakable to anyone inside the community. Keyword filtering is necessary, but on its own it's a speed bump, not a wall, and for the laziest of malicious actors, they just change the language.

Trust & Safety professionals are all too familiar with this problem, and I don't want to pretend it's easily solved. What I found on Instagram wasn't that problem. What I found was the same pattern I had already documented on Facebook: hashtags that should never have been permitted in the first place, sitting in the open, indexed and searchable. Some of them I deliberately posted during my investigation without any intervention from the platform.

Post, Wait, Track, Repeat

One of the original objectives of the investigation was to determine how easily a child could be contacted by an adult on Instagram. Over two days, I made two posts from fake-Evelyn's profile, using the AI-generated images I had pulled from the account I described earlier. I spaced the posts deliberately. I wanted time between them for the algorithm to work and for users to react.

Post 1: "Another #photoshoot feeling #blessed #teen #14andhot #ageisjustanumber #sundress"

Post 2: "Why am I holding a lollipop??? 🤣🤪 #teenmodel #sexyshoot #teenfashion #lollipop #preteenlife"

Looking at the above posts, specifically the second one, you should notice that almost any of these hashtags by itself could plausibly appear on a benign post, #14andhot being the obvious exception, which makes its survival worse. But when you read the full captions, the hashtag stacks, the combinations, the context clues, it stops being ambiguous. A contextual model trained for this kind of signal should be ringing alarm bells. Instagram's wasn't, and if it was, the platform still allowed me to post them.

After the second post, likes and comments started coming in. Those users found the posts one of four ways: they were actively searching the hashtags I had used, they were following one or more of those hashtags (a feature Instagram offered at the time that pushed tagged content into a user's feed automatically, the way following an account would), they had already followed fake-Evelyn, or Instagram's own recommendation systems had served the posts into their feeds. Each of those paths implicates the platform differently, some through active user behavior, and some through the platform doing the work for them.

Once I had a set of users who had reacted to my posts, the next step was to understand who they were. I pulled up each account and walked through it systematically: what they had posted, who their followers were, what those followers had posted, who they themselves were following, what those accounts had posted, whether their handles appeared anywhere else online, and whether they had been tagged into posts by other users. Typically in an investigation of a specific user, you'd use a similar framework to build a profile of that person. I was after something bigger. I wanted to map the network they sat inside.

Nodal Analysis

In the Trust & Safety world, we see the same behavioral pattern again and again: malicious users on social media rarely do this work using their main account. They build dedicated accounts for their predatory activity. And once a predator searching for CSAM finds a user who posts it, they do what anyone does when they find a useful source on the internet. They follow the account so they can find it again. When the source posts CSAM back at them, that user follows in return. The follow graph, in other words, functions as a bookmark list of favorite sources. Which means the graph is mappable.

I worked outward from the users who had liked or commented on my posts, following the trail of who they followed and who followed them back. That's how I identified the first cluster of accounts whose behavior was consistent with trafficking in CSAM. Many of those accounts were less than a year old, but they had follower counts that didn't match their age. New accounts typically don't have thousands of followers. When they do, it usually means the account is a backup — a replacement a user built after their previous account was removed — which the original audience quickly re-followed. The platform takes an account down; the network reassembles.

Once I began following those accounts from fake-Evelyn's profile, Instagram's recommendation system did the rest. The "Suggested for You" surface began pushing me additional accounts with the same signals. The platform was, effectively, completing the map for me.

The signals on those accounts were consistent. They used hashtags designed to route around keyword filters. They pushed Telegram links in their bios to move buyers off-platform. I followed one of those Telegram links and was met with a menu of folders that claimed to sell CSAM and rape videos for as low as 140 rupees (about $1.70 USD at 2023 exchange rates). One note here: the restrictions I was operating under prevented me from purchasing anything to verify the offering was legitimate. It could have been a scam. So, I provided the Telegram link to the New Mexico Attorney General's office in my report for them to follow-up.

 

The users I was tracking on Instagram stacked loaded keywords in their posts, "young," "girl," "gymnastics," "teen," "bikini", and in some cases inserted emojis between the words so that automated systems reading the string as a phrase wouldn't match on it, while any human inside the community would read the intent immediately.

Some of the accounts weren't selling; they were fishing. One profile presented as a 13-year-old girl, claimed to be a lesbian, and said she only wanted contact from other girls. Pinned to the profile was a screenshot, framed as a complaint, in which she said an ex-girlfriend had posted a half-naked photo of her. The screenshot wasn't her complaining. It was a signal, a way of telling potential targets that she had explicit images of herself and might share them. The account sat inside the same follower graph I was mapping, connected to the same cluster of accounts running the selling and backup-account patterns.

By the time I had worked through the graph, I had identified accounts engaged in distributing or soliciting CSAM on Instagram, many of them openly advertising to buyers. In one instance, the profile of a user openly advertised "this year turning 17" and was selling "Worn Panties."

Another user I had found was collecting Instagram Reels of young girls, some nearly undressing, and openly advertising their PayPal.

As with the earlier Telegram case, I have to emphasize (specifically so that Meta's legal team doesn't hunt me down) that the restrictions I was operating under prevented me from directly contacting that user to verify whether they were actually selling CSAM. I provided the information to the New Mexico Attorney General's office for their independent investigation, and with that, Phase 1 of the Instagram investigation closed.

Did Anything Change

I thought I was done when I sent my Phase 1 report to the New Mexico Attorney General's office. Facebook, Instagram, WhatsApp, all of it. Evidence compiled, screenshots preserved, findings written up. My job was done.

Motley Rice called a month later, same question as the Facebook check-back covered in Part 1, same constraints, eight hours across both platforms. Part 1 covered what I found when I returned to Facebook. This is what I found when I returned to Instagram.

The first surprise was that I didn't need to buy a new profile. Unlike my Phase 1 Facebook account — which was disabled by the time I tried to log back in, under circumstances Meta's legal team declined to explain during my deposition — fake-Evelyn was still accessible. Instagram hadn't touched her. The account that had posted AI-generated images of fake-Evelyn, with hashtags like #14andhot and #ageisjustanumber was still sitting there, undisturbed.

In Phase 1, I had let predators find me. Post, wait, track, repeat. The methodology worked because Instagram's recommendation surfaces completed the network once I had a few anchor users. I didn't need to search for predators, because the platform was surfacing them. In Phase 2 I wanted to invert that. I had eight hours and a specific question: what does Instagram surface when fake-Evelyn goes looking for it?

The Filter

On Facebook in Phase 1, I had tested the keyword filter in two languages and found that Spanish was the speed bump while English was the wall. Instagram's filter worked differently. When I searched the industry-known CSAM keyword loli (a term used to refer to sexualized depictions of underage girls), the platform returned the same banner I had seen on Facebook: "Child sexual abuse is illegal." As it should. I wanted to see how deep the filter went.

I started testing variations. loli.girl returned the banner. One letter added to the end, loli.girly, returned search suggestions. The top suggestion was a handle named in a way that left no ambiguity about what that account was advertising: “kitten.kreampie”. One character past the filter, and the platform was handing me the network.

This is the problem I described in Phase 1, keyword filtering as a speed bump, not a wall, except Phase 1 documented it happening at the group level on Facebook. Here it was happening on Instagram's core search surface, on a keyword that is not adjacent vocabulary or a codeword. Loli is the canonical term. The filter caught the canonical term. It did not catch the canonical term with one letter added.

Other searches surfaced other problems. teennaughty and modelteen returned explicit results. To Meta's credit, "teen" can describe a user who is eighteen or nineteen, so it's defensible that those keywords are available on the platform at all. What's not defensible is some of the content I found inside them.

Mapping the Threat

I went back to the methodology that had worked in Phase 1. Find an anchor, a user engaging with content consistent with CSAM trafficking, and work outward mapping their social graph. What had changed wasn't the methodology. It was what the anchor looked like.

In Phase 1, my anchor users were accounts reacting to my posts. In Phase 2, my anchor was a single post under the modelteen keyword: a topless girl who appeared to be less than thirteen years old, in a swimming pool. The post had twenty-eight likes when I found it. I started with those twenty-eight users and pulled the thread.

One of the users who had liked the post was following several accounts whose handles contained the words bikini and girl. Those accounts were running the same play I had documented in Phase 1, profile photos of children, bios explicitly stating the content, thousands of followers and almost no posts. The same backup-account pattern Phase 1 showed me, now confirmed in a second graph.

Following the trail further, I landed on an account with the handle tonybeavers1 (no relation, before anyone asks). I want to note that I am naming this handle deliberately. Context matters, and this user's handle sat alongside an account history that makes context the only reason to name him: he posted upskirt videos of minors, some in slow motion. The platform indicated the account had over 230 posts and more than 17,000 followers. One more time, as close as the account could get to the legal line without technically crossing it, in full view of a platform whose recommendation systems were, by this point in my investigation, pushing accounts like his into my "Suggested for You" feed. I hope Meta has actioned on that account since then.

Over the Line

If you have ever had younger siblings, you might be familiar with a game called "I'm not touching you." A sibling puts their hand as close to your face as they can without making contact, repeating "I'm not touching you" over and over again, to get a reaction. They think that by not actually touching you, they are not technically breaking any rules, and they can keep going as long as they want without consequence. I was never a fan of that “game” then. I am especially not a fan of it when it comes to CSAM.

Searches on keywords like modelteen surfaced content that was not, by the strict legal definition, CSAM. For the lawyers reading this, I know that "borderline CSAM" is not a legal term. Let me describe what I mean. One user using the modelteen keyword posted pictures of girls who appeared to be under twelve years old, wearing underwear or two-piece swimsuits, with the child's genitalia as the central focus of the frame. The same user allowed comments on those pictures, and the comment threads filled with sexual remarks, including one user writing "My face need it."

This was a recurring pattern throughout my investigation. The accounts I was documenting got as close to the legal line as they could without crossing it. They treated Instagram's policy boundary as a game, if the image technically wasn't CSAM, and the caption technically wasn't a solicitation, and the hashtag stack technically had plausible-deniability, then the platform wouldn't act. They wanted to see how close to CSAM they could get. But some did go over the line.

The Suggestion Algorithm

Warning: this section contains descriptions of predatory content directed at children.

In Phase 1, I documented Instagram's recommendation system completing the network for me. Once I had followed a few accounts with CSAM-trafficking signals, Suggested for You started pushing me to accounts with the same signals. That was the passive version of the problem. Phase 2 showed me the active version.

After I had followed several of the users orbiting the modelteen anchor post, the recommendation engine started working. One of the accounts it surfaced had the handle trade_pics_young. The profile had no public posts, nothing to see from the outside, nothing to report. This is a documented tactic in the Child Safety community: some predators will not publicly post CSAM themselves, because they don't have to. They use the platform as a free advertising layer and move the actual content to encrypted private messages, often off-platform entirely. Instagram becomes the discovery surface; Telegram, or WhatsApp, or whatever end-to-end encrypted messaging channel becomes the distribution surface. "Technically" no CSAM on Instagram. That's the defense.

Another suggested account, itradeteenvids11to17, wasn't even being subtle. The bio read: "I trade vids of my self and other girls between 11 to 17." The profile photo, as in every other case I had documented, appeared to be taken from another user. A single post. Seven hundred forty followers. The same predator playbook Facebook Phase 1 had taught me, running on Instagram. Surfaced to fake-Evelyn by Instagram's own recommendation system, under the banner "Suggested for you."

Another suggested account was running a different play. The profile posed as a young girl and posted what I assessed to be CSAM, an image of what appeared to be a topless child less than thirteen years old. Overlaid on the image in text was the following: "If you post this then anyone can send any porn no matter how fucked up/illegal - you have to jerk off to it." The comment section was filled with users asking to be direct-messaged, volunteering to participate, requesting content. It was not a post. It was a recruitment instrument. Instagram had suggested it to fake-Evelyn.

One of the users in that comment thread used the handle dicpicaddme. The bio described the user as "Straight, 15" and solicited direct messages. That account was following a profile posing as a young girl whose content included what I suspected to be CSAM, an image of a topless girl with a purple smiley-face emoji covering her breast and a hand at her throat. The account had four posts and over eleven hundred followers. Four posts. Eleven hundred followers.

To recap the graph: a single keyword search for modelteen surfaced an anchor post. Twenty-eight users had engaged with the anchor post. Following those users, and the users they followed, produced a cluster of accounts running the Phase 1 predator playbook. Following those accounts caused Instagram's recommendation engine to serve me additional accounts with the same signals, including accounts whose entire stated purpose was to solicit or trade CSAM. The platform was not just failing to stop these users. It was introducing them to me.

I wasn't the only one finding this. While I was running my investigation in 2023, researchers at the Stanford Internet Observatory (David Thiel, Renée DiResta, and Alex Stamos) were independently documenting the same pattern. Their June 2023 report, and the Wall Street Journal's coverage of it (Instagram Connects Vast Pedophile Network), concluded that Instagram's recommendation algorithms were actively connecting buyers and sellers of CSAM. Different methodology, different team, and yet, the same finding.

The New Mexico trial put a third source on the record: Meta's own documents. An internal test from June 2019 found that users who followed minors' accounts were recommended more of them, along with photos of teens in Explore. The same document reported, in Meta's own words: "26% of the people we recommend to Groomers were Teens." In an internal chat from October 2020, a Meta employee wrote that the People You May Know feature was responsible for 80% of violating adult/minor connections. 3 years later, I was mapping the network from the outside. Meta had already mapped it from the inside.

Missed Calls

Earlier, I mentioned the documented tactic of using Instagram as a free advertising layer while moving the actual content to encrypted private messages. The WhatsApp account I had created during Phase 1, the one I had set up after the Nigerian +234 administrator on Facebook asked me to move to WhatsApp, was still associated with the fabricated 14-year-old profile. During Phase 2 I rarely interacted with anyone on WhatsApp. I didn't need to. The account was getting called and messaged on its own, more than 250 calls and messages across ten days.

The messages ranged from solicitations for sexual favors and videos to direct distribution of CSAM links. Several of the chat threads openly advertised Telegram channels and cloud folders claiming to contain "child sex videos." Some of them included thumbnail previews directly in the message, previews that, based on what was visible, appeared to be actual CSAM rather than decoy imagery.

One caveat I want to make on the record, mostly to appease the armchair lawyers in the room. Because of the investigation's constraints, I was unable to verify with certainty whether the links provided actually led to CSAM content. Some of these operations could have been scams, people using CSAM advertising as bait for a straightforward fraud. With that said, if you are using CSAM imagery as bait to run a scam, you are still using CSAM imagery.

Instagram was the shop window. WhatsApp, and other end-to-end encrypted messaging platforms were the back room where the deals were being made.

The Lowest Hanging Fruit

Two weeks on Phase 1. Eight hours on Phase 2. A month and a formal complaint in between. That is the entire window in which I documented what you have just read across Part 1 and Part 2.

I want to be explicitly clear about my methodology, because the ease of this matters. I didn't use any special hardware. No burner laptops, no air-gapped devices, no dedicated investigation machines. I didn't route my traffic through a chain of VPNs or bounce through public Wi-Fi at libraries and coffee shops to obscure my origin IP. I didn't use burner phones with anonymous SIM cards to get around phone verification. I didn't infiltrate black-market Tor groups. I didn't use three layers of crypto wallets to buy membership into salacious Facebook groups. A 14-year-old wouldn't have done that. Most predators wouldn't have done that. Everything you have just read could have been done by anyone with a laptop and a browser.

I called this investigation, going in, "The Lowest Hanging Fruit." A laptop, a browser, and a little less than three weeks gave me: Facebook groups whose age ranges started at ten years old; a recommendation engine that funneled a fake 14-year-old into groups named "Girls under 13 years old"; Instagram hashtags the platform let me post without intervention; a search filter that failed on a single added letter; a suggestion engine that introduced me by name to accounts soliciting CSAM; and a WhatsApp inbox that took more than 250 calls and messages in ten days. Any predator with the same laptop and the same browser has access to the same tree. The question is what the rest of it looks like.

I know how hard this problem is. If it were easy, Trust & Safety as a profession wouldn't exist. Every tool built to connect people has eventually been used by someone to harm them, and no detection system catches every signal the first time it sees it. Predators were always going to be on Meta's platforms. The question was what the platforms were designed to notice about them, and when.

What the investigation documented, twice, on two different platforms, separated by a formal complaint, was not a novel process. It was standard predator tradecraft, the same methods Europol had catalogued in 2016 and the Trust & Safety community had documented for over a decade, all of it operating in the open. The gap between the mitigations that were technically possible and the ones actually deployed, that is the story.

Mark Zuckerberg coined the motto "move fast and break things." I did move fast. I wish I could tell you these findings exist because I broke through Meta's safety parameters. But from what I could see in my investigation, and what a jury and a judge in New Mexico also saw, the parameters seemed to be working as intended.

Author’s Note

Thank you to the team at the New Mexico Attorney General's office, to Motley Rice, and to the colleagues who kept me honest across three years of silence. Thank you to every reader who stayed with this series to the end.

The work to protect children continues where it has always been done, at NCMEC, on ICAC task forces, in law enforcement offices around the world, and inside the platforms themselves, where the investigators and Trust & Safety professionals I used to sit next to still do this work every day. They deserve more recognition than they will ever get.

On March 24, 2026, a jury in Santa Fe heard enough of this evidence to award the maximum penalty under New Mexico law. That was not the end of the investigation. It was the moment the evidence earned a hearing.

On August 6, 2026, the hearing produced its judgment. The court found Meta's platforms to be a cause of and a substantial contributor to a public nuisance in New Mexico, ordered $567 million into an abatement fund, on top of the jury's $375 million penalty, and ordered the mechanics this series documented shut off: no New Mexico minor's account may be recommended to an unconnected adult, and no unconnected adult may message a New Mexico user under eighteen. The orders run for five years, cover one state, and do not reach WhatsApp.

The children are still online.