SecuritylabAugust 14, 2026🇷🇺Translated from Russian

How to Detect and Remove Stolen Photos from Fake Profiles, Listings and Ads

Photographs are routinely stolen from social networks, old advertisements, building chats, school websites and review platforms. The images later appear in unknown profiles, advertisements, product cards, rental listings or suspicious Telegram channels. People usually discover the theft when friends notice or when they run the pictures through dedicated reverse-image search services.

One photograph can violate several rights at once. Using a portrait to advertise courses infringes the right to one’s image, commercial-use rules and the photographer’s copyright. Creating a fake page with someone else’s face to solicit money requires a fraud report rather than a simple takedown request.

Legal basis in Russia

Article 152.1 of the Russian Civil Code protects the image of a citizen. Publication or distribution of a person’s photograph without consent is prohibited except in cases of public interest, open-place photography or paid posing. Copyright exists independently; the creator can demand removal, attribution or compensation. Consent from the recognizable person is always required for publication.

Where to search for copies

A single search engine rarely finds every duplicate. Yandex Images performs well on Russian-language sites. Google Lens excels at locating similar images and cropped fragments. TinEye often surfaces older publications missed by larger engines. Bing Visual Search serves as a supplementary tool for foreign sites. Text searches by name, nickname, company or rare phrases can reveal hidden results.

Users should also upload cropped versions focusing on the face, interior details or background objects, because thieves frequently crop, recolor or overlay stickers on images.

Preserving evidence before complaining

Before contacting the offender or platform, capture the entire page, record the exact URL, save the page as PDF, note the discovery date and retain the original file with metadata. For serious cases, a notary can officially inspect the page. Archive services such as web.archive.org are useful but incomplete; courts prefer screenshots, PDFs and notarized records.

Filing complaints

Platforms respond faster to built-in forms. VKontakte accepts reports via the post or community menu, with users flagging impersonation and linking the real account. Odnoklassniki handles photo complaints in its violations section. Telegram allows in-app blocking; fraud cases can also be reported to @notoscam. Avito, Yula and Cian collect reports on individual listings. Marketplaces provide dedicated copyright forms. When platforms ignore requests, complainants may contact the hosting provider.

Complaints to Roskomnadzor are appropriate when personal data such as phone numbers or addresses are leaked alongside the photo. Police should be contacted for extortion, blackmail or fraud. Courts can award compensation and issue injunctions.

Protecting future images

Technical prevention is limited, yet several practical measures reduce risk: publish lower-resolution versions, apply watermarks, store originals securely, photograph products against a background containing the seller’s nickname, avoid uploading sensitive documents, tighten privacy settings on family albums and regularly run reverse-image searches.

Related articles

SecuritylabPrivacy & Surveillance

Bypassing VPN Detection on iPhone: Detailed Methods to Avoid App Blocks

Many iPhone users encounter apps that detect and block active VPN connections even after switching servers or protocols. The detection often occurs locally on the device by inspecting network interfaces rather than relying solely on external IP addresses. This guide explains how apps identify VPN tunnels through iOS network data and provides practical workarounds including moving the VPN to a router, configuring per-app exclusions, and using web versions of services. It also covers why protocol obfuscation and port changes fail to hide local VPN activity from applications. Additional troubleshooting addresses automatic VPN profiles, ad blockers, and iCloud Private Relay interference. The article emphasizes that no universal toggle exists in iOS to hide an active VPN from all apps.

HabrPrivacy & Surveillance

New Obfuscation Method Dissolves Personal Data Records in Layer of Plausible Variants

A Russian information security researcher has proposed a data protection technique that renders stolen personal records unusable even after full compromise. The approach mixes real data such as phone numbers, emails, passports, addresses, INN and SNILS with vast numbers of semantically valid alternatives. Attackers receive nearly complete information including a 361-character message containing PIN codes and word order, yet lack the secret vector space and reconstruction algorithm required to identify the correct record. Without these components, brute-force attempts produce millions of plausible results with no architectural method to verify accuracy. The method is presented as an alternative to traditional encryption when data must remain accessible yet protected against extraction. A public sandbox is available for testing the approach.

HabrPrivacy & Surveillance

Hydrat Project Builds Automated WireGuard Gateway for Resilient VLESS and Tor Routing

A developer has released Hydrat, a self-hosted gateway that connects devices via WireGuard while automatically managing VLESS and Tor backends to survive server blocks and quality degradation. The system maintains a pool of tested proxies, performs continuous health checks, and switches routes without requiring client-side profile changes. Two Go processes handle control logic and network enforcement separately, using SQLite for state and nftables plus Xray for traffic routing. TCP and UDP can be assigned independent exits, with geoip.dat support and custom rules to keep marketplace apps functional. The project emphasizes stability over direct connections and is designed for deployment on servers in Russian jurisdiction.

AntiMalwarePrivacy & Surveillance

OpenAI Contractors Manually Review Real User Chats in Project Lily

OpenAI has engaged hundreds of external contractors to analyze actual user conversations with ChatGPT as part of its model improvement efforts. The reviewers, working under project Lily, examine real queries that may contain personal, medical, or other sensitive information despite the use of a Privacy Filter. Contractors summarize prompts, compare four model responses, and assign ratings from one to seven while flagging behaviors such as excessive sycophancy or inappropriate emojis. User identities are hidden and some data is filtered, yet OpenAI acknowledged that not all personal information is reliably removed. The same human review process is also employed by Anthropic for its Claude model. Users can opt out of future training use through account settings, although prior data remains unaffected.