Executive Summary
Between December 2024 and June 2025, Ohio resident James Strahler II conducted an extensive AI-powered sextortion campaign targeting multiple women through cyberstalking, harassment, and the creation of non-consensual deepfake pornography. Using over 100 AI web-based models across 24 platforms, Strahler generated more than 700 sexually explicit images and videos of his victims, which he distributed to their workplaces and posted on child exploitation websites. His tactics included threatening victims and their families with public humiliation unless they provided additional explicit content, making rape threats referencing home addresses, and demanding compliance from victims' mothers. The case resulted in a 15-year federal prison sentence and marked the first conviction under the newly enacted Take It Down Act of 2025.
This incident highlights the emerging threat landscape where readily accessible AI tools are being weaponized for sophisticated harassment campaigns, demonstrating how threat actors are adapting generative AI capabilities for malicious purposes at an unprecedented scale and sophistication level.
Why This Matters Now
The proliferation of accessible AI deepfake tools has created a new category of cyber threats where attackers can generate convincing non-consensual content at scale, requiring updated security frameworks to address AI-powered harassment and extortion campaigns.
Attack Path Analysis
James Strahler II conducted a cyberstalking campaign using AI-generated pornographic content to extort victims through Initial Compromise via social engineering and credential theft, escalated privileges to access victim social media accounts, moved laterally across multiple platforms and AI services, maintained Command & Control through persistent harassment campaigns, exfiltrated personal images and data for AI manipulation, and caused significant Impact through psychological harm, reputational damage, and distribution of illegal content.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attacker gained initial access to victim information through social engineering, credential theft, or public data harvesting to obtain personal photos and identifying information for targeting
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Gather Victim Identity Information: Email Addresses
Phishing: Spearphishing Attachment
Internal Spearphishing
Exfiltration Over C2 Channel
Endpoint Denial of Service: Application or System Exploitation
Data Encrypted for Impact
Data Manipulation: Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Incident Response Plan
Control ID: 500.15
PCI DSS 4.0 – Incident Response Plan Implementation
Control ID: 12.10.1
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management
Control ID: ID.AM-2
DORA – ICT Risk Management Framework
Control ID: Article 11
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
AI platforms used for generating deepfake content create liability risks requiring enhanced content validation, user verification, and egress security controls.
Entertainment/Movie Production
AI-generated explicit content threatens talent protection and reputation management, necessitating zero trust segmentation and threat detection capabilities.
Legal Services
Take It Down Act compliance and cyberstalking prosecutions demand specialized expertise in digital forensics and AI-generated evidence handling.
Higher Education/Acadamia
Student targeting through social media exploitation requires comprehensive threat detection, encrypted communications, and incident response frameworks.
Sources
- Man gets 15 years for extorting women with AI-generated porn videoshttps://www.bleepingcomputer.com/news/security/man-gets-15-years-in-prison-for-cyberstalking-and-sextortion/Verified
- Columbus Man Sentenced to 15 Years in Prison for Cyberstalking Exes, Creating AI-Generated Child Sexual Abuse Materialhttps://www.justice.gov/usao-sdoh/pr/columbus-man-sentenced-15-years-prison-cyberstalking-exes-creating-ai-generatedVerified
- Take It Down Platform - FTChttps://takeitdown.ftc.gov/Verified
- Take It Down Act - Public Law 119-12https://www.govinfo.gov/content/pkg/PLAW-119publ12/pdf/PLAW-119publ12.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have reduced the attacker's ability to expand across multiple AI platforms and cloud services through segmented access controls. The blast radius of this cyberstalking campaign would likely have been constrained by limiting lateral movement between platforms and controlling egress paths for content distribution.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Identity-aware access controls would likely have limited the attacker's ability to leverage compromised credentials across multiple cloud platforms and services without proper verification
Control: Zero Trust Segmentation
Mitigation: Workload isolation policies would likely have reduced the attacker's ability to escalate from initial access to broader account privileges across integrated social media and cloud storage services
Control: East-West Traffic Security
Mitigation: Traffic inspection and policy enforcement would likely have limited the attacker's ability to move seamlessly between AI generation platforms and social media services without triggering security controls
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility into communication patterns would likely have reduced the attacker's ability to maintain persistent, coordinated harassment campaigns across multiple cloud-based communication platforms
Control: Egress Security & Policy Enforcement
Mitigation: Outbound traffic controls would likely have limited the attacker's ability to systematically transfer large volumes of generated content to external websites and distribution platforms
While psychological harm to victims would still have occurred, the reduced scale of content generation and distribution would likely have limited the breadth of reputational damage and victim exposure
Impact at a Glance
Affected Business Functions
- Personal Privacy Protection
- Digital Identity Security
- Online Safety
Estimated downtime: N/A
Estimated loss: N/A
Personal intimate images of at least 6 adult female victims were compromised, with over 700 AI-generated explicit images created and distributed. Real and AI-generated nude images were shared with victims' co-workers and posted on websites. Personal information including home addresses was obtained and used in threats.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to detect and block unauthorized uploads to AI platforms and suspicious websites that could be used for generating harmful content
- • Deploy Zero Trust Segmentation with identity-based policies to limit access to personal data repositories and prevent lateral movement across cloud services and social media platforms
- • Establish Multicloud Visibility & Control to monitor anomalous interactions with AI services, repeated API calls to content generation platforms, and suspicious automation patterns
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal user behavior and alert on covert tool usage, unauthorized access patterns, and bulk content generation activities
- • Enforce Encrypted Traffic protection with data loss prevention controls to prevent exfiltration of personal images and sensitive data that could be used for AI manipulation and extortion



