The fake-link economy: three documented patterns that hijack creators’ names

Written by

in

What is happening

If you search for an adult creator by name, a meaningful share of what you get back was not made by her. Some of it is affiliate spam wearing her name. Some of it sits on a hijacked university subdomain. Some of it is a landing page that outranks her own website. None of it leads where the searcher thinks it leads.

This is not a new observation in security research, but it is usually studied from the attacker’s side, as an SEO or malware problem. We looked at it from the side of the person trying to find a real link, and from the side of the creator whose name is the bait. Below are three patterns we documented directly, what independent sources confirm about each, and what a person on either side can actually do.

Two things we want to be explicit about up front, because they limit what this article claims. First, naming a domain is a statement about that domain, not about the person whose name appears on it. Where we say a page uses someone’s name, that is a claim about the page. Second, we did not open most of these pages, and we do not link to any of them.

Pattern one: the templated link-in-bio page

The first pattern is a title formula. Across Linktree, a large number of pages carry the identical page title “[Name] OnlyFans Official — Exclusive Content & Account”. We confirmed this template is live and widespread: a single search returns page after page using it verbatim, differing only in the name at the front.

We opened one of them. A page under the slug johannenordeng1 describes itself as belonging to an “Instagram Model, Adult Content Creator”. It contains no links to any creator platform. What it contains is affiliate spam — a link labelled “Best Online Slots. Gambling.” and one labelled “Hot Web Cam Video Chat Online.” The page was created in December 2024. It is not hers.

We logged seven further Linktree slugs carrying the same title template. We are deliberately not listing them, for a reason that matters more than the omission: the template alone does not tell you whether a page is fake. Genuine creators use it too — it appears to circulate as an SEO tip. That is precisely what makes it effective cover. A visitor who learns to treat the phrase as a red flag will start distrusting real pages; a visitor who learns to trust it will be led into affiliate funnels. The signal is worthless in both directions, which is the point of using it.

Gambling links breach Linktree’s own rules. Its Community Standards prohibit advertising gambling and casino games, prohibit creating large numbers of accounts to collect affiliate per-click funds, and separately prohibit profiles that impersonate other individuals or organisations. A page like the one above breaches at least three clauses at once.

Pattern two: disposable “-official” domains

The second pattern is a domain template rather than a page template: a creator’s name, the suffix -official, and the .online TLD, with the page title “[Name] Official – Exclusive Content & Connections”. We documented two live examples. Both outrank the genuine websites of the people whose names they carry. Searching the title formula shows the template is not a one-off; it returns further live examples on the same pattern, plus variants that drop the “-official” infix and use the bare name on .online.

We want to be careful here. We have verified that this is a template deployed at scale on a single cheap TLD, and we verified the ranking displacement in the two cases we checked. We have not opened these pages and we are not asserting what any individual one contains or who operates it. The documented harm is the displacement itself: a person searching for a creator’s own site is served something else that looks more official than the official thing, because it says “Official” in the title and the real site does not.

Pattern three: leak-SEO on institutional subdomains

The third pattern is the best-corroborated, and it is not really about creators at all — they are the keyword, not the target.

On the majority of creator-name searches we ran, results appeared on university and institutional subdomains. These pages target creator names with “leaks” and “onlyfans” in the URL path. They rank because the parent domain’s authority carries them.

This is what Google calls site reputation abuse, and what the industry calls parasite SEO. Google’s own description of the tactic is that both users and its systems think they are dealing with a trusted website when in reality they are dealing with a scammer.

Two independent sources put numbers on it. In April 2026, security researcher Alex Shakhov documented 34 hijacked .edu subdomains at institutions including MIT, Harvard, Stanford, Columbia, Johns Hopkins and the University of Washington, all serving indexed pornographic spam — reported by EdScoop. The cause is mundane: DNS records pointing at services that no longer exist, which anyone can then claim.

In July 2026, UpGuard published an analysis of Google’s DMCA transparency data. Between September 2011 and May 2026 it identified 384,286 adult-content takedown requests covering 631,193 URLs, filed against 2,167 unique government and education domains across 80 countries. The requests came from 11,046 distinct copyright owners, almost all individual creators. Google removed 132,266 of the reported URLs; 468,407 got no action — only 21.6% of requests produced any removal at all.

UpGuard’s finding is that the number of compromised institutional domains detectable this way has roughly doubled every two years since 2020, and that these pages are entry points into traffic distribution systems that route visitors onward into scams and malware. Crucially, the pages frequently contain no stolen material at all. The creator’s name is the lure, nothing more.

Why the mechanism works

None of this would function if audiences went to creators directly. They largely cannot.

Instagram restricts links soliciting adult services, which pushes creators toward a neutral intermediary page instead of a direct platform link. That is a rational compliance choice, and it has a side effect: it trains an entire audience that the normal way to reach a creator is to follow an unfamiliar third-party link. Once that habit exists, a fake intermediary is indistinguishable from a real one, because there was never a direct link to compare it against.

Handles compound the problem. Account names frequently bear no resemblance to the public name — one account we verified is a bare numeric identifier belonging to a creator whose name would suggest something entirely different. So a visitor cannot fall back on asking whether the handle matches the name either. There is no inspectable property of a URL that distinguishes real from fake. That is the whole vulnerability, and it is structural rather than accidental.

How to tell real from fake

  1. Start from an account you already trust, not from search. If you found the person on a social platform, follow the link in that profile. Search results are the compromised channel; a profile you already follow is not.
  2. Treat “Official” in a title as meaning nothing. Both templates documented above put “Official” in the title. Genuine pages usually do not need to.
  3. Check what the page actually links to. A real link-in-bio page links to platforms and social accounts. If it links to casinos, cam aggregators, “free download” pages or a survey wall, you have your answer without needing to know anything about the creator.
  4. Distrust the domain, not the name. A creator’s name in a domain costs about a dollar. Names on .online, .click, .site and similar cheap TLDs are trivially registrable by anyone.
  5. Never trust a .edu or .gov result on this topic. An institutional domain hosting a page about a creator’s “leaks” is a compromised institutional domain. The authority you are responding to is the exact thing being exploited.
  6. Anything promising “leaked” or “free” content is a funnel. Per UpGuard’s finding, these pages usually contain no content at all. They exist to route you somewhere else.
  7. If a page asks you to verify, sign up, or download anything before showing you a link, close it.

If you are being impersonated

Recourse is real but slow, and it is worth knowing which lever fits which problem.

  • Linktree, impersonation or spam: the Report a Violation form in its Trust Center. Reports are reviewed manually. Linktree’s transparency report for January–June 2025 records 9,668 violation reports received, of which 18.26% were found to breach standards — so make your case clearly.
  • Linktree, name or trademark misuse: the separate IP infringement form. This queue is faster — Linktree reports a median first response of under ten hours.
  • Instagram impersonation: help.instagram.com/370054663112398. Meta only accepts reports from the person being impersonated or their representative, and requires photo ID.
  • Search results: Google’s legal removal troubleshooter handles copyright and other legal requests. Where a page has already been taken down but still appears in results, the Refresh Outdated Content tool is faster.
  • Institutional pages: report to the institution’s own security or abuse contact, not only to Google. De-indexing hides the page; it does not fix the hijacked subdomain, and the operator will simply publish another.

One honest caveat on DMCA. It is the tool most creators are pointed toward, and it is the wrong shape for this problem. UpGuard’s data shows only 21.6% of requests produced any removal, and because many of these pages host no copyrighted material at all — only a name — legal and security experts have questioned whether copyright is even the right instrument. Impersonation and trademark routes often fit better. We are not aware of any published dataset measuring adult-creator impersonation specifically, as distinct from content piracy; if one exists, we have not found it.

What we do about it

WinkView exists because of the gap this article describes. The mechanism that makes impersonation work is the absence of a trustworthy starting point — a place where the link you follow is the one the creator actually gave.

So we publish only links we can trace to a surface the creator controls, we say on every page where the link came from, and we leave the field blank when we cannot verify it rather than guessing. We are not trying to be a better search result for “leaks”. We are trying to be the boring, verifiable first link, so that fewer people ever run the search that leads them into any of the three patterns above.

If you are a creator and a page in one of these patterns is using your name, we will help you document it for a report. If you are a researcher or journalist working on this, our observations are available on request.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *