Hello world,

as many of you may already be aware, there is an ongoing spam attack by a person claiming to be Nicole.

It is very likely that these images are part of a larger scale harassment campaign against the person depicted in the images shared as part of this spam.

Although the spammer claims to be the person in the picture, we strongly believe that this is not the case and that they’re only trying to frame them.

Starting immediately, we will remove any images depicting “Nicole” and information that may lead to identifying the real person depicted in those images to prevent any possible harassment.
This includes older posts and comments once identified.

We also expect moderators to take action if such content is reported.

While we do not intend to punish people posting this once, not being aware of the context, we may take additional actions if they continue to post this content, as we consider this to be supporting the harassment campaign.

Discussion that does not include the images themselves or references that may lead to identifying the real person behind the image will continue to be allowed.

If you receive spam PMs please continue reporting them and we’ll continue working on our spam detections to attempt to identify them early before they reach many users.

  • Scott_of_the_Arctic@lemmy.world
    link
    fedilink
    arrow-up
    21
    arrow-down
    2
    ·
    1 day ago

    I’ve heard that if you actually add her on friendica, the mayor of Toronto shows up at your house and gives you an old fashioned.

  • yarr@feddit.nl
    link
    fedilink
    English
    arrow-up
    40
    ·
    2 days ago

    This annoys the fuck out of me and I hope whoever is behind it doesn’t realize their goals, because I don’t want lemmy to degrade into a bunch of spam PMs.

    • douglasg14b@lemmy.world
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      18 hours ago

      TBF, it’s bound to happen.

      Guaranteed almost.

      Lemmy has minimal controls for protecting against spam and bot spam. It’s built to handle the internet 5 to 10 years ago, not the internet today.

      I can only hope that this changes because as soon as the platform becomes popular enough (which it is slowly). Then the rate of bot spam and other sorts of spam will just go through the roof, and there’s very little that admins can do to combat it without it becoming a full-time job.

      • KeenFlame@feddit.nu
        link
        fedilink
        arrow-up
        1
        ·
        4 hours ago

        We can have an opt in spam filter that makes it harder, the instances can defederate spamming instances (user) unless they do something which yes there is a lot admins can do at signup. Or have I misunderstood something?

    • Random_Character_A@lemmy.world
      link
      fedilink
      arrow-up
      6
      ·
      edit-2
      17 hours ago

      I don’t either want to see story on TV about Internet hacker group “Lenny” destroying womans life by a persistent harassment campaign.

  • YarHarSuperstar@lemmy.world
    link
    fedilink
    English
    arrow-up
    19
    ·
    2 days ago

    I’ve been thinking this since it started and saying it for a bit. I don’t understand at all how there were memes of this on the front page all the time and it took this long to do even this. Has there been any attempt at an effort to notify whoever is in the picture that this is happening? I would like to help if possible.

    • Zomg@lemmy.world
      link
      fedilink
      arrow-up
      20
      ·
      2 days ago

      I think “notify her” feeds the harassment they’re referring to, even if contacting her is well intended

      • YarHarSuperstar@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        17 hours ago

        I mean depending how its handled and on context, yes of course, but I’m not suggesting we traumatize this person further than whatever has already happened. Like someone else said letting the university is a decent first step.

  • 18-24-61-B-17-17-4@lemmy.world
    link
    fedilink
    English
    arrow-up
    20
    arrow-down
    1
    ·
    2 days ago

    I can’t believe I managed to never get one of these spam messages. I didn’t even know what a Nicole was until the week or two ago.

  • Mpatch@lemmy.world
    link
    fedilink
    arrow-up
    324
    arrow-down
    3
    ·
    3 days ago

    I gotta give it to you guys. The foresight to prevent a disaster is 10/10. Top tier. Well done.

      • finitebanjo@lemmy.world
        link
        fedilink
        arrow-up
        14
        arrow-down
        4
        ·
        3 days ago

        I saw a theory a while back that the IPs which receive the various images get logged allowing the recipients accounts to be tied to an IP and possibly even a physical address based on the timeframe it was sent. Is that a real concern or just conspiracy, do you think?

        • MrKaplan@lemmy.world
          link
          fedilink
          English
          arrow-up
          22
          ·
          3 days ago

          That appears to be a baseless conspiracy theory.

          Except for the gore pms, I believe all the images have been uploaded to Lemmy instances or Imgur, which means that the uploader has no way to track IPs accessing those images. The gore images were uploaded to another service that at least on the surface appears to be another regular image hoster that wouldn’t expose IP access logs to uploaders.

          • Aphelion@lemm.ee
            link
            fedilink
            arrow-up
            7
            ·
            3 days ago

            I don’t think its baseless given that anyone can set up their own Lemmy instance to host the PM’d images.

            • MrKaplan@lemmy.world
              link
              fedilink
              English
              arrow-up
              6
              ·
              3 days ago

              The instance domains I’ve seen involved so far at least weren’t set up specifically for this purpose at least. Most of the URLs were pointing to established services and not different per recipient.

              While I can’t rule out that individual users may have received a different URL in an attempt to extract their IP and information about their browser, this at least does not appear to have been done in a larger scale.

              • Captain Aggravated@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                5
                ·
                2 days ago

                A day or two ago, someone spammed out a picture of a murdered body with the standard Fediverse Chick copypasta. That seemed to freak people out; the nicoled community locked down, this thread happened, etc.

                The gore photo seems to be a second actor/copycat. The Nicole spammer either came from their own instances or opened accounts very shortly before spamming, the gore photo, and a following anime style picture done in red-on-white saying “Do you like insanity?” seem to come from accounts that were made 2 years ago.

        • Ricky Rigatoni@lemm.ee
          link
          fedilink
          arrow-up
          2
          arrow-down
          1
          ·
          3 days ago

          I find it difficult to believe there are enough fediverse users not using a VPN at all times to make that effort worthwhile.

    • givesomefucks@lemmy.world
      link
      fedilink
      English
      arrow-up
      53
      arrow-down
      4
      ·
      3 days ago

      It’s pretty obvious …

      What’s scary is how many people just accepted that some woman wanted to randomly spam thousands of pictures with her smoking weed.

  • CarbonatedPastaSauce@lemmy.world
    link
    fedilink
    English
    arrow-up
    256
    ·
    3 days ago

    Yeah it seemed funny at first but the longer this went on the creepier it got as we all realized this isn’t just a catfish.

    Whoever is doing this to the actual person in the photos is a terrible human being and should go climb under a rock for the rest of their lives.

        • tischbier@feddit.org
          link
          fedilink
          English
          arrow-up
          6
          ·
          1 day ago

          It got super creepy when more shots of this women were released of her doing activities that no one would ever take a photo of themselves doing. Then the last photo was released separately of a NSFW don’t read if you are not in a place to read gore/graphic/assault

          Tap for spoiler

          Real photo of a dead woman who looks like Nicole in a morgue body bag with her flesh peeled off and her face beaten. It’s unlikely that this disturbing turn is real but it was horrific for people who received this last spam. That is what triggered the ultimate ban on all images (since this is most likely a psychopathic copycat). :(

        • TacoSocks@infosec.pub
          link
          fedilink
          English
          arrow-up
          33
          ·
          3 days ago

          I’ve seen several different images and there was a video on peertube. All of them look like content from a hacked webcam.

          • Ghoelian@lemmy.dbzer0.com
            link
            fedilink
            arrow-up
            16
            ·
            3 days ago

            Yeah, that’s what I thought from the very first DM I received. It looks like Shea totally unaware a picture was taken of her. Surely, if this were real, “Nicole” would use a more flattering picture to potential friends.

        • Cryophilia@lemmy.world
          link
          fedilink
          arrow-up
          11
          arrow-down
          2
          ·
          3 days ago

          It’s just creepy because in every other obvious scam like this for the last 10 years they use the same single picture of the same person on everyone. Now suddenly there are dozens of different pictures, all clearly of the same woman, going to different people.

  • jaybone@lemmy.zip
    link
    fedilink
    English
    arrow-up
    122
    arrow-down
    2
    ·
    3 days ago

    Is this Nicole thing really still a thing? That’s so like back when I still had a 401k.

    • Senseless@feddit.org
      link
      fedilink
      arrow-up
      30
      ·
      edit-2
      3 days ago

      So was it last week or the day before yesterday? It all happens so fast, I can’t - and frankly - refuse to catch up.

    • stebo@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      5
      ·
      3 days ago

      i received another message yesterday, after my instance’s admin claimed they fixed the issue (i assume my blocking the spammer’s ip address from making new accounts)

      • MrKaplan@lemmy.world
        link
        fedilink
        English
        arrow-up
        17
        ·
        3 days ago

        the problem with this spam and generally federated platforms is that you can only really try detecting it based on the content. the accounts tend to get created on another instance and then the messages federate over to you, which means you won’t see a lot of the identifying information you’d see for a local user, such as their IP address.

        • jaybone@lemmy.zip
          link
          fedilink
          English
          arrow-up
          4
          ·
          2 days ago

          IP bans aren’t great either. A decent spammer will just use a vpn. Then you’re just banning IPs from a service that other users might also use. An even more sophisticated bad actor would just use a bot net.

        • PattyMcB@lemmy.world
          link
          fedilink
          arrow-up
          5
          ·
          3 days ago

          I just chalked it up to “a necessary evil” in order to take advantage of federated platforms. I found it funny at first, and then just ignored it. I never thought that it could’ve been some smear campaign, but rather scammers looking for easy targets.

          I’m glad mods are doing something about it, even if it’s not a perfect fix.

  • Squirrelanna@lemmynsfw.com
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 days ago

    To clarify for others, as I have no interest in doing this myself, but if people feel like sharing, are they allowed to do so provided they censor the pictire/remove it entirely from a screenshot? Not sure why someone would, but I figure it doesn’t hurt to ask.

  • mechoman444@lemmy.world
    link
    fedilink
    arrow-up
    71
    ·
    3 days ago

    About damn time. The joke has run it’s course a long time a ago and if these posts are victimizing an individual they most definitely need to be stopped.

  • DonutsRMeh@lemmy.world
    link
    fedilink
    arrow-up
    38
    ·
    2 days ago

    Damn, I never thought about it this way. Wow. I always took it as a funny thing not thinking of the person in the photo being an actual person who could very well be harassed. Thank you for bringing this to light. Whoever thought of this is a good human being. <3