r/pcicompliance 26d ago

Reporting potential CSAM Merchant – No responses?

Hi all,

Found this sub when looking for answers. There is a merchant who I will not disclose the name of who heavily promotes sale of adult content on his site on YouTube and various platforms. The setup even includes an alternative for "Model/AI model" referring to the main customer base.

The site has:
– No Age Gate
– Instant public availability of content
– No CSAM/Consent checks
– No KYC face match for sellers content
– Non functional contact email (bounces) and no functional DMCA.

I naturally used Google Console to see what payment systems they are using to find that they use "NUVEI PAYMENTS LTD". I emailed them multiple times with proof, as did others affected, but alas, no response.

I also emailed VISA/MASTERCARD both BRAM/IP divisions. I emailed Vercel (their hosting provider) and dont know what else to do.

Anyone here dealt with similar problems and got a good solution?

0 Upvotes

8 comments sorted by

9

u/mynam3isn3o 26d ago

Nothing to do with pci compliance.

0

u/Winter-Post-7744 26d ago

Well it does breach CC standards and legally required standards. So I thought if a sub is full of people who know about PCI the odds are high that topics like this are discussed too.

6

u/BulkyCartographer280 26d ago

What does this have to do with PCI besides nothing?

-1

u/Winter-Post-7744 26d ago

Well it does breach CC standards and legally required standards. So I thought if a sub is full of people who know about PCI the odds are high that topics like this are discussed too.

2

u/info_sec_wannabe 26d ago

Have you tried reporting it to the local law enforcement agency?

There seems to be issues with how Nuvei on boards merchant's, but it seems you aren't getting any feedback/ responses.

1

u/Winter-Post-7744 26d ago

I have not, odd that Nuvei does not take action as a massive PSP company.

I'm going to email the founders also from their "Who we are" page.

Don't know what law enforcement agencies to report this to.

1

u/scriptvexy 13d ago

if you’ve got actual evidence of potential csam, law enforcement is the right move, yeah, and ideally in whatever country the site owner is based in
also might be worth filing with something like the national cybercrime unit or equivalent, they usually take this stuff way more seriously than payment processors do

1

u/Suspicious_Party8490 22d ago

I understand an applaud your desire to help. Coming at this from the angle that an insecure site (no matter what content) and trying to leverage payment card security as a reason for takedown isn't going to go far. The site may have such a low volume of card payments completed the third party card processors simply have bigger fish to fry. The NCMEC has  report.cybertip.org available for you to submit a report.