If you have encountered child sexual abuse material (CSAM) online, your immediate priority is to report it to the correct authority. This is not a situation where you should attempt to gather evidence, investigate the source, or handle the material in any way. Reporting CSAM is a legal obligation for service providers in most jurisdictions and a moral imperative for everyone. This article exists to direct you to the right reporting channels as quickly as possible. For a broader overview of the abuse reporting process, see my complete guide to reporting IP abuse.
Critical Warnings Before You Proceed
Read these before taking any other action:
- Do NOT download, screenshot, or save CSAM material. Possessing this material is a criminal offense in virtually every jurisdiction, even if your intent is to preserve evidence for a report.
- Do NOT attempt to investigate the source yourself. Tracing hosting infrastructure, contacting suspected perpetrators, or conducting any form of independent investigation can compromise law enforcement operations already in progress.
- Do NOT share the material with anyone other than the official reporting channels listed below. Forwarding CSAM, even to report it, through unofficial channels is illegal.
- Report immediately using the appropriate channel below. Note the URL where you encountered the material and report it. That is all you need to do.
Where to Report CSAM
NCMEC CyberTipline (United States)
The National Center for Missing & Exploited Children operates the CyberTipline at report.cybertip.org. This is the primary reporting mechanism for CSAM in the United States and accepts reports from anywhere in the world. NCMEC works directly with law enforcement agencies and has legal authority under federal law to receive and process these reports. US-based electronic service providers are legally required to report to NCMEC under 18 U.S.C. Section 2258A.
If you are in the US or the material is hosted on US infrastructure, this should be your first report.
IWF (United Kingdom and International)
The Internet Watch Foundation at iwf.org.uk is the UK's designated reporting body for CSAM. The IWF also operates internationally and maintains a URL list used by ISPs and hosting providers worldwide to block known CSAM content. If you are in the UK or the material is hosted on UK infrastructure, report through the IWF portal. The IWF also accepts reports from outside the UK.
National Reporting Hotlines by Country
Different countries have designated bodies responsible for receiving CSAM reports. Use the hotline for the country where you are located or where the content appears to be hosted:
| Country | Reporting Body | Website |
|---|---|---|
| United States | NCMEC CyberTipline | report.cybertip.org |
| United Kingdom | Internet Watch Foundation (IWF) | iwf.org.uk |
| Canada | Canadian Centre for Child Protection | cybertip.ca |
| Australia | Australian Federal Police / eSafety Commissioner | esafety.gov.au |
| European Union | INHOPE Network (national hotlines per member state) | inhope.org |
| New Zealand | Department of Internal Affairs | dia.govt.nz |
| Germany | eco Complaints Office / jugendschutz.net | internet-beschwerdestelle.de |
| France | Point de Contact / PHAROS | internet-signalement.gouv.fr |
If your country is not listed, the INHOPE network (inhope.org) maintains a directory of member hotlines in over 50 countries. You can also report directly to NCMEC's CyberTipline, which forwards reports to the appropriate international law enforcement agencies.
Hosting Provider
If you can identify the hosting provider or ISP serving the content, many providers maintain a dedicated csam@ contact address specifically for these reports. You can use the IP Location tool to look up the IP address of the server hosting the material and find the abuse contact information for the hosting provider.
When reporting to a hosting provider, keep your report brief: provide the URL, the date and time you encountered it, and state that the content is CSAM. The provider's trust and safety team will handle the rest. Do not include any description of the material itself.
Law Enforcement
For situations where a child is in immediate danger, contact local emergency services (911 in the US, 999 in the UK, 112 in the EU). For non-emergency law enforcement reports:
- United States: FBI (tips.fbi.gov) or local FBI field office. See also my guide on reporting cybercrime to law enforcement and the FBI IC3.
- United Kingdom: National Crime Agency (NCA) CEOP Command at ceop.police.uk
- Canada: Local police and RCMP
- Australia: Australian Federal Police at afp.gov.au
What Information to Include in Your Report
When filing a report through any of the channels above, include the following:
- The URL where you encountered the material. This is the single most important piece of information. Copy the full URL from your browser's address bar.
- Date and time of discovery: as precise as possible, including your time zone.
- How you encountered the material: brief context such as "found via search engine," "appeared on a forum," or "hosted on a website I was reviewing for abuse."
- IP address of the server (if known), use the IP Location tool to look up hosting details if you have the domain or IP.
- Your contact information: so the reporting body or law enforcement can follow up if needed.
Do NOT include the material itself. Do not attach images, videos, or screenshots to an email. Use only the official reporting portals (NCMEC CyberTipline, IWF, or your national hotline), which are built to receive this type of report securely and legally.
Legal Obligations
For Service Providers
In the United States, 18 U.S.C. Section 2258A requires a provider to report qualifying material to NCMEC as soon as reasonably possible after obtaining actual knowledge, and penalizes a provider that knowingly and willfully fails to do so. This applies to hosting companies, ISPs, social media platforms, cloud storage providers, and any entity that provides an electronic communication service or remote computing service. Note that the duty attaches to providers, not to every individual who encounters the material.
The penalty amounts were raised by the REPORT Act in May 2024, so figures you find in older write-ups are out of date. For an initial knowing and willful failure the maximum fine is $850,000 for a provider with at least 100 million monthly active users and $600,000 for a smaller provider. For a second or subsequent failure the maxima are $1,000,000 and $850,000 respectively. (The pre-2024 figures were $150,000 and $300,000.)
In the United Kingdom, the duty to report detected and previously unreported CSEA content to the National Crime Agency took effect on 7 April 2026. Ofcom’s provider guidance explains the scope for regulated user-to-user services, registration, reporting formats and how prior NCMEC reporting affects the duty. It does not require a service to detect content it has not identified. Apply the rules for the specific service rather than assuming a single workflow applies to every provider.
In the European Union, distinguish the proposed long-term regulation from existing national duties and temporary rules for voluntary detection. The Council’s current policy overview tracks these separate measures. A proposal is not itself a reporting obligation; providers need the applicable enacted rules for their service and jurisdiction.
For Individuals
Members of the public can report suspected child sexual exploitation through the NCMEC CyberTipline or their national hotline. Individual reporting duties depend on jurisdiction and role. The provider-specific duties above must not be treated as a universal rule for every individual.
If You Are a Hosting Provider or ISP
If you operate hosting infrastructure and receive a CSAM report or discover CSAM on your systems, follow this sequence:
- Restrict public access promptly. Use the provider's incident procedure to prevent further public access while preserving existing data under controlled access. Do not leave material available while waiting for a forensic copy.
- Activate the provider's legal and incident-response process. Qualified personnel should determine applicable reporting and preservation duties. This is not an instruction for members of the public to download or copy material.
- Use the official reporting channel. Follow the current NCMEC provider guidance where applicable and contact appropriate law enforcement.
- Preserve existing relevant records securely. Limit access, record the handling steps and follow lawful retention instructions. Avoid unnecessary viewing or redistribution.
- Document actions and timestamps. Keep reporting references and an access record; documentation is useful evidence, not a guarantee of legal protection.
If you are unsure about your legal obligations as a provider, consult legal counsel experienced in internet law and CSAM compliance in your jurisdiction. Do not delay reporting while seeking legal advice, file the report to NCMEC or your national hotline first, then consult counsel.
A compromised customer account may explain how material reached a service, but it does not remove an applicable provider reporting duty. Coordinate containment, lawful preservation and reporting through the provider’s incident process. The general server-compromise guide provides related operational context; its collection steps are not instructions for a member of the public to copy suspected CSAM.
This article is part of the IP Abuse Reporting Guide. See also: Report Cybercrime to Law Enforcement and the FBI IC3.

