Oldenburg, Germany: numerous messages sent through one or more student accounts on Oldenburg schools' email servers contained AI-manipulated deepfake images of children and young people, some of which police say may meet the offence of distributing child or youth sexual abuse material, alongside threats of violence and calls to self-harm; students and parents reported it and police are investigating (September 2026)
The Oldenburg-Stadt police inspectorate said on 22 September 2026 that in the preceding days numerous messages had been sent through one or more student accounts on the email servers of Oldenburg schools. The messages contained, among other things, deepfakes (manipulated depictions of children and young people); on an initial assessment some of these could constitute the offence of distributing child or youth sexual abuse material, and some messages contained threats of violence and calls for recipients to harm themselves. According to dpa, students and parents reported the incidents to the police, and dpa, reporting a police spokesman, describes the images as made with artificial intelligence (the written police statement calls them deepfakes, manipulated depictions, without naming AI). Investigators are examining whether unknown persons gained unauthorised access to the accounts; first digital traces were secured and the police are working with the affected schools. RND reports that the accounts were on the IServ school platform, whose provider said it had no access to the messages and believed the incident was limited to Oldenburg. The exact number of schools (the police refer to 'the affected schools', plural), messages, depicted children and recipients, and who created the images, are not reported.
- AI system
- Unidentified image tool
- Occurred
- Sept 2026
- Reported
- 22 September 2026
- Event location
- Germany
- What the AI did
- Depicted or impersonated the person
- Reported harm
- Exploitation or Abuse
- Whose AI use
- Someone else’s AI use
- Setting
- Education · Privacy
- Evidence
- AI involvement reported · Causal attribution alleged · 4 sources, 2 underlying accounts
- 4 claims: 4 reported. 5 open questions
- People reported harmed
- Not reliably quantifiable from the sources
AI system as recorded: Unidentified AI image-manipulation tool used to produce deepfake images of children and young people; the tool and its operator are not reported. The messages were sent through student accounts on the IServ school platform (RND).
What Happened
The police statement on Presseportal (POL-OL, 22 September 2026) says the police learned that in the past days numerous messages had been sent through one or more student accounts on the email servers of Oldenburg schools. They contained, among other things, deepfakes, 'manipulated depictions of children and young people'; after a first assessment some of these depictions could be criminally relevant and meet the offence of distributing child or youth pornographic content. Some of the messages also contained threats of violence and calls to harm oneself. The police suspect one or more student accounts were used for sending and are examining whether and how unknown persons gained unauthorised access; they are working closely with the affected schools, have secured first digital traces, and the investigation into authorship and background continues. The statement advises recipients not to forward, share or download possibly criminal images or videos, not to delete the messages, to change passwords, and to use two-factor authentication. The dpa report carried by Zeit Online describes the images, in reporting a police spokesman's statements, as made with artificial intelligence and that students and parents had come forward and reported the incidents; the exact number of messages and where they were sent from was unclear. RND (Braunschweig edition, 23 September) identifies the platform as IServ; its spokesman said the schools operate their IServ platforms, that the company learned of the case through an Oldenburg school on the police's initiative, that it has no access to the messages or accounts, and that it assumes the incident occurred only in Oldenburg. IServ also said no compromise of user passwords was known and there was no indication that the schools' IServ instances had been compromised. None of the sources says whether the depicted children are students at the schools or whether they have been identified.
Reported harm
According to the Oldenburg police, AI-made deepfakes of children and young people, some possibly constituting child or youth sexual abuse material, were sent to students through school email accounts together with threats of violence and calls to self-harm; students and parents reported the incidents (police statement; dpa).
Outcome
OngoingPolice investigation by the Polizeiinspektion Oldenburg-Stadt into the origin and authorship of the messages and their criminal relevance, including whether unknown persons accessed the student accounts without authorisation; first digital traces secured and being analysed (police statement of 22 September 2026). No suspect, charge or school measure is reported.
What remains unknown
- Who created the deepfakes and with which AI tool; whether the student accounts were compromised or used by their holders.
- Whether the depicted children and young people are real, identifiable students at the schools, and how many were depicted.
- How many schools (more than one per the police statement), messages and recipients were involved (police: 'zahlreiche Nachrichten').
- Exact dates of sending ('in den vergangenen Tagen' before 22 September 2026).
- Any effects on the depicted children or recipients beyond the reports to police, and any school measures.
What the evidence supports
AI involvement: reported. The police statement calls the images deepfakes, 'manipulierte Darstellungen von Kindern und Jugendlichen'; dpa's report of a police spokesman's statements describes them as images created with artificial intelligence ('mit Künstlicher Intelligenz erstellten Bilder'); the written police statement does not mention AI. No tool is identified and no forensic finding is published.
4 claims: 4 reported. What the statuses mean
Reported In the days before 22 September 2026, numerous messages were sent through one or more student accounts on the email servers of Oldenburg schools; they included deepfakes (manipulated depictions of children and young people), some of which the police, on a first assessment, consider could meet the offence of distributing child or youth sexual abuse material, and some contained threats of violence and calls to harm oneself.
Causal attribution. Police statement (reviewer translation: 'The messages contained, among other things, so-called deepfakes, that is, manipulated depictions of children and young people'). Whether the material is criminal is under investigation.
- presseportal.de(opens in new tab) supports · German
'Der Polizei ist bekannt geworden, dass in den vergangenen Tagen über einen oder mehrere Schüleraccounts der E-Mail-Server Oldenburger Schulen zahlreiche Nachrichten versandt wurden.'; 'Die Nachrichten enthielten unter anderem sogenannte Deepfakes, also manipulierte Darstellungen von Kindern und Jugendlichen.'; 'Darüber hinaus enthielten die versandten Nachrichten zum Teil Gewaltandrohungen sowie Aufforderungen, sich selbst etwas anzutun.'
- oldenburger-onlinezeitung.de(opens in new tab) supports · German
'Einige Bilder könnten nach erster Einschätzung der Ermittler/innen kinder- oder jugendpornografische Inhalte darstellen.'
- presseportal.de(opens in new tab) supports · German
'Nach einer ersten Bewertung könnten einzelne dieser Darstellungen strafrechtlich relevant sein und den Straftatbestand der Verbreitung kinder- beziehungsweise jugendpornografischer Inhalte erfüllen.'
Reported dpa, reporting a police spokesman's statements, describes the images as created with artificial intelligence; students and parents had contacted the police and reported the incidents.
Causal attribution. dpa's report of a police spokesman (reviewer translation: 'Students and parents had contacted the police and reported the incidents').
- zeit.de(opens in new tab) supports · German
'Wie ein Polizeisprecher sagte, sollen einige der mit Künstlicher Intelligenz erstellten Bilder den Straftatbestand der Verbreitung kinder- oder jugendpornografischer Inhalte erfüllen.'; 'Schüler und Eltern hatten sich bei der Polizei gemeldet und die Vorfälle angezeigt.'
Reported Police are investigating whether unknown persons gained unauthorised access to the student accounts, have secured first digital traces, and are working with the affected schools; authorship remains under investigation.
Causal attribution. Police statement as published and relayed.
- presseportal.de(opens in new tab) supports · German
'Ob und auf welche Weise sich bislang unbekannte Personen unberechtigt Zugang zu diesen Accounts verschafft haben, wird durch die Ermittler geprüft.'
- oldenburger-onlinezeitung.de(opens in new tab) supports · German
'Die Ermittlungen zur Urheberschaft und zu den Hintergründen dauern an.'
- presseportal.de(opens in new tab) supports · German
'Die Polizei arbeitet eng mit den betroffenen Schulen zusammen. Erste digitale Spuren wurden bereits gesichert und werden derzeit ausgewertet.'
Reported The accounts were on the IServ school platform; an IServ spokesman said the company has no access to the messages or accounts and assumes the incident occurred only in Oldenburg; it said no compromise of user passwords was known and there was no indication that the school-operated IServ instances had been compromised.
Causal attribution. RND's reporting of the platform and of the company spokesman's statement; RND attributes the account description to the Oldenburg police, but the inspected police release does not name IServ, so the platform identification rests on RND.
- rnd.de(opens in new tab) supports · German
'Über einen oder mehrere Schüleraccounts der Plattform IServ sind in den vergangenen Tagen Nachrichten an Oldenburger Schulen verschickt worden'; 'Das Unternehmen habe keinen Zugriff auf die Nachrichten oder Einsicht in die Schüleraccounts.'; 'Wir gehen aber davon aus, dass der Vorfall nur in Oldenburg stattgefunden hat.'; 'Nach aktuellem Stand sei nicht bekannt, dass Passwörter von Nutzern kompromittiert wurden'; 'keine Hinweise darauf, dass die von den Schulen betriebenen IServ-Instanzen selbst kompromittiert worden seien'
Sources
4 sources inspected, from 2 underlying accounts. Sources that repeat one account do not corroborate each other.
- Polizeiinspektion Oldenburg-Stadt (POL-OL) on Presseportal, 22 September 2026: Manipulierte Bilder über Schüleraccounts versandt - Polizei ermittelt(opens in new tab)
s1 · presseportal.de · Official statement · German · Inspected · 22 September 2026 · Shares an underlying account with another listed source · Primary
- zeit.de(opens in new tab)
s2 · Wire report · German · Inspected · Shares an underlying account with another listed source
- rnd.de(opens in new tab)
s3 · News report · German · Inspected
- oldenburger-onlinezeitung.de(opens in new tab)
s4 · News report · German · Inspected · Shares an underlying account with another listed source
How the sources were read, and where the events happened
Read live on 2026-09-27 (police statement, 22 September 2026; German). Quotations are German originals; English renderings are reviewer translations, no human translator. Applies to s1.
Read live on 2026-09-27 (dpa Niedersachsen via Zeit Online, 22 September 2026; German). Adds a police spokesman's statements; same police chain as s1. Reviewer translation. Applies to s2.
Live fetch returned 403; read on 2026-09-27 via Internet Archive capture (RND, 23 September 2026; German). Police facts relayed from the same police chain; the IServ spokesman's statement is RND's own reporting. Reviewer translation. Its lede repeats the dpa lede verbatim. Applies to s3.
Read live on 2026-09-27 (Oldenburger Onlinezeitung, 22 September 2026; German). Rewrite of the police statement. Reviewer translation. Applies to s4.
Event countries: Germany. Affected-person countries: Germany. Court countries: Unknown.
The messages were sent through accounts on the email servers of Oldenburg schools and the Oldenburg-Stadt police are investigating (police statement). The depicted children's location is not stated, so affected_person_countries rests on the student recipients at Oldenburg schools. No court proceedings are reported.
Reviewed for publication 2026-09-27: Published under the 2026-09-15 charter as a core depicted_or_impersonated case: the police report AI-made deepfakes of children and young people, some possibly sexual abuse material, sent through school email accounts together with threats and self-harm calls, reported by students and parents. One police chain; RND adds the platform provider's statement. No child or school is identified.
People described
Children and young people depicted in the deepfakes, and students at Oldenburg schools who received the messages (numbers and identities not reported)
People reported harmed in this case
Not reliably quantifiable from the sources
The police speak of 'zahlreiche Nachrichten' (numerous messages) and depictions of children and young people but give no number of depicted children, recipients or schools; a count of messages is not a count of people. Unquantified with zero placeholders.
Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.
Cite this case
Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.
APA
NOPE. (2026). Oldenburg, Germany: numerous messages sent through one or more student accounts on Oldenburg schools' email servers contained AI-manipulated deepfake images of children and young people, some of which police say may meet the offence of distributing child or youth sexual abuse material, alongside threats of violence and calls to self-harm; students and parents reported it and police are investigating (September 2026). AI incidents. https://nope.net/incidents/2026-oldenburg-school-email-accounts-ai-deepfakes-of-children-threats
BibTeX
@misc{2026_oldenburg_school_email_accounts_ai_deepfakes_of_children_threats,
title = {Oldenburg, Germany: numerous messages sent through one or more student accounts on Oldenburg schools' email servers contained AI-manipulated deepfake images of children and young people, some of which police say may meet the offence of distributing child or youth sexual abuse material, alongside threats of violence and calls to self-harm; students and parents reported it and police are investigating (September 2026)},
author = {NOPE},
year = {2026},
howpublished = {AI incidents},
url = {https://nope.net/incidents/2026-oldenburg-school-email-accounts-ai-deepfakes-of-children-threats}
} Related cases
Berlin-Weißensee: two pupils of the Heinz-Brandt-Schule are suspected of creating and distributing AI-generated sexualised nude images of female classmates in at least three cases; the school suspended them and sanctioned pupils who are said to have known and not reported, and the police's sexual-offences unit investigates with liability under section 184c StGB (youth pornography) under consideration
On 'the previous Friday' (19 June 2026, read relative to the 24 June 2026 report) the leadership of the Heinz-Brandt-Schule in Berlin-Weißensee (Pankow district) learned that two of its pupils were suspected of having created and distributed AI-generated sexualised nude images of female classmates; the school wrote to parents that it was 'shocked and appalled' that classmates' photographs had been abused in this way and described the alleged acts as a massive attack on the personality rights of the affected girls and a form of sexualised violence. The two pupils alleged to be mainly responsible were suspended from lessons with immediate effect, and the school imposed measures on pupils who are said to have known about the images without reporting them. The Senate Department for Education confirmed the incidents and the ongoing investigation in the Tagesspiegel's report of 24 June 2026. The school's letter says the investigation is conducted on behalf of the public prosecutor. A Berlin police spokesman said complaints had been filed over the creation of so-called deepfakes, that the investigation had been taken over by the State Criminal Police Office unit responsible for sexual offences against minors, and that criminal liability for possessing, obtaining, creating or distributing youth pornography under section 184c of the Criminal Code was under consideration; the police gave no further details, citing victim protection. At least three cases are alleged. The school said it would revise its prevention and sex-education concepts and asked parents to talk to their children about handling other people's photographs and AI applications. Nobody is named; the number of girls depicted is not reported.
Henderson, Kentucky: police identified AI-generated nude images of two middle-school children on a device after a report that such images were being created and shown to other students at South Middle School; a juvenile was lodged at the juvenile detention centre on charges of distributing sexually explicit images without consent and possessing and distributing matter portraying a sexual performance by a minor
Henderson Police said that on 'last Thursday' (17 September 2026) they received a report that AI-generated nude images of children were being created and shown to other students at South Middle School in Henderson, Kentucky. During the investigation officers found and identified AI-generated photographs of two minor victims on a digital device. A juvenile accused of sharing the images was lodged at the Juvenile Detention Center on three charge types: distribution of sexually explicit images without consent; two counts of possession or viewing of matter portraying a sexual performance by a minor over 12 and under 18; and distribution of matter portraying a sexual performance by a minor over 12 and under 18. The school said on Monday 21 September that it was aware of a situation involving a student allegedly misusing artificial intelligence and inappropriate images, that the police investigation was active and that it had remained in communication with the families involved. 14 News (WFIE) reported the case on 21 September; WKYT carried the same report. The tool is not named. The depicted children's exact ages are not reported, though the charge descriptors put them between 12 and 18. The accused is described as a South Middle School student; the accused's age and any relationship to the depicted children beyond attending the same school are not reported.
East Jakarta: police confirm a grade-9 student at a state junior high school edited several female schoolmates' photographs with AI into indecent images that circulated as WhatsApp stickers; a social-media post said about 200 images were sold; the student was later beaten by schoolmates angry at the images (police statements differ on whether the depicted students or their friends did so) and both matters are under police investigation (Kompas, ANTARA, detik, VIVA, Media Indonesia, 23-24 September 2026)
On 23 September 2026 the spokesperson of the East Jakarta metropolitan police (Polres Metro Jakarta Timur) confirmed to reporters that a grade-9 student at a state junior high school in Pulogadung, East Jakarta, had edited photographs of several female schoolmates using artificial intelligence so that they appeared indecent, and that the edited images had been made into WhatsApp stickers; the police women-and-children protection unit is investigating. The case surfaced through a post on Threads which said about 200 edited photographs had been produced and sold to others; Kompas.com noted on 24 September that the sale allegation still rested only on that post, VIVA reported that police were still checking the claim that the images had been sold, and ANTARA reported on 23 September that police were still establishing the editing method, the recipients and the number of depicted students. As of 24 September the depicted students had not filed a report (detik and VIVA date the spokesperson's telephone remarks 'Kamis (22/9/2026)', a date that is internally inconsistent) and police appealed to them to do so. According to the parents' account relayed by police, on 15 and 16 September several people took the student who made the images to an empty house and then to a reservoir in Kayu Putih, punched him on the nose, ears and head, kicked his chest and stomach and threatened him with a bladed weapon; police attribute the beating to friends of the depicted students (ANTARA, detik, VIVA), while Kompas.com's 23 September report quotes the same spokesperson as saying the depicted students themselves beat him; he filed an assault report, which police are handling alongside the image case, and the school has held mediation with the students' parents. No student or school is named in the reports.
Jaú, São Paulo: eight 15-year-old ninth-grade boys at a private school are reported to have made fake nude images of a female classmate with artificial intelligence and shared them in a WhatsApp group; the school suspended them and the Civil Police are investigating a 15-year-old for dissemination of child pornography and defamation
In early September 2026 a private school in Jaú, in the interior of São Paulo state, identified the circulation of fake intimate images of a female classmate made with artificial intelligence and contacted the families. According to the police report described by the press, eight ninth-grade boys, all aged 15, kept a WhatsApp group in which they used digital programs to manipulate images of the student so that she appeared unclothed. The school suspended the eight and informed the girl's parents. The father of one of the boys checked his son's phone, found the files and took the boy and the phone to the police to register a report; the girl's parents also registered a police report. The São Paulo Public Security Secretariat said the Civil Police are investigating a 15-year-old for dissemination of child pornography and defamation that occurred on the morning of Thursday 3 September. The school said the content originated on a private platform outside the school environment and that it had adopted protective and welcoming measures for the student and opened an internal inquiry. The AI tool used is not named. The students are minors and are not named in any report.
If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.