Victims filed removal requests to scrub abuse content from the web. Those same requests were then published online, naming them, their schools, their workplaces, and in some cases their families.
Reporting by The Hankyoreh shows this was not a Korea-specific failure. Victims from Brazil, Japan, Argentina, Bolivia, Colombia, and Vietnam were exposed through Google’s practice of forwarding legal takedown notices to Project L, a public transparency archive affiliated with Harvard Law School, known publicly as Lumen.
A Pipeline Built for Transparency Became a Source of Harm
The system meant to guard against secret censorship ended up publishing the private disclosures of sex crime victims verbatim.
Lumen was designed to document legal demands to remove online content, functioning as a public check against secret censorship. Google’s own help documentation states it forwards copies of legal notices to Lumen “for publication” when legally permitted.
Google had indicated it would not share sensitive data from digital sex crime removal requests. Hankyoreh’s investigation found those requests were transmitted and published with identifying information intact, including full names, student ID numbers, phone numbers, workplaces, and detailed descriptions of abuse.
Google VP for Trust and Safety Amanda Storey described the exposure as what she characterized as “an unintended disclosure of information” resulting from “human error.” Google said it “permanently deleted the exposed data relating to victims in Korea” and halted transmission of new Korean removal notices to Lumen.
Google has not publicly explained how its internal rules against sharing sensitive data were bypassed. It has also not disclosed what filtering or categorization systems existed, or what specific technical safeguards it is now building into the pipeline.
Victims From Multiple Countries Were Exposed
The testimony Hankyoreh reviewed, drawn directly from published removal requests, makes the global scope concrete.
A Brazilian victim wrote: “Photos of me from when I was a minor were distributed without my consent. They were posted on an adult website, but I was 13 or 14 at the time.”
A Japanese victim described a secretly filmed video reposted on a public adult site, writing that its existence had left them “mentally and physically exhausted.” A Bolivian victim filed more than 10 removal requests within a single month in 2018. When Hankyoreh checked years later, at least one of the original URLs remained accessible.
Requests appeared in Japanese, Spanish, and Portuguese, suggesting Google’s routing system did not distinguish by content sensitivity across languages or legal regimes. Cases involving deepfakes and hacked intimate content were also among those exposed, according to Hankyoreh’s review.
Regulators Are Moving; Key Questions Remain Open
Korean authorities have opened a formal investigation and are demanding years of Google records.
Korea’s Personal Information Protection Commission has launched a formal investigation into how victims’ data was exposed through Google’s removal process. Korean authorities have separately demanded years of Google records related to the incident.
The Ministry of Gender Equality and Family and the Korea Communications Standards Commission pressed for deletion of 47 confirmed victim requests. At least 100 additional instances also surfaced, where victim-support organization names appeared as searchable terms in Lumen’s database.
Hankyoreh reported a 13-day window between notifying Korean authorities and the full removal of the exposed data.
The total number of affected victims globally remains unknown. Google has offered no public timeline for notifying those whose data was published, and has not said whether it will restructure its transparency model to exclude victim-initiated abuse reports from external sharing entirely.




























