Why this happens

Cloud account credentials are commonly compromised through phishing, password reuse on breached sites, and SIM swap attacks. Two factor authentication via SMS provides only partial protection against modern attackers.

Once inside, attackers commonly download the full photo library before exiting. The original account compromise may have occurred weeks before the content surfaces online.

Legal framework in Ireland

Harassment, Harmful Communications and Related Offences Act 2020, sections 2 and 3. Section 2 (intent to cause harm): up to 7 years on indictment. Section 3 (without intent to harm): up to 12 months on summary conviction.

Ireland's Coco's Law (named for Nicole Fox Fenlon) created two tiered offences: a serious indictable offence where intent to cause harm is shown, and a summary offence where it is not. Coimisiún na Meán enforces platform compliance under the broader online safety regime.

Evidence to preserve

Do not: Do not change passwords before the access logs are preserved. Account log retention is limited and changing the password may trigger log rotation that erases the intrusion evidence.

Five step removal process

  1. 1

    Preserve all evidence first

    Cloud account access logs showing the unauthorized access dates and IP addresses. The full list of devices and locations that have accessed the account.

  2. 2

    File the Harassment, Harmful Communications and Related Offences Act 2020 (Coco's Law) criminal complaint

    Report to local police or the national cybercrime unit. Hotline.ie can assist.

  3. 3

    Submit an erasure request under GDPR Article 17 (right to erasure) plus Data Protection Act 2018

    Each major platform has a designated data protection contact. The request must cite the legal basis and identify the URLs. The platform has 30 days to respond. DPC accepts complaints for non compliance.

  4. 4

    Run a biometric scan to find every additional copy

    Content posted to one platform is rarely confined to one platform. ScanErase identifies every current hosting location in a single scan, including mirror copies and AI generated variants.

  5. 5

    File TAKE IT DOWN Act notices for covered platforms

    Use your scan report to file the federal 48 hour notice yourself, in parallel with your domestic rights. The two regimes are cumulative, not exclusive.

Statutory citations to include in your complaint

Frequently asked questions

Is cloud account hack a crime in Ireland?

Yes. Harassment, Harmful Communications and Related Offences Act 2020, sections 2 and 3 criminalises this conduct. Section 2 (intent to cause harm): up to 7 years on indictment. Section 3 (without intent to harm): up to 12 months on summary conviction.

What evidence should a Ireland victim of cloud account hack preserve?

Cloud account access logs showing the unauthorized access dates and IP addresses. The full list of devices and locations that have accessed the account. Any password change notifications, recovery emails, or security alerts received. Full page screenshot of every URL where the leaked content has appeared.

Does GDPR Article 17 (right to erasure) apply to this scenario?

Yes. GDPR Article 17 (right to erasure) plus Data Protection Act 2018 gives the victim a direct erasure right against any platform processing the imagery. DPC enforces non compliance.

What support is available in Ireland for cloud account hack?

Hotline.ie provides direct support to victims and can assist with both the criminal complaint and the platform removal process. Contact at https://www.hotline.ie.

Can a Ireland victim also file a US TAKE IT DOWN Act notice?

Yes when the hosting platform is subject to US jurisdiction. The 48 hour federal removal obligation runs in parallel with rights under Harassment, Harmful Communications and Related Offences Act 2020 (Coco's Law) and GDPR Article 17 (right to erasure) plus Data Protection Act 2018.