Is Ghost-Chatting Legal? OnlyFans Lawsuits 2026

What the OnlyFans chatter class actions alleged, how the December 2025 N.Z. v. Fenix ruling landed, and how agencies reduce ghost-chat liability.

Yasmin Khalil, Head of Compliance and Legal at WhaleFinders

Yasmin Khalil

Head of Compliance & Legal

15 min read

Is Ghost-Chatting Legal? OnlyFans Lawsuits 2026

TL;DR: No US statute bans ghost-chatting outright, and in December 2025 a federal judge dismissed every claim in N.Z. v. Fenix, the largest OnlyFans chatter class action to date. But read the order closely and the picture is uncomfortable for agencies: OnlyFans escaped on personal jurisdiction, Section 230, and its own terms-of-service disclosures, three defenses that agency companies mostly cannot use. By May 2026 the platform was out of the amended case while a privacy claim survived against the chatter agencies themselves. Ghost-chatting remains legal to operate, but the liability now sits with us, the agencies, and the fix is operational: written creator authorization, hard conduct rules for chatters, and disciplined data handling.

What Ghost-Chatting Is and Why It Got Sued

Ghost-chatting is the practice of trained operators (chatters) sending and answering direct messages from a creator's account, in the creator's voice, with the creator's permission. It is the revenue engine of nearly every serious OnlyFans agency. Paid messages, tips, and unlocked content driven by conversation routinely produce 50 to 80 percent of a managed account's earnings, and no individual creator can hold hundreds of simultaneous conversations across time zones. That is the entire reason chatter jobs exist as a profession and why agencies invest in structured hiring and training pipelines.

The scale makes the outsourcing obvious once you look at the numbers. OnlyFans' FY2024 filing shows $7.22 billion in gross fan spend across 4.63 million creator accounts and 377.5 million fan accounts, handled by a company with 46 employees. The platform takes its 20 percent fee and leaves the labor of monetization to creators, which in practice means creators' teams. Messaging at that volume was never going to be one woman on one phone.

The legal problem is not the labor arrangement. It is the fan's belief. Fans pay under the impression that they are talking to the creator herself. When two Illinois subscribers concluded they probably were not, and when five anonymous plaintiffs in California reached the same conclusion a year earlier, that gap between belief and reality became the theory of two class actions. Fraud, misrepresentation, privacy violations, and racketeering were the labels; "I paid for her and got an employee" was the substance.

For agencies, this litigation wave matters more than any terms-of-service debate. Platform permission questions are contract questions between the creator and OnlyFans. Lawsuits are different: they are fans, with lawyers, testing whether ghost-chatting is actionable deception. In 2025 and 2026 a federal court finally gave partial answers.

Inside the Class Actions: What Fans Alleged

Two cases define the landscape.

N.Z. v. Fenix International Ltd. was filed on July 29, 2024 in the Central District of California, case number 8:24-cv-01655-FWS-SSC, by five plaintiffs proceeding under their initials, represented by class-action firm Hagens Berman. The complaint named the OnlyFans corporate entities (Fenix International Limited and Fenix Internet LLC) alongside a roster of management companies. According to classaction.org, the agency defendants included Unruly Agency (doing business as Dysrpt Agency), Elite Creators, Moxy Management, Boss Baddies, Behave Agency, A.S.H. Agency, Content X, and Verge Agency. All of those claims were later dismissed, which matters when we talk about what was actually proven: nothing was.

The allegations were sweeping. Plaintiffs claimed OnlyFans charges fans to "communicate directly with creators," then connects them instead with professional chatters hired to impersonate creators and push spending higher, using scripts and CRM tooling to run dozens of personas at once. Reporting by 404 Media and the Hagens Berman case page described chatter workforces operating from countries such as Venezuela, the Philippines, and Romania. On top of the deception theory, plaintiffs stacked a privacy theory: that intimate messages, photos, and purchase histories fans believed were shared with one person were actually exposed to rotating shifts of strangers.

The legal claims ran the table: civil RICO and RICO conspiracy, the federal Wiretap Act, the Video Privacy Protection Act, the California Invasion of Privacy Act, California Penal Code section 502 (unauthorized computer access), breach of contract, fraud and deceit, and California's Unfair Competition Law and False Advertising Law.

Brunner and Fry v. Fenix, the second case, was filed in the Northern District of Illinois in spring 2025 by two Illinois subscribers, as reported by Court Watch and 404 Media. It is narrower: it targets only the Fenix entities and leans on breach of contract and consumer-deception theories, alleging OnlyFans "consciously and deliberately frustrates the agreed common purposes of the contract" by letting fans believe chat is authentic. Notably, the complaint conceded the plaintiffs had no direct proof they ever spoke to a chatter; they inferred it from message volume and inconsistencies, including one creator with roughly 700,000 subscribers whose personal reply volume would be physically impossible.

That evidentiary weakness is worth flagging because it runs through both cases. No plaintiff produced a chat log with a confirmed chatter on the other end. The complaints argue the system makes deception inevitable; they do not document a specific lie by a specific defendant to a specific plaintiff. Federal fraud pleading standards punish exactly that gap.

N.Z. v. Fenix: What the Court Actually Decided

On December 12, 2025, US District Judge Fred W. Slaughter dismissed every claim in N.Z. v. Fenix (2025 WL 3627591), with leave to amend by January 2, 2026. Eric Goldman's Technology & Marketing Law Blog, which covered the ruling in detail, headlined it as OnlyFans defeating the "chatter scam" claim. The claim-by-claim breakdown is where the agency lessons live.

  • RICO and RICO conspiracy: Outcome: Dismissed, Court's reasoning: No coordinated enterprise or common fraudulent purpose pled; underlying wire fraud not alleged with specificity

  • Federal Wiretap Act: Outcome: Dismissed, Court's reasoning: No interception "in transit"; chatters read messages after delivery

  • California Invasion of Privacy Act: Outcome: Dismissed, Court's reasoning: Same in-transit defect

  • Video Privacy Protection Act: Outcome: Dismissed (as then pled), Court's reasoning: Disclosed data "would not readily permit an ordinary person to identify the specific person"

  • Penal Code 502: Outcome: Dismissed, Court's reasoning: No unauthorized access overcoming technical barriers

  • Fraud and deceit: Outcome: Dismissed, Court's reasoning: Terms of service disclosed the possibility of third-party agents, undermining justifiable reliance

  • Breach of contract: Outcome: Dismissed, Court's reasoning: Integration clause plus the disclaimer that fan and creator transactions are contracts between fans and creators

  • UCL and FAL: Outcome: Dismissed, Court's reasoning: Derivative of the failed fraud and privacy claims

Three structural rulings mattered as much as the merits. First, the court held it had no personal jurisdiction over Fenix International Limited or Fenix Internet LLC at all: the UK-based operator's California contacts were too thin. Second, Section 230 of the Communications Decency Act partially applied. Claims treating OnlyFans as the publisher of communications between fans and creator accounts were barred; only claims based on OnlyFans' own representations survived that filter, and those then failed on the terms-of-service disclosures. Third, the court sanctioned plaintiffs' counsel roughly $13,000 under Rule 11 after briefs were found to contain AI-hallucinated material, a $10,000 fine involving a Hagens Berman partner and $3,000 against co-counsel who had used ChatGPT to draft portions of the filings, as the ABA Journal reported.

Then came the 2026 sequel. Plaintiffs amended, and on May 22, 2026, Bloomberg Law reported that the court again dismissed Fenix International from the case, while a Video Privacy Protection Act claim survived against the chatter agency defendants. Sit with that asymmetry for a second. After nearly two years of litigation, the platform is out. The agencies are the parties still standing in front of a federal judge.

What the Ruling Does Not Settle for Agencies

It would be easy to read December 2025 as "ghost-chatting won." That is not what happened, and we would be doing our own segment a disservice by pretending otherwise. Four limits matter.

The dismissal was procedural and pleading-based, not a blessing. No court held that ghost-chatting is lawful or that fans have no claim. The court held that these plaintiffs, on these complaints, failed to plead viable claims. Leave to amend was granted, an amended complaint was filed, and part of it survived. A dismissal for failure to plead fraud with specificity is an invitation to plead better, and plaintiff firms now have a public roadmap of exactly which allegations were missing.

OnlyFans' best defenses are not our defenses. Fenix won on personal jurisdiction because it is a foreign operator with thin forum contacts. A US agency LLC that recruits American creators, banks in dollars, and messages American fans is subject to jurisdiction where it operates. Fenix won partially on Section 230 because it hosts third-party communications; an agency does not host chatter messages, it authors them, which is exactly the conduct 230 does not protect. And Fenix won on its own terms of service, a contract the fan clicked through with the platform. An agency has no contract with the fan at all, so there is no disclosure document to point to.

The wiretap reasoning is fact-specific. The interception claims failed because plaintiffs described chatters reading messages after delivery inside the account. Different facts, such as message data mirrored in real time into external CRM or notification tooling, could be argued differently by a sharper complaint. Agencies running third-party inbox software should treat that as a live design question, not a settled one.

The privacy exposure is now agency-shaped. The claim that survived into mid-2026 is the Video Privacy Protection Act claim against agencies. The VPPA carries statutory damages of $2,500 per violation, which is what makes it a class-action favorite. The theory, that fan identity plus intimate purchase and viewing data was exposed to unauthorized third parties, describes the everyday data flow of a sloppy chatting operation. Whether it ultimately holds up or not, the pleading survived a motion to dismiss, and discovery against agency defendants is where operational sloppiness becomes evidence.

The Agency Liability Map: Fraud, Contract, and State Law Theories

Here is the honest map of where a fan-side lawyer, a state attorney general, or a disgruntled creator could aim next. None of this requires new law; every theory below already exists.

Fraud and consumer protection

The fraud claim in N.Z. failed on justifiable reliance because the platform's terms disclosed that third parties might be involved. That shield thins dramatically when the misrepresentation happens inside the chat itself. A chatter who types "yes baby it's really me, I don't use assistants" when a fan asks directly has manufactured a specific, documented, false statement of fact, the exact ingredient the dismissed complaints lacked. Every state has an unfair and deceptive acts statute (California's UCL, the Illinois Consumer Fraud Act, and their siblings), and those statutes do not require a contract with the defendant.

Contract and creator-side claims

Fans have contract privity problems suing agencies. Creators do not. A creator who never authorized account access in writing, or whose contract is silent on who speaks in her name, can plausibly frame aggressive chatter conduct as breach, misappropriation of her identity, or damage to her brand. This is why management contract clauses covering account operation, communications authority, and indemnification are not boilerplate; they are the difference between "she authorized us to do exactly this" and a right-of-publicity fight with our own client.

Impersonation and publicity statutes

Several states criminalize online impersonation, including California Penal Code section 528.5 and Texas Penal Code section 33.07. Read them carefully and the operative words are "without consent" of the person impersonated, plus intent to harm or defraud. Ghost-chatting with the creator's written consent is on the right side of that line as to the creator. The unresolved academic question is whether the fan can be the defrauded party under such statutes; we have not seen a successful case on that theory, and the December ruling gives no comfort to it, but "untested" is not the same as "safe."

Privacy and data claims

The surviving VPPA claim is the template: fan identity linked to intimate content consumption, disclosed to people the fan never agreed to. Add state privacy statutes, and add the mundane risk of a chatter screenshotting fan conversations to a group chat. Every one of those screenshots is a potential exhibit.

Employment claims from inside

The plaintiffs' bar does not only represent fans. Chatters themselves, typically overseas contractors paid hourly plus commission, raise worker classification questions that are their own liability lane. A misclassification claim arrives with the same discovery reach into scripts, schedules, and control as a fraud claim, and it is far easier to plead.

Platform enforcement

Finally, the non-court risk. OnlyFans polices account access patterns, and an agency that triggers enforcement can lose the account that funds everything else. The litigation era gives the platform every incentive to enforce more visibly. Account-ban avoidance practices and legal risk reduction are now the same project: clean access, clean consent, clean logs.

How to Reduce Ghost-Chat Legal Risk in 2026

We treat the December order and the May follow-up as a free compliance audit written by a federal judge. Here is the playbook we run, in priority order.

  1. Get creator authorization in writing, specifically. Not "agency will manage the account." Write it plainly: the creator authorizes the agency and its personnel to access the account, and to compose and send messages to fans in the creator's name and persona. Add that the creator has reviewed and approved the messaging approach. This kills the creator-side impersonation and publicity theories before they start.

  2. Ban the specific lies, in a signed conduct policy. The dismissed complaints failed for lack of a documented false statement. Do not manufacture one. Our chatter rules prohibit: explicitly denying team involvement when a fan asks directly (deflect or route to the creator instead), promising in-person meetings, claiming to be typing live from a specific place, soliciting off-platform payment, and inventing life events to extract money. Every chatter signs the policy; violations are termination events. Bake this into day-to-day chat team management rather than a binder nobody opens.

  3. Lock down fan data like it is deposition evidence. The claim that survived 2026 is a data-exposure claim. Minimum bar: chatters work inside the platform or inside access-controlled tooling, no exporting chat logs or fan media, no personal devices for fan content, NDAs with real teeth, access revoked the day someone leaves, and a written register of who can touch which account. If we use inbox or CRM software, we know exactly what fan data it stores, where, and who can see it, because the in-transit interception question is fact-specific and unsettled.

  4. Keep records that prove the good story. Consent documents, conduct policies, training completion logs, and script libraries reviewed for the banned-statement list. In litigation, the agency that can produce its rules and training in 24 hours looks like a business; the one that cannot looks like the complaint's description of it.

  5. Structure for the lawsuit you might get anyway. Proper entity separation between agency operations, an indemnification clause running both directions with creators, and errors-and-omissions or media liability insurance quoted with chat operations disclosed. US agencies cannot copy the Fenix jurisdiction defense, so the fallback is making a suit survivable.

  6. Train for the direct question. "Am I actually talking to you?" is the highest-risk message in the inbox. Decide the answer with each creator in advance, script it honestly, and audit for compliance. Structured chatter training should drill this the way airlines drill engine failure: rare, decisive, career-ending if improvised badly.

None of this requires disclosing team involvement to every fan in every message, which no US court has required. It requires never affirmatively lying about it, and never leaking what fans share.

Where AI Chatting Rules Fit In

The chatter lawsuits are also the opening act for AI. Every deception theory aimed at a human ghost-chatter transfers, with more force, to a model generating intimacy at scale, and Eric Goldman's post on the ruling made exactly that point: as AI takes over conversational roles, litigation over undisclosed machine interaction will grow. The sanctions order in this very case, $13,000 against plaintiffs' counsel for AI-hallucinated briefs, is a reminder that courts in 2026 have zero patience for undisclosed AI anywhere in the pipeline.

The regulatory direction is one-way. California's bot disclosure statute already requires disclosure when automated accounts are used to incentivize purchases in covered contexts, and Utah's Artificial Intelligence Policy Act imposes disclosure duties on businesses using generative AI with consumers in certain settings. Platforms are moving the same direction on synthetic content and account authenticity. An agency deploying AI-assisted chat without a written policy on model use, human review, and disclosure posture is stacking a second, faster-moving risk on top of the ghost-chatting baseline. We covered the operating rules in our AI chatting compliance guide for OnlyFans agencies, and the short version is: AI drafting with human approval is defensible today; fully autonomous intimate conversation with no disclosure and no human in the loop is the fact pattern the next class action wants.

Our position at WhaleFinders is conservative on purpose. Human chatters, written creator consent, banned-statement conduct rules, and data discipline survive every theory currently in play. That standard costs a little margin and buys a lot of sleep.

FAQ

Is ghost-chatting illegal in the United States?

No statute prohibits a creator from authorizing other people to run her messages, and no court has held ghost-chatting unlawful. The legal risk comes from adjacent theories: fraud and state consumer-protection claims if chatters make specific false statements, privacy claims if fan data is exposed, and creator-side claims if consent was never documented. Legal by default, actionable when run sloppily.

What did the OnlyFans chatter class actions actually allege?

The lead case, N.Z. v. Fenix (C.D. Cal., filed July 2024), alleged that OnlyFans and a group of management agencies ran a scheme connecting fans to professional chatters impersonating creators, and pled RICO, wiretap, Video Privacy Protection Act, CIPA, fraud, contract, and California unfair-competition claims. A second, narrower class action by two Illinois subscribers followed in 2025. Neither complaint documented a confirmed chatter conversation; both inferred it from scale and inconsistencies.

What did the December 2025 ruling decide?

On December 12, 2025, Judge Fred W. Slaughter dismissed every claim, finding no personal jurisdiction over the Fenix entities, partial Section 230 immunity, no in-transit interception for the wiretap claims, and no justifiable reliance for fraud because OnlyFans' terms disclosed possible third-party involvement. The dismissal came with leave to amend, and plaintiffs' counsel was sanctioned about $13,000 for AI-fabricated material in briefs.

So did OnlyFans win for good?

Mostly, for now. After plaintiffs amended, Bloomberg Law reported on May 22, 2026 that Fenix International was dismissed again, while a Video Privacy Protection Act claim survived against the chatter agencies. The platform is out; the agency defendants are still litigating. Appeals and further amendments remain possible.

Can a fan sue an agency directly?

Yes, and that is now the live pattern: the surviving 2026 claim runs against agencies, not the platform. Agencies cannot use the defenses that saved Fenix (foreign jurisdiction, Section 230, the platform's own terms of service), so their protection has to be operational: no affirmative identity lies in chat, tight fan-data handling, and documented creator consent.

Does the creator's consent make ghost-chatting legal?

Consent solves the creator-side problem. State online-impersonation statutes such as California Penal Code 528.5 turn on impersonating someone without their consent, so written authorization removes that theory and most publicity claims. Consent does not, by itself, answer fan-side deception theories, which is why conduct rules on what chatters may never claim matter just as much.

Do AI chatters change the legal analysis?

They raise the stakes. Every deception theory against human ghost-chatters applies at least as strongly to undisclosed AI, disclosure statutes in states like California and Utah are already on the books, and commentators covering N.Z. v. Fenix expect AI-conversation litigation to grow. Run AI as a drafting layer with human review and a written policy, not as an autonomous undisclosed persona.

Put a full marketing department behind your agency

WhaleFinders runs the niche strategy, daily content direction, and platform playbooks for OnlyFans agencies, white-label under your brand.

Join the newsletter

Be the first to read our articles.

Our Recent Blog Posts

Our Recent Blog Posts

Keep reading

See All Posts

Payment Processor Adult Content Crackdown

The payment-processor pressure that pushed adult content off Kickstarter, Steam, and Itch.io is not a gaming story. It is an early-warning system for OnlyFans agencies whose funnels, billing, and creator payouts all sit downstream of Visa and Mastercard. This post reads the contagion as a canary and shows which surfaces to stress-test before the squeeze reaches your stack.

The payment-processor pressure that pushed adult content off Kickstarter, Steam, and Itch.io is not a gaming story. It is an early-warning system for OnlyFans agencies whose funnels, billing, and creator payouts all sit downstream of Visa and Mastercard. This post reads the contagion as a canary and shows which surfaces to stress-test before the squeeze reaches your stack.

W

Yasmin Khalil, Head of Compliance and Legal at WhaleFinders

Yasmin Khalil

Section 230 Sunset and OnlyFans Agencies

A House bill would end Section 230 immunity on December 31, 2026, and a bipartisan Senate bill would repeal it two years after enactment. This post reads both through the FOSTA-SESTA precedent so an OnlyFans agency owner can see how a repeal could hit the social funnels and adult platforms a roster depends on, and what to change now rather than after the fact.

A House bill would end Section 230 immunity on December 31, 2026, and a bipartisan Senate bill would repeal it two years after enactment. This post reads both through the FOSTA-SESTA precedent so an OnlyFans agency owner can see how a repeal could hit the social funnels and adult platforms a roster depends on, and what to change now rather than after the fact.

W

Yasmin Khalil, Head of Compliance and Legal at WhaleFinders

Yasmin Khalil

Bluesky Age Verification Hits Adult Funnels

Bluesky spent 2025 becoming the go-to less-restrictive traffic funnel for adult creators, and in 2026 that opening is closing state by state. This post explains the July 2026 Texas rollout, how Kids Web Services verification actually works, which states are now gated, and whether Bluesky still earns a slot in your funnel mix.

Bluesky spent 2025 becoming the go-to less-restrictive traffic funnel for adult creators, and in 2026 that opening is closing state by state. This post explains the July 2026 Texas rollout, how Kids Web Services verification actually works, which states are now gated, and whether Bluesky still earns a slot in your funnel mix.

W

Yasmin Khalil, Head of Compliance and Legal at WhaleFinders

Yasmin Khalil