How Many CyberTipline Reports Actually Become Criminal Cases??
CyberTipline reports are not equivalent to criminal indictments or convictions. The figures cited in the “CyberTipline totals” tables are counts of reports, not counts of confirmed crimes. Law enforcement agencies use NCMEC’s tools to identify and prioritize suspected crimes and suspected offenders. They do not use these tools to issue indictments or seek convictions. The existence of an incident on CyberTipline does not prove that an individual or company committed a crime.
NCMEC does not publish a “CyberTipline-to-prosecution conversion rate.” There is no third-party source that publishes reliable data on this issue. This makes it difficult to estimate the number of reports that lead to federal criminal charges.
Again, CyberTipline totals measure reports. They do not measure proven crimes or prosecutions. While reports can be converted into proven crimes or prosecutions, several steps are involved in this process.
As of the date of this article’s writing, there is no public dataset available that tracks CyberTipline reports from intake through prosecution. If such data exist, it are not available to the public or the press.
As of January 2025, Electronic Service Providers (ESPs) have submitted 61.8 million files through CyberTipline reports. The vast majority of these files were sent using reporting tools developed by NCMEC. In 2025, more than 2 million reports (and more than 10.8 million files) resolved to a U.S. IP address. At least one report resolved to an IP address in each of the 50 states. As of NCMEC’s 2025 reporting, more than 2,000 ESPs were registered with NCMEC to report known cases of child sexual abuse material (CSAM). While these statistics may appear large, their numbers do not correlate one-to-one with the numbers of successful federal prosecutions involving CSAM.
Why is there no reliable national prosecution rate?
After referral to the Internet Crimes Against Children (ICAC) Task Force Program, NCMEC does not have visibility into law enforcement action. While NCMEC works with the Federal Bureau of Investigation (FBI) and the U.S. Department of Homeland Security (DHS) to assist law enforcement, NCMEC does not report on arrests, search warrants, indictments, or guilty pleas.
As a result, NCMEC publishes no data on:
- Time elapsed from report intake to arrest or indictment.
- Rate of indictment resulting from referred reports.
- Rate of conviction resulting from referred reports.
- Percentages related to other aspects of investigative and judicial processing.
Although NCMEC publishes annual statistics on how reports are categorized, these statistics apply to the number of reports CyberTipline intakes, not to the number of investigations that reach federal court. Similarly, while NCMEC publishes a breakdown of reports by platform, this data does not apply to investigative outcomes. While NCMEC publishes totals for routed reports to foreign law enforcement, NCMEC does not publish feedback rates for those reports.
There are many other factors that make it difficult to correlate CyberTipline reports to federal criminal prosecutions. For example:
- CyberTipline referrals that are sent to local law enforcement agencies do not always lead to federal investigations. Some of these reports lead to state criminal prosecutions and others lead to no charges.
- Annual CyberTipline totals may not be directly comparable from year to year. The vast difference between the volume of reporting in 2025 versus the volume of reporting in prior years is partially attributable to significant changes in platform reporting tools and methods.
- CyberTipline totals measure files, but not necessarily unique targets of investigation. A single investigation can lead to many referrals involving thousands of files, meaning a single suspect can be responsible for thousands of reports.
- CyberTipline totals measure intake, meaning that they do not reflect the numbers of targets that were charged with crimes or that entered the federal justice system.
If you are facing scrutiny due to a report submitted to NCMEC, this is not proof that you will face federal criminal charges. This lack of clear reporting also means that we do not know what your specific chances for a successful defense are in light of your circumstances.
What happens to a CyberTipline report after NCMEC receives it?
When NCMEC receives a CyberTipline report, its first and foremost priority is to make sure the child mentioned in the report is safe. To that end, the first step in NCMEC’s processing of the report is to screen it for markers that a child is facing serious physical or other danger in the moment. When the child’s situation is deemed high-risk, the child is flagged for expedited intervention, and this triggers an immediate referral from NCMEC to the appropriate law enforcement agency.
While NCMEC collects data and shares information with police agencies, it does not lead investigations. NCMEC makes all CyberTipline reports available for independent review by police. In the United States, reports are sent to the ICAC Task Force Program, which takes lead responsibility for directing the next step of the process. ICAC task forces use the reports in their possession to make their own determinations. They may investigate a report, close a report, or reassign it to a jurisdiction or authority that is better positioned to take action.
It is essential to understand that law enforcement officers must independently decide whether a report is actionable. To a layman, the phrase “actionable,” meaning “worthy of action,” might be ambiguous. However, in law enforcement, the term “actionable” means that it is legally justified to take police action, such as executing a search warrant or making an arrest. As a result, an NCMEC referral is not the same as an arrest warrant, indictment, or conviction. To warrant any of these legal consequences, federal law enforcement must satisfy requirements that are wholly and uniquely independent of NCMEC’s referral process.
Based on NCMEC’s 2025 data, the following proportions result from the reported intake of 21.3 million reports:
- At least 18.8 million reports result in reports being made available to law enforcement agencies. This accounts for roughly 88% of the intake, and it includes reports that are routed to law enforcement agencies around the world.
- At least 4.5 million reports result in being identified as informational, which results in about 21% of the intake.
- Approximately 16.4 million reports involved uploads by users located outside of the United States. This accounts for 77% of the intake.
When analyzing these statistics, several key points emerge. First, it is important to note that “informational” is not necessarily synonymous with “closure decision.” Instead, this means that NCMEC did not route the report to law enforcement. Second, law enforcement’s decision to investigate is based on various factors, including whether the investigation is within the agency’s jurisdiction. While only about 9% of these reports are U.S.-based, 77% involve uploads by users located outside of the United States. This is a recurring theme with platforms such as Instagram, Meta, Google, and X (formerly Twitter), and it indicates that a large percentage of these reports will not result in federal criminal prosecutions in the United States solely due to jurisdictional barriers.
This is the point at which most people call a lawyer. Spodek Law Group takes federal criminal defense cases nationwide from its New York and Los Angeles offices.
Why do report totals greatly overstate distinct criminal cases?
There are numerous reasons why the totals reported on CyberTipline reports do not equal the number of distinct criminal cases. Some examples include:
- A single criminal case can arise from many separate CyberTipline reports.
- a single CyberTipline report can contain many files, accounts, and incidents.
- A single report may describe multiple alleged crimes involving both an individual victim and multiple other victims.
- Duplicate and repeated reports can inflate report totals well beyond the number of distinct offenders.
Because of these factors, NCMEC reports count the number of reports rather than reporting the number of individuals at issue. As a result, NCMEC reports will not accurately reflect either the number of distinct criminal cases or the number of distinct suspects or victims involved in any of those cases.
Based on NCMEC’s 2025 reports:
- More than 75% of all reported activity came from five Electronic Service Providers (ESPs), with Meta alone making up approximately half of all reported activity.
- While Meta generated approximately 13.8 million reports in 2024, it generated nearly 11 million reports in 2025. The difference is partly due to the way that Meta bundles reports. Meta bundles multiple accounts together in a single report when those accounts were created using the same IP address. As a result, this method bundling decreased reports that were listed as informational.
- The total of more than 2 million reports that resolved to the United States has been broken down by platform and category in various tables below. It appears that the reports are spread across a wide variety of platforms and categories, and this is to be expected given that reports can come from numerous sources.
In addition, this includes “viral child sexual abuse material,” meaning that a video or image of a child was captured, uploaded to the Internet, and then downloaded and uploaded by thousands of other people. In this scenario, reports are triggered by the download of and upload of a single piece of CSAM, and those reports are made as years after a single video or photo of child abuse was taken. This includes re-posted, shared, and uploaded material.
Finally, changes in reporting obligations have pushed platforms to report more frequently. Furthermore, platforms have improved their capabilities to detect and report known CSAM and CSAM in transit, resulting in reports that are both more numerous and more automatic. The combined result is reporting that far more than is warranted given the reported figures’ ability to relate back to criminal investigations and prosecutions.
Which reports are most likely to survive law enforcement triage?
While an NCMEC referral is not equal to any stage of a criminal case, the referral designation is still important. NCMEC only makes a referral when it deems that there is “enough information to investigate.” If this is correct, the report is actionable. Law enforcement is still required to make its own independent determination, but a well-supported report is more likely to be taken to the next stage.
To be a well-supported report, there must be sufficient jurisdictional information. When reports are routed through the ICAC Task Force Program, law enforcement must use the information contained in reports to make their own independent determinations. Based on NCMEC’s 2025 reporting, this means:
- More than 10% of industry-generated reports lacked any jurisdictional information.
- More than 30% of social media reports lacked information on uploaders’ identities.
- More than 30% of social media reports lacked information on IP addresses for uploads.
- More than 40% of image-based reports lacked information on uploaders’ identities.
- More than 70% of image-based reports lacked information on IP addresses for uploads.
- Nearly 75% of image-based reports from social media sources lacked either an uploader’s identity or the IP address of the upload.
- More than 80% of reports for CSAM in transit were either missing an uploader’s identity or the IP address of the upload.
A high report volume doesn’t necessarily mean more investigations. As several interviews with law enforcement personnel indicate, many law enforcement officers feel that “the reports keep coming, and we simply don’t have the personnel to keep up.” This lack of personnel, according to these personnel, is partly due to “the bad quality” of many reports, often resulting from the automated nature of these reports. In this context, “bad quality” does not refer to the reports’ ability to relate back to a specific person, device, or account. Instead, it refers to their inability to provide law enforcement officers with actionable information.
As a result, many files identified on CyberTipline are not useful for law enforcement investigations. In some cases, NCMEC staff are unable to do anything to improve report quality because they “simply cannot control what the providers decide to include in the reports.” In some cases, improving reporting quality may require changes to the reporting form or reporting process. For example, according to one interview, “the CyberTipline form has no structured field for chat transcripts.” As a result, if a provider attaches a chat transcript to a report, “some of the time investigators may not even realize it’s there,” and “it may just be one of dozens of files in a ZIP folder attached to a report.” As a result, a reported chat transcript may remain unread by investigators until the investigator obtains a warrant to review the suspect’s account on the platform.
While there are many challenges in converting CyberTipline reports into prosecutions, this does not mean that a report which contains sufficient information is sure to be taken to federal court. An investigation can be legally sufficient but still simply too low-priority, and this means there will be nothing for federal criminal law enforcement to do.
Can police open CyberTipline files without first getting a warrant?
The Fourth Amendment restricts government agents, not independently acting private companies. As a result, providers that operate reporting portals to identify and report CSAM (or that report CSAM in transit) do not trigger the Fourth Amendment. However, once a report reaches law enforcement, the Fourth Amendment applies to the agents handling the reports.
The question that remains open is whether the Fourth Amendment imposes requirements on NCMEC. As recently as November 2023, the U.S. District Court for the District of Maryland treated NCMEC as a government actor in the Fourth Amendment context in United States v. Ackerman. 501 Fed. Appx. 704. A court’s determination as to whether NCMEC is a government actor is important. If NCMEC is considered a government actor, this limits what it can do and increases the likelihood that information processed on CyberTipline can be excluded if the process violates the Fourth Amendment.
For now, one clear issue remains. As clarified in United States v. Holmes, 2019 WL 5604657, there is currently a split among federal district courts and appellate courts about when police need a warrant to open a file from CyberTipline that has not been reviewed by the private company that uploaded it. The FBI’s access to several files attached to a CyberTipline report was suppressed because the FBI did not obtain a warrant. These files had been uploaded to Facebook, and Facebook did not review them before adding them to the report.
Some courts believe that the Fourth Amendment protects users even against reports sent by a private company to law enforcement, unless a warrant is obtained. Other courts have taken the view that “the private search doctrine” protects federal law enforcement when viewing an unreviewed attachment as long as the attachment’s content hash-matches known CSAM files. The Supreme Court has not yet resolved this split, and as a result, the warrant requirements for accessing reports from the CyberTipline depend on where the investigation is happening and what the reporter reported.
Regardless of when it becomes admissible, federal law enforcement will never be able to access a suspect’s device through a warrantless device search generated from a CyberTipline report. To do so, law enforcement must obtain a warrant based on probable cause.
While this is one aspect of obtaining a warrant, there are many other important aspects that can make a federal law enforcement agent’s search and seizure actionable. For example, while agents may not be able to search a user’s device without a warrant, that does not mean the Fourth Amendment prevents agents from executing warrants based on other evidence.
Ultimately, files that are attached to a CyberTipline report can become evidence in federal criminal cases if they were obtained lawfully. For this reason, it is imperative that individuals and companies have clear, present, and effective defense strategies in the event of a CyberTipline-triggered investigation. At Spodek Law Group, we have experience defending clients in these cases, and we can help you build a defense strategy that uses all of the applicable legal protections to its maximum effect.
Contact a Federal Criminal Defense Attorney
Nothing here is legal advice, and the details of your case matter. Todd Spodek and Spodek Law Group take federal criminal and white collar cases nationwide, from offices in New York, Brooklyn, Queens and Los Angeles. You can reach the firm at 212-300-5196.
Reading is good. Calling is better.
Answered within 24 hours, guaranteed. Some stories are better told out loud -
212 300 5196