Guest Blog – How Online Harassment Shaped the Internet: Why Coco’s Law and Ireland’s Internet Safety Model Matter

We’re pleased to welcome this guest blog from Maria Thomas, a cybercrime investigator, researcher and educator specialising in online harassment, child safety and open-source intelligence (OSINT). In this article, Maria explores how online harassment has evolved alongside digital technologies, the role emerging AI tools play in amplifying abuse, and why legislation such as Ireland’s Coco’s Law represents an important step in recognising that online harm is real harm.

 

Since the advent of the internet, humanity has been treated to a transformation in the way we communicate, learn, and build communities. Yet from the beginning, there has been a significant amount of misbehavior, which has evolved into an ever increasingly sophisticated ecosystem of abuse. Anonymous insults on message boards have shifted into coordinated harassment campaigns, doxxing, cyberstalking, and intimate image abuse. The recent introduction of AI to the general public has only exacerbated the problem, allowing anybody to create damaging images at scale with a low barrier of entry. Harassment is no longer the simple background radiation of being online – it has become something more potent, and in some cases, deadly.

We need to be aware of how and why this is occurring. Too long have we accepted dangerous and aggressive behavior online as an inevitability, something to be dealt with on an individual level. But this has exploded into something that cannot be defended against piecemeal, and intimate image abuse has become prevalent. Laws and regulations need to evolve alongside the threat, laws like Ireland’s Harassment, Harmful Communications and Related Offences Act 2020, also known as Coco’s Law.

The Evolution of Online Harassment

Online harassment has been around since the advent of the internet, originating with spamming Multi-User Dungeons (MUDs) and posting shock messages on Usenet to get a reaction out of users. As time went on and technology evolved, so did the types of abuse – impersonation, cyberstalking, doxxing, and image-based abuse, to name just a few. Campaign attacks against individuals or groups became more and more common as the years progressed. It became easy to organize coordinated attacks using message boards and social media.

Online harassment and offline abuse differ in several important ways. Digital abuse can be persistent, accessible indefinitely via screenshots, archived pages, and reposts. It is asymmetric – the abusers tend to know more about the victims than the other way around, and it is possible for hundreds or thousands of abusers to target a single victim simultaneously. Platforms are designed to maximize engagement, and are incentivized to amplify emotionally charged hostile content in order to drive use of their sites. The medium is primed for bad behavior.

The methods of harassment have also expanded dramatically. Recent technological advances have introduced new threats, such as AI “nudifiers” capable of generating nonconsensual sexually explicit images from ordinary photographs at scale. Prior to this technology, would-be harassers had to spend time and skill to create such harmful content. Now, the ability to inflict serious psychological harm is easy and available to anyone. In the eleven days between the end of December 2025 and January 2026, X’s Grok AI produced about three million sexualized images, 23,000 of them appearing to depict children. As of February 2026, a study conducted by UNICEF, ECPAT and INTERPOL found that, in a group covering eleven countries and over a million children, one in twenty-five of those children had been the victims of their images being digitally manipulated into sexually explicit deepfakes in the past year.

For many victims, the emotional impact is profound. Public humiliation, anxiety, depression, withdrawal from online participation, and fear for personal safety frequently accompany sustained digital abuse. As this becomes more common, society is coming to realize that online violence should not be viewed as somehow less “real” than offline violence. The consequences often extend well beyond the screen.

Why People Engage in Digital Harassment

The psychology of online harassment helps explain why otherwise ordinary individuals may participate in behavior they would never consider offline, specifically, the Social Identity Model of Deindividuation Effects (SIDE Model), and the Online Disinhibition Effect.

In 1895, French social psychologist Gustave Le Bon wrote the book “The Crowd: A Study of the Popular Mind,” exploring mob behavior. In this book, he identifies three primary forces that shape crowd behavior: anonymity, contagion, and suggestibility. Anonymity lowers the idea of personal responsibility, and allows people to act in ways they would not normally – disinhibition. Contagion is what occurs when emotions and actions spread from one person to another – when your neighbor in a group is angry, it is signaling to you to be angry as well. Finally, suggestibility is the crowd’s willingness to accept strong leaders and phrases – think of a charismatic politician with a slogan. The internet is a perfect breeding ground for this type of mob behavior.

In 1991, social psychologists Martin Lea and Russell Spears created the Social Identity Model of Deindividuation Effects (SIDE Model), which has since been expanded. This model explains how people interact with each other online, notably, that anonymous individuals tend to identify with the norms of their online communities, rather than their personal values. It clarifies that anonymous people are actually more likely to behave in normative ways based on their community, rather than randomly. In good communities, this leads to good behavior. In toxic communities, this leads to toxic behavior. Since many platforms are incentivized to reward hostile behavior, this creates an aggressive norm for anonymous individuals to learn from and lean on to justify their abuse, even if they would normally not consider engaging in such behavior in a non-anonymous context.

In 2004, Dr. John Suler, a psychology professor at Rider University, published his study on the Online Disinhibition Effect. This discusses how different traits of being online – anonymity, physical invisibility, delayed communication, and psychological distance – reduce social restraints. The people involved in the online communication are reduced to characters, and without immediate feedback from the other person’s emotional or physical responses, empathy becomes easier to suppress.

Finally, neurochemically, harassment is addictive. Dr. Molly Crockett, psychology professor at Princeton University, discusses research showing that when an individual is engaging in punishing behavior that they feel is morally justified, it releases dopamine, which is a neurotransmitter we are hard-wired to seek out. Dopamine is addictive – too much dopamine damages the neuron receptors and causes the individual to seek out more to make up for the deficit. Many people engage in harassment from a position of a “moral high ground,” whatever that may be for them. That, paired with the dopamine-rewarding engagements such as “Likes” and “Reblogs” makes online harassment uniquely tantalizing.

All of this together has turned online harassment into an epidemic of massive scale. The ease of which it is possible for us to harm each other, and our penchant to engage in such behavior has left swaths of victims in its wake.

Technology Is Accelerating the Problem

Artificial intelligence has accelerated many forms of online abuse, especially image-based abuse.

One of the fastest-growing threats involves AI-generated intimate imagery. So-called “nudifier” applications can create convincing fake nude images using photographs scraped from social media profiles. Victims don’t even have to take any intimate images for such abuse to occur.

Children and young adults are particularly vulnerable. Images can spread globally within minutes, while perpetrators may remain anonymous or operate from multiple jurisdictions. Recently, at least one school in the United Kingdom has been ransomed by threat actors taking images from the school’s website, nudifying the children, and then threatening to release the images if the school does not send them money. Individual child sextortion is also a quickly increasing problem. The rapid development of generative AI has created significant challenges for law enforcement, technology platforms, and legislators attempting to keep pace with emerging forms of exploitation.

These developments increasingly show that online harassment is not just a technological or a behavioral issue, but a mix of both. Figuring out the ways to combat it from both angles is key to creating ways to prevent such behavior in the first place.

Coco’s Law: Recognizing That Digital Harm Is Real Harm

In 2020, Ireland responded to this changing landscape with the Harassment, Harmful Communications and Related Offences Act 2020, widely known as Coco’s Law.

Named in memory of Nicole “Coco” Fox, who experienced prolonged online harassment before her death, the legislation represents one of Europe’s most comprehensive attempts to modernize criminal law for the digital age.

The Act introduced new criminal offences relating to the nonconsensual distribution, publication, or threatened publication of intimate images, including deepfakes. Importantly, it also recognizes that serious psychological harm may result even when there is no physical contact between offender and victim. The legislation came into force in 2021 and has significantly strengthened Ireland’s legal framework for addressing image-based abuse.

Perhaps the most important contribution of Coco’s Law is symbolic as well as legal. It sends a clear message that online abuse is not somehow less serious because it occurs through digital technologies. The emotional, professional, and psychological consequences experienced by victims are genuine and deserving of legal protection.

Looking Beyond Criminal Justice

Although legislation such as Coco’s Law is an essential milestone, criminal justice alone cannot solve online harassment.

Technology companies must continue improving platform design to reduce opportunities for coordinated abuse. Schools must provide digital citizenship education that emphasizes empathy, consent, and responsible online behavior. Parents need accessible resources that encourage open communication with children about online experiences. Researchers and investigators must continue studying emerging technologies, including generative AI, to understand how they reshape both victimization and offender behavior. Digital platform executives must take responsibility on how to make their spaces safe for their users.

Most importantly, society must recognize that online abuse is neither inevitable nor harmless. Every successful content removal, every intervention, every investigation, and every educational initiative reduces opportunities for repeat victimization. We must work together to make this wonderful tool, the internet, a better place.

 

About the Author

Maria Thomas is a cybercrime investigator, researcher, and educator specializing in online harassment, child safety, and open-source intelligence (OSINT). She has spent her career investigating cyber-enabled abuse and supporting organizations responding to digital threats. She regularly speaks at cybersecurity conferences and writes about emerging online threats and the people behind them. You can find her on LinkedIn and Substack.