
Ofcom has today fined an online porn provider £700,000 for not having age checks in place, and a further £30,000 for failing to respond to a legally binding information request.
The UK’s independent online safety watchdog has also today confirmed it has secured better protections from an online file-sharing service to tackle child sexual abuse material.
Porn site fined introduces age checks and blocks UK
Robust age checks are a cornerstone of the UK’s Online Safety Act. Sites that host pornographic material must use highly effective age assurance to determine whether a particular user is over 18, in order to prevent children from accessing that content.
Between July 2025 and November 2025, the provider of Xgroovy[dot]com failed to comply with these duties. As a result, Ofcom has imposed a financial penalty of £700,000.[1]
The provider has since introduced a form of age assurance capable of being highly effective, then subsequently ‘geoblocked’ access from UK IP addresses, meaning it is no longer directly available to people in the UK. We will continue to monitor the site for compliance.
Ignoring legally binding information requests
Gathering accurate information from companies is fundamental to our job of making life safer online for people in the UK. These requests help us assess and monitor industry compliance with their safety duties, and firms are required, by law, to respond in an accurate, complete and timely way.
During the course of our investigation, the provider of Xgroovy[dot]com failed to respond to a formal request for information. As a result, we have fined it an additional £30,000.
We will also impose a daily penalty of £200 per day until the information is provided, or 3 November 2026, whichever is sooner.
George Lusty, Director of Enforcement at Ofcom, said: “The message to adult websites is clear: put effective age checks in place to keep children from accessing porn. If companies fail to do this, or ignore legally binding requests from us, they should expect to face fines.”
File-sharing site strengthens CSAM defences following Ofcom action
Last year, Ofcom launched an enforcement programme to assess the safety measures being taken by file-sharing services, which are frequently exploited by offenders to distribute child sexual abuse material (CSAM) at scale. The spread of this material causes devastating harm to victims and remains one of the gravest online safety challenges.
As a direct result of Ofcom’s action under this programme, several services have either deployed hash-matching technology to mitigate the risk of CSAM being shared or taken steps to prevent people in the UK from accessing their sites.
Today, Ofcom has confirmed that – in response to compliance remediation action by our enforcement team – the provider of another file-sharing site has revised its risk assessment and taken steps to introduce perceptual hash matching.[2]
Notes to editors:
- Fines are passed on to HM Treasury. If a company fails to pay a fine, we will pursue recovery of that debt wherever possible, regardless of where the firm is based.
- Compliance remediation is a process in which providers are given an opportunity to make specific improvements with our enforcement team or face formal action. See page 11 of Ofcom’s Online Safety Enforcement Guidance.
- We have also today issued provisional decisions that Cyberitic, LLC and ZD Media have failed to comply with age-check duties under the Online Safety Act. Both providers now have an opportunity to make representations to us before we make our final decisions.
Related content