Just the Facts · Article
Three real demand letters, eighteen years apart
Every other page here is argument. This one is evidence: three actual demand letters received by real businesses, two of them downloadable in full. Different decades, different laws — and in all three the owner had no idea the exposure existed.
These are real letters, received by real businesses we worked with. Client names, domains, page addresses, case numbers and captured identifiers have been removed from the documents — deleted, not covered over. Everything else is exactly as it arrived.
2008 — a construction company, and six photographs
The first arrived by fax. A regional construction firm had a website built for them; the developer used stock photographs; nobody kept a record of where they came from. Getty Images' compliance operation identified the images and sent a legal demand — to the business, not to the developer, because the business owns the site.
It settled for $4,500, paid by the company's attorney. The web developer contributed $1,500 of it, in roughly $100 monthly instalments that ran until 2010, plus free hosting through the middle of that year. The final payment cleared more than two years after the letter arrived.
We cannot publish this one. The Getty document came as paper and fax, and no digital copy survives anywhere — not in the email archive, not on any drive, not in a 13.9 GB Outlook archive we searched specifically for it. That absence is worth noting on its own: the letter that cost the most is the one there is no file of.
2016 — six images, $3,575, and nobody knew where they came from
Eight years later, the same pattern with a better paper trail. A business services firm received a first notice in March 2016 — a polite "Image License Validation" identifying six rights-managed photographs on six different pages of the site, each shown as a thumbnail next to a screen capture of the page it was found on. Twelve business days to respond.
The formal demand followed three weeks later: $3,575.00 for the six images, with fourteen business days to pay or produce licences. The letter noted that Getty had incurred an additional $400 per image in pursuit costs and was waiving them, since the use "may have been unintentional." It also made two points people consistently get wrong — that taking the images down does not resolve the claim, and that infringement occurs regardless of knowledge or intent.
This matter was resolved by identifying the correct owner and redirecting the claim to them. The full letter is downloadable below.
2026 — one analytics request
The most recent letter has nothing to do with photographs. It is a CIPA "pen register" demand under California Penal Code § 638.51, sent by a serial filer representing himself, and it arrives with a complete draft complaint already written, described as "prepared and ready to be filed" in Los Angeles Superior Court.
Strip away the boilerplate about browser mechanics and the entire case is one paragraph: on page load, before the visitor clicked, accepted, rejected, dismissed or scrolled past anything, the site sent a request to Google Analytics carrying the measurement ID, a client ID, a session ID and browser details. No hack. No breach. Standard analytics, running before consent.
There is a detail in that evidence paragraph worth reading closely. The complaint describes a California consumer who accessed and interacted with the website. The browser details he pasted in report HeadlessChrome at a 980×700 viewport — an automated scanner, not a person. He documented his own bot in his own complaint. You can read it yourself — the whole letter is below.
The remedy he demands is also instructive. Read the prayer for relief and it asks the business to disable third-party trackers until consent is obtained, re-architect the site so nothing fires on page load before interaction, and implement true opt-in consent. That is a block-first consent model — precisely the fix we would recommend anyway. Implementing it both ends the ongoing exposure and demonstrates good faith.
What the three have in common
- Eighteen years apart, under three different legal theories — and in every case the owner did not know the exposure existed until a letter arrived.
- None of them involved a hack, a breach, or anything anyone would describe as wrongdoing. Photographs someone else chose; analytics installed by default.
- In all three, the underlying defect was visible from outside the website. Anyone could see it, including an automated crawler — which is exactly how each was found.
- In all three, the fix would have cost a fraction of the resolution. Licensing six photographs is not $3,575. Gating analytics behind consent is an afternoon.
That is the whole argument for scanning your own site: every one of these letters started with a defect a crawler could see and prove. Remove the defect and there is nothing to find — no matter who is sending letters that month.
A note on the sender of the 2026 letter
In July 2026 that filer was declared a vexatious litigant in the Central District of California after 29 lawsuits in under five years, including seven nearly identical complaints in seven months. Read the companion article on that ruling before drawing comfort from it — the order is narrow, it binds one filer in one district, and it sanctioned his conduct rather than the legal theory. The template is still circulating.
Published as educational exhibits, not legal advice, and Technology On Call is not a law firm. If you have received a demand letter, talk to a qualified attorney. Client-identifying details have been removed from both documents.
Download the exhibits
The real document as it arrived: the cover letter and the full draft complaint, including the evidence paragraph where the filer pastes in browser details reporting HeadlessChrome. The company name, its domain and tagline, the captured Google Analytics identifiers, and the sender's contact details and signature have been removed from the file itself — the pages were rasterised and the content painted out, so there is no text layer underneath and nothing to lift off. The mailing envelope was dropped entirely. A redaction note is included as the final page.
A faithful transcription, not a scan. This one arrived as an email in 2016 and no document version exists; its evidence thumbnails were served from an image-tracking domain and are long gone. Every word, figure and deadline is reproduced from the original notice, with the client's name, domain, page addresses, case number and access code removed.
Sources
- Getty Images, Unauthorized Use Notification (29 March 2016) — original in our files, published redacted above
- CIPA § 638.51 pen-register demand letter (2026) — original in our files, published redacted above
- Cal. Penal Code § 638.51
- Shah v. Crain Communications, Inc., No. 2:26-cv-03070-RGK-CTS (C.D. Cal., 20 July 2026)
More from Just the Facts
- Is Any of This Actually Real?
- How Real Is the Threat? A By-the-Numbers Risk Assessment
- Who's Really Suing — CIPA Website-Wiretap Filers
- When the Court Reins One In: the Vivek Shah Vexatious-Litigant Ruling
- The Demand-Letter Economy
- Verifying Licensed Images, Fonts & Video
- Copied Content: Plagiarism, Copyright & the Hidden SEO Risk
- Passwords, Backups & VPNs: the security that decides whether a breach sinks you
- Website accessibility is the most-sued thing on the internet
- Your cookie banner probably isn't doing anything
- The instructions your website isn't giving the browser
- The privacy signal your site is ignoring
- Code you didn't write, running on your site tonight
- Three documents nearly every site gets wrong
- What an accessibility statement is actually for
- Cookies without locks
- Anyone can send email as you