The Keffals campaign against Kiwi Farms began in August 2022, sparked by months of escalating harassment that culminated in a swatting attack on trans Twitch streamer Clara Sorrenti in her London, Ontario apartment. After weeks of being hunted online and forced to flee her country, Sorrenti launched a public campaign to deplatform Kiwi Farms—a website that had become a hub for coordinated stalking, doxxing, and harassment. The campaign succeeded when Cloudflare, the major internet infrastructure provider protecting the site, announced its removal on September 3, 2022, citing “an unprecedented emergency and immediate threat to human life unlike we have previously seen from Kiwifarms.” This incident exposed critical vulnerabilities in how online harassment is handled by major technology platforms and infrastructure providers. It also demonstrated the power of public pressure campaigns to influence corporate policy decisions at the infrastructure level—a precedent with significant implications for content moderation, free speech, and platform governance in the internet age.
Table of Contents
- What Led to the Keffals Campaign—Six Months of Coordinated Harassment
- The Swatting Attack That Changed Everything
- The Strategic Decision to Go Public and Launch #DropKiwiFarms
- How Infrastructure Providers Became the Pressure Point
- The Limitations and Risks of Infrastructure-Level Deplatforming
- The Business and Policy Implications
- Lessons and the Broader Pattern of Coordinated Online Harassment
- Conclusion
What Led to the Keffals Campaign—Six Months of Coordinated Harassment
The campaign didn’t emerge from nowhere. Throughout the spring and summer of 2022, kiwi farms users had orchestrated a sustained harassment campaign against Sorrenti after she criticized another streamer who was subsequently banned from Twitch. Kiwi Farms operated discussion threads filled with sexually explicit material, leaked phone numbers, home addresses, and dead names—the deliberate misuse of a trans person’s former name. This 6-month campaign escalated from online abuse to real-world threats and attempts to locate her physical residence.
The persistence and coordination of this harassment created a continuous environment of fear that eventually forced Sorrenti’s hand. What distinguished this campaign from typical online bullying was its systematic approach to physical location tracking. Kiwi Farms users employed various methods to identify Sorrenti’s whereabouts, including analyzing photos she posted for background details and cross-referencing information across multiple platforms. This represented not merely trolling but a deliberate intelligence-gathering operation designed to enable real-world violence.

The Swatting Attack That Changed Everything
On August 5, 2022, kiwi Farms users capitalized on their location research. They sent an impersonation email to London, Ontario police falsely claiming that Sorrenti had made mass shooting threats against City Hall. Police responded with a heavily armed SWAT team that awakened Sorrenti in her apartment, conducted an arrest and search, and seized her possessions. This “swatting” attack—a dangerous practice of making false emergency calls to send armed responders to someone’s home—crossed a critical threshold from online harassment to facilitated physical danger. The swatting incident revealed a significant limitation in how law enforcement and internet service providers respond to coordinated harassment campaigns. Despite the clear origin of the threats, Kiwi Farms remained online and operational.
Police investigation takes time; platforms often claim they’re cooperating with authorities. Meanwhile, the target of the attack remains vulnerable. Sorrenti’s case illustrated that reactive enforcement after violence occurs is insufficient when dealing with websites explicitly designed to facilitate harassment at scale. After moving to a hotel for safety, Sorrenti discovered that Kiwi Farms users had located this refuge as well by analyzing Discord photos. They then used her hacked Uber Eats account to order pizzas to her location under her dead name—a form of public humiliation designed to expose her whereabouts and continued presence. This forced her to leave Canada entirely, becoming yet another person displaced by coordinated online harassment.
The Strategic Decision to Go Public and Launch #DropKiwiFarms
After weeks of being systematically hunted, Sorrenti made a calculated strategic decision: rather than wait for law enforcement or platforms to act, she would mobilize public pressure directly against the companies providing Kiwi Farms with essential internet services. In late August and early September 2022, Sorrenti launched the #DropKiwiFarms campaign, using social media to publicize the harassment she had endured and to pressure Cloudflare—the major content delivery network and DDoS protection service that made Kiwi Farms accessible—to revoke its services. This represented a significant tactic shift in internet activism.
Rather than asking platforms to remove harmful content, Sorrenti targeted the infrastructure layer—the companies that provide the technical backbone that keeps websites online. Cloudflare, as a CDN and DDoS protection service, was not the host of Kiwi Farms but provided critical protection against the distributed denial-of-service attacks that might otherwise take the site offline. By focusing pressure on this infrastructure provider, the campaign was essentially asking: “Who do you allow to use your services?”.

How Infrastructure Providers Became the Pressure Point
Cloudflare had historically positioned itself as a free-speech absolutist company, proudly serving all websites regardless of their content—including controversial sites and even services associated with extremism. This stance was tested repeatedly, but Cloudflare maintained that it didn’t moderate content; it merely provided neutral infrastructure. However, the combination of documented physical violence (the swatting), public documentation of the harassment campaign, and media coverage created a scenario that Cloudflare could not ignore. The decision to focus on Cloudflare rather than the website host itself proved strategically smart. Most website hosts are distributed and harder to pressure simultaneously.
Cloudflare, by contrast, is a single point of failure for many sites’ internet accessibility. Removing protection there would make the site vulnerable to constant DDoS attacks—an effective way to disable it without technically removing it from the internet. The tradeoff Sorrenti’s campaign forced was this: Is providing infrastructure protection to a website known for organized violence consistent with your corporate values? On September 3, 2022, Cloudflare CEO Matthew Prince announced the decision to stop providing services to Kiwi Farms. His statement acknowledged the severity: “We have decided to terminate our relationship with Kiwifarms as they have violated our terms of service. We don’t typically discuss the reasons we remove a site, but given the circumstances and the ongoing questions, we believe it’s important to be transparent that Kiwifarms has been the source of a series of ongoing and sustained harassment campaigns, and we firmly believe that the narrative set out in the open letter and the media coverage describing the current situation is accurate.”.
The Limitations and Risks of Infrastructure-Level Deplatforming
While the deplatforming appeared decisive, it revealed important limitations in how infrastructure removal actually works in practice. Kiwi Farms didn’t disappear; it relocated to DDoS-Guard, a Russian-based DDoS protection service. This move meant that the site remained online, accessible, and operational, though under more precarious conditions. Eventually, DDoS-Guard also removed Kiwi Farms from its service, but not before demonstrating a critical vulnerability: there are always other infrastructure providers willing to serve controversial sites. The Russian-based hosting illustrates a key limitation of pressure campaigns targeting infrastructure: they can displace harmful content to less-regulated jurisdictions but may not eliminate it entirely.
Kiwi Farms has continued operating through various domain registrars and hosting arrangements, suggesting that determined communities can find ways to maintain online presence even after major infrastructure providers withdraw support. Additionally, the reliance on public pressure and corporate goodwill for content moderation means that decisions are inconsistent and dependent on media attention—a site might operate freely for years until a high-profile incident triggers outrage. Another consideration is the precedent this set. If infrastructure providers could be pressured to remove sites based on their content and user behavior, what would prevent this power from being used in other contexts? The decision to deplatform Kiwi Farms may have seemed justified given the documented violence, but the mechanism—coordinated public pressure on infrastructure providers—could theoretically be applied to other sites for various reasons. This raised questions about content moderation at the infrastructure layer versus the platform layer.

The Business and Policy Implications
The Keffals campaign had immediate ripple effects across the technology industry. Other platforms and infrastructure providers faced scrutiny regarding which sites they would host and serve. The incident became a case study in how public campaigns could influence corporate policy at the infrastructure level—a domain that had previously seemed removed from traditional content moderation debates.
For investors and business analysts, the Keffals case highlighted the risks that infrastructure providers face when their services are used to facilitate harassment or violence. Cloudflare’s decision was framed in terms of corporate values and safety, but it also reflected a business calculation: the reputational and potential legal liability of supporting a site involved in documented violence exceeded the value of appearing neutral and accessible to all. This represented a meaningful shift in how infrastructure companies viewed their responsibility, with significant implications for how they manage risk and corporate policy going forward.
Lessons and the Broader Pattern of Coordinated Online Harassment
The Keffals campaign demonstrated both the power and limitations of public pressure campaigns in addressing online harassment. It succeeded in removing one website from mainstream internet infrastructure, but it did so through a mechanism—corporate pressure rather than legal enforcement—that raises complex questions about accountability, consistency, and the role of private companies in regulating online speech.
Since the Kiwi Farms deplatforming, similar campaigns have targeted other websites and platforms accused of facilitating harassment. The Keffals case established a playbook: document the harassment, publicize the perpetrators and platforms, pressure infrastructure providers, and leverage media coverage to create reputational risk. Whether this approach represents an effective solution to the problem of coordinated online harassment or an unsustainable reliance on corporate goodwill remains an open question for policymakers, technologists, and investors to consider.
Conclusion
The Keffals campaign against Kiwi Farms originated from months of relentless, coordinated harassment that escalated to real-world violence through a swatting attack. Rather than waiting for traditional enforcement mechanisms to intervene, Sorrenti strategically targeted the infrastructure providers enabling the harassment, successfully pressuring Cloudflare to deplatform the site. The campaign succeeded in removing Kiwi Farms from mainstream internet services, though the site found refuge with less-regulated providers, illustrating both the power and limitations of infrastructure-focused pressure campaigns.
For the investing and business communities, the Keffals case represents a significant moment in how corporations manage content moderation responsibility at the infrastructure layer. It demonstrates that platforms and infrastructure providers face meaningful reputational and legal risks when their services facilitate documented violence and harassment. However, it also raises important questions about consistency, precedent, and whether reliance on corporate pressure rather than regulatory or legal frameworks is a sustainable approach to addressing online harassment in the long term.