The thriving industry of non-consensual, intimate deepfakes resides far closer to the conventional internet than the shadowy depths of the dark web. The authors of a groundbreaking new paper detailing this phenomenon identified 88 publicly accessible websites actively distributing AI-generated intimate imagery without the consent of the depicted individuals. Notably, 38 of these platforms were exclusively dedicated to this illicit content.
The research team meticulously aggregated data over a six-week period during February and March 2026. Initial sweeps utilizing targeted keywords and Google Alerts yielded approximately 400 distinct addresses. Following rigorous manual verification, investigators distilled this list to 88 actively operational resources. Subsequently, the authors systematically delineated the specific providers supplying hosting, Content Delivery Networks (CDNs), Domain Name System (DNS) resolution, cryptographic certificates, advertising networks, analytics, and tangential auxiliary services.
The Dominance of Cloudflare and Google
Astonishingly, Cloudflare emerged as the paramount infrastructure provider across four distinct technological categories. The ubiquitous service facilitated 64 out of 105 identified hosting connections, 68 of 122 CDN links, 67 of 87 DNS resolutions, and 56 of 144 analytics implementations. Because a single website frequently leverages multiple providers concurrently, the aggregate number of connections naturally exceeds the total count of investigated platforms.
Concurrently, Google demonstrated overwhelming dominance within the realms of SSL certificates and digital advertising. Investigators detected Google-issued certificates on 61 of the 88 websites. Furthermore, Google’s advertising infrastructure actively monetized 40 out of the 92 identified ad network connections. Namecheap consistently ranked as the preferred domain registrar, WordPress maintained absolute supremacy among Content Management Systems, and Proton Mail led the utilization of secure email services.
Concentrated Dependency Among Dedicated Platforms
For the 38 platforms singularly devoted to non-consensual imagery, the absolute dependency upon prominent tech conglomerates appeared even more pronounced. Cloudflare unequivocally sustained 33 of 43 determined hosting connections and 34 of 39 DNS resolutions. Google provisioned an overwhelming 31 out of 38 SSL certificates, while Proton Mail facilitated 6 of the 19 identified email infrastructures.
The Search Engine Paradox
A striking, paradoxical reality materialized regarding search engine discoverability. An astonishing 82 out of the 88 websites equating to 93.2% prominently surfaced within the first two pages of Google Search results when queried by their specific name or web address. Conversely, advanced conversational models including Gemini, ChatGPT, Claude, and Grok adamantly refused to generate hyperlinks directing users toward such explicit content. Historically, security researchers have also identified applications specifically engineered to generate similar imagery lurking within the official repositories of Google Play and the Apple App Store.
Corporate Responses and Legal Ramifications
The authors categorically refrain from asserting that Cloudflare, Google, Proton, or any other implicated corporation consciously endorses or deliberately facilitates the proliferation of these illicit materials. Instead, the research decisively illuminates the profound, inescapable technical dependency these illicit platforms maintain on ubiquitous, mass-market internet infrastructure.
In response to the findings, Google officially stated that absent specific domain names, the corporation remains utterly unable to verify the researchers’ conclusions regarding individual websites. The company reiterated its uncompromising prohibition against the monetization and algorithmic promotion of non-consensual intimate content. Cloudflare, Proton, and Namecheap conspicuously declined to respond to formal inquiries initiated by 404 Media. Meanwhile, WordPress vehemently contested the researchers’ characterization of its fundamental role as an infrastructure provider. Within the United States, federal authorities have already begun aggressively wielding the provisions of the TAKE IT DOWN Act against websites harboring malicious deepfakes.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.