Study Finds 88 Deepfake Abuse Sites Rely on Major Internet Providers
Researchers want providers to cut off verified abuse sites. Google says it needs specific domains to investigate, while WordPress disputes the study’s treatment of software as infrastructure.
Listen to this story
The audio brief
Story brief
3 key pointsPublished September 30 in Stanford’s Journal of Online Trust and Safety, “The Backbone of Abuse” maps services used by 88 active sites hosting non-consensual AI-generated intimate imagery, based on a six-week search. Cloudflare, Google, Namecheap, WordPress and Proton were prominent across hosting and delivery, certificates and ads, domain registration, publishing software, and email. The researchers urge providers to investigate reports and withdraw services, but the debate highlights an important distinction: some tools distribute software or serve site components without hosting or controlling a website. The authors do not allege that providers knowingly enabled abuse.
- 01
Researchers collected 400 URLs, but only 88 hosted targeted material; 312 were unrelated sites using abuse-related keywords to boost search visibility.
- 02
Google said it needs the specific domains to investigate; its policies prohibit non-consensual explicit imagery and allow it to block ads or suspend advertiser accounts.
- 03
WordPress.org says it distributes open-source software, while Hany Farid argues Automattic’s WordPress.com, Jetpack and CDN can host sites or serve their images.
A newly published peer-reviewed study identified 88 active sites hosting non-consensual AI-generated intimate imagery and traced the internet services they used. Cloudflare, Google, Namecheap, WordPress and Proton emerged as dominant providers in the sample. The researchers want those providers to stop supplying services to abuse sites—a recommendation that has prompted disagreement over the difference between operating a service and distributing software.
The paper, “The Backbone of Abuse,” was published September 30 in Stanford’s Journal of Online Trust and Safety. Its authors are Dartmouth computer scientist Hany Farid and Lancaster University researchers Sophie Nightingale and Sarah Morgan. As 404 Media reported, their focus was the services supporting distribution, rather than only the people creating or uploading the images.
From search results to infrastructure
Over six weeks between February and March, the team used keyword searches and Google Alerts to collect 400 URLs. They narrowed that collection to 88 sites actively hosting non-consensual intimate imagery, then used publicly available web-analysis tools, including WHOIS, to identify infrastructure providers. Most of the imagery depicted female celebrities, actresses, singers, K-pop idols, politicians or activists.
The initial search also exposed a complication: 312 sites were unrelated to deepfakes. They included gambling, travel and cooking sites using abuse-related keywords to try to rank higher in search results, according to 404 Media’s account of the study. The 400 URLs therefore were not a count of abuse sites.
The paper mapped several distinct roles across the 88-site sample:
- Cloudflare supplied the largest share of services, including hosting, content delivery networks, domain-name servers and analytics.
- Google supplied SSL certificates, used for secure website connections, and advertising space for most sites studied.
- Namecheap was the leading domain registrar—the service through which website names are registered.
- WordPress accounted for most content management systems, the software used to organize and publish website content.
- Proton supplied mail servers.
We aren’t saying that infrastructure providers are knowingly facilitating this content — or that they are aware of what’s on every site that uses their provisions — but it’s in providers’ power to vastly improve their moderation and cease services to sites as soon as they are identified as hosting this content. And to check sites that are reported to them.
Sarah Morgan, study researcher, speaking to 404 Media
Google asks for domains; WordPress challenges the premise
Google told 404 Media it could not investigate the findings without the specific domains. It said its policies prohibit non-consensual explicit content, including AI-generated imagery, and that violations can trigger blocked ads or suspended advertiser accounts. People can also request removal of such images from Search.
The company said it promotes non-explicit results where possible and lowers the search rankings of sites with high numbers of removals. Cloudflare, Proton and Namecheap did not respond to 404 Media’s requests for comment.
WordPress’s response drew a different boundary. A spokesperson said WordPress.org distributes open-source software but does not host websites or control content on independently hosted sites. Its software license permits anyone to use it for any purpose. Calling that a supplied infrastructure service, the spokesperson argued, conflates software with the services that operate a site.
Farid countered that WordPress.com, operated by Automattic, does provide hosting. He also pointed to Jetpack and the WordPress.com content delivery network: those services can serve images for sites hosted elsewhere. His argument was that an image can pass through Automattic infrastructure even when Automattic does not host the website itself.
Verification before a cutoff
The researchers’ recommendation goes beyond removing individual search results or advertisements. They want providers to investigate reported sites, improve moderation and withdraw services from sites hosting non-consensual imagery. Morgan described a proposed verification process involving providers, nongovernmental organizations and governments: confirm offending URLs, then share them with participating platforms so they can be blocked.
Sources
- 404media.coInternet Infrastructure Services Empower Deepfake Abuse, New Study Finds
Reader comments
Newest comments first. Replies stay oldest first.