Skip to content

Security1 publisher2 min readPublished

Researchers map 88 deepfake abuse sites to Cloudflare, Google, Namecheap, WordPress and Proton

Dartmouth and Lancaster researchers tie 88 non-consensual deepfake sites to five mainstream web providers led by Cloudflare, Google and Namecheap. The sites surfaced in keyword searches and every provider already bans illegal use, so the gap the study points to is enforcement.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Researchers map 88 deepfake abuse sites to Cloudflare, Google, Namecheap, WordPress and Proton
Generated illustration

What happened

  • The paper appeared Wednesday in Stanford's peer-reviewed Journal of Online Trust and Safety, written by Hany Farid of Dartmouth and Sophie Nightingale and Sarah Morgan of Lancaster University.
  • Over six weeks in February and March, the team collected 400 candidate URLs and narrowed them to 88 that were actively hosting non-consensual intimate imagery.
  • Cloudflare supplied the largest share of services to the sites, covering hosting, content delivery, domain-name servers and analytics.
  • Google provided SSL certificates and advertising space for the majority of the sites studied.
  • Namecheap was the dominant domain registrar, WordPress supplied most of the content management systems and Proton provided mail servers.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability Provider abuse teams can rebuild the study's site list with the same free lookup tools the researchers used, so finding the sites is a cheap step for any of the five.
  • constraint Google's position makes the domain list the gate. No review of its certificates or ad placements on these sites starts until researchers or victims hand over specific addresses.
  • contradiction WordPress's reply takes one name off the enforcement list. Open-source software has no customer account to suspend, so self-hosted sites answer only to whoever hosts them.
  • decision With the content criminal in the U.S. and banned by each provider's own terms, the choice left to the remaining providers is whether to cut service once they hold the domains.

The sites are easy to find. 404 Media, which has covered deepfakes since they appeared in 2017, reports that the material has circulated on social networks, through basic web searches, in downloadable apps and on open forums, not on dark web sites [16]. The researchers' method fits that record. They found candidates with keyword searches and Google Alerts, then used open-source tools such as WHOIS to see which companies served each site [2][3]. Of the URLs they collected, 22 percent were actively hosting the imagery [1]. Most of it depicted female celebrities, actresses, pop singers, K-pop idols and women working in politics or activism [14].

"Five players emerged as dominant infrastructure providers," the researchers wrote [4]. Each of those providers forbids customers from using its services for illegal activity [8]. Publishing or threatening to publish AI-generated non-consensual sexual imagery is a federal crime in the U.S. and elsewhere [9]. The study's claim is that the companies keep serving these sites anyway, after years of knowledge about them [15].

Cloudflare, Proton and Namecheap did not respond to 404 Media's requests for comment [10]. Google answered with a condition. "Without the specific domains from the report, we can't investigate these claims," a Google spokesperson told 404 Media [11]. The company said its ad platform treats non-consensual explicit content as an egregious violation, blocking ads on such sites or suspending the advertiser accounts involved [12]. 404 Media's account does not say whether the researchers sent their domain list to Google or to any other provider.

WordPress disputed its place on the list. A spokesperson said WordPress is "open-source software, not a hosting provider" [13], and wrote: "WordPress.org does not host websites or provide hosting services to sites that use WordPress, and we do not have access to or control over content published on independently hosted WordPress sites." [17]

What to watch

  • Whether the researchers hand the 88 domains to Google and the other providers, and whether any site then loses its certificate, DNS, registration or mail service.
  • Any statement from Cloudflare, Namecheap or Proton on whether their abuse teams will review the sites named in the paper.
  • Any U.S. prosecution of site operators under the federal law that makes publishing AI-generated non-consensual sexual imagery a crime.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories