Internet Infrastructure Services Empower Deepfake Abuse, New Study Finds


Internet Infrastructure Services Empower Deepfake Abuse, New Study Finds

Abusive, sexually explicit deepfakes have only become easier to make and more widespread in the last nine years. Since we first covered deepfakes when they appeared in 2017, they’ve never been the stuff of dark web sites or shadowy networks. They’re found on social media networks, through basic web searches, and on easily downloadable apps and accessible forums. 

The most prominent hosts of non-consensual, AI-generated imagery are supported by some of the biggest web infrastructure providers in the world, getting their hosting, email, advertising, and content management systems from these companies. A new study examines how providers like Cloudflare, Google, Proton, Namecheap, and WordPress help non-consensual imagery sites thrive. Despite years of knowledge about these wildly popular sites, big tech companies continue providing infrastructure services that prop up abuse imagery, even though their own terms of service often prohibit illegal and harmful content, the study claims. 

Hany Farid, professor in Computer Science at Dartmouth College, Sophie Nightingale, a senior lecturer in psychology at Lancaster University, and Lancaster’s Sarah Morgan, who acts as the project coordinator on Nightingale’s “Protecting Ordinary People from Deepfake Harms” fellowship published their paper, “The Backbone of Abuse: How Infrastructure Providers Enable the Proliferation of AI-Generated Non-Consensual Intimate Imagery” in Stanford’s peer-reviewed Journal of Online Trust and Safety on Wednesday. 

In a six-week period between February and March, they identified 400 URLs based on keyword searching and Google Alerts, then narrowed the sites down to 88 that were actively hosting non-consensual intimate imagery. Most of the content on these sites was of female celebrities, actresses, pop singers, K-pop idols, and women working in politics or activism. From there, they used open-source web-analysis tools like WHOIS to see what infrastructure providers the sites used.   

“Five players emerged as dominant infrastructure providers: Cloudflare, Google, Namecheap, WordPress, and Protonmail,” the researchers wrote in their paper. Cloudflare provided “the lion’s share of services,” they wrote, by providing website hosting, content delivery network, and domain-name server services, as well as analytic tools. Google provided SSL certificates and advertising space for the majority of the sites studied, while Namecheap was the dominant provider of domain registrar services, WordPress provided the majority of their content management system services, and Proton provided mail servers.

Each of these service providers forbid customers and users from using their services for illegal activity. Publishing or threatening to publish AI-generated non-consensual sexual imagery is a federal crime in the U.S. and elsewhere, and sexual abuse imagery in general is illegal in many countries. 

Cloudflare, Proton, and Namecheap did not respond to 404 Media’s requests for comment about these findings. 

A spokesperson for Google told 404 Media in a statement: “Without the specific domains from the report, we can’t investigate these claims. We have strict policies against non-consensual explicit content — including AI-generated imagery — across all our products. We make it easy for people to quickly remove this content on Search, continuously update our systems to limit its visibility, and we prohibit monetizing or promoting non-consensual and sexually explicit content.”

The Google spokesperson added that its advertising platform prohibits monetizing or promoting non-consensual and sexually explicit content, and treats this content as egregious violations, blocking ads on the sites or suspending the advertiser accounts involved. They also noted people can request the removal of non-consensual explicit images from Search, and pointed to Google’s recently-updated removal request process. Google has also updated its ranking algorithms by promoting non-explicit content where possible, they said, and demotes sites in search results that have a high number of removals against them.

A WordPress spokesperson said WordPress is “open-source software, not a hosting provider,” and wrote in a statement: “WordPress.org does not host websites or provide hosting services to sites that use WordPress, and we do not have access to or control over content published on independently hosted WordPress sites.” They noted that WordPress’s software is distributed under the general public use license, allowing anyone to use it for any purpose. “We take the issue of non-consensual intimate imagery seriously, but describing WordPress as providing services or infrastructure to these sites conflates the software a site uses with the services that host and operate it,” the spokesperson said.

In response to WordPress’s statement, Farid noted that while WordPress.org is not a host, WordPress.com is a hosting service. “It’s operated by Automattic, which Matt Mullenweg also runs, and it hosts millions of sites. Any NCII site on WordPress.com is squarely within scope,” he told 404 Media. “Automattic provides services to self-hosted sites. Jetpack and the WordPress.com CDN serve images from i0.wp.com/i1.wp.com for sites that enable it, meaning the intimate images themselves can be served from Automattic infrastructure even when the site is hosted elsewhere. That’s infrastructure by any definition.”

Farid also noted that WordPress.org maintains “an ongoing service relationship with self-hosted sites,” he said, with core updates, plugin and theme distribution, and security patches coming from WordPress.org servers. Farid mentioned Automattic’s ongoing legal battle with WP Engine, during which, in 2024, Mullenweg announced WP Engine was blocked and then unblocked from accessing WordPress servers; this “showed the project can and will cut a specific operator off from those services,” he said.

“So ‘no access to or control over’ is not entirely accurate,” Farid said. 

‘The Most Dejected I’ve Ever Felt:’ Harassers Made Nude AI Images of Her, Then Started an OnlyFans

Kylie Brewer isn’t unaccustomed to harassment online. But when people started using Grok-generated nudes of her on an OnlyFans account, it reached another level.

These providers do draw their own moral and legal lines on what kinds of customers they’ll tolerate and when they cooperate with authorities. After initially refusing to do so, Cloudflare dropped hate speech and doxing site Kiwifarms from its protection services in 2022, and terrorist manifesto host 8chan in 2019. In 2018, Cloudflare banned sex work harm reduction social network Switter from using its services, citing anti-trafficking legislation FOSTA/SESTA, and in 2017, it Cloudflare stopped services to neo-Nazi site The Daily Stormer. In 2023, victims of the sex trafficking ring Girls Do Porn demanded Cloudflare stop providing services to sites hosting their abuse; Cloudflare claimed it doesn’t have “control over the content of websites using those services,” doesn’t have “the ability to alter or remove content on them,” and doesn’t “have knowledge of the people or entities who post any specific content to such websites.” 

404 Media previously reported Proton gave the Swiss government payment data related to a Stop Cop City Protonmail account, which in turn handed it to the FBI, and in 2024, Proton gave Spanish police information that identified a pseudonymous activist.

New Research Shows Deepfake Harassment Tools Spread on Social Media and Search Engines

An analysis of how tools to make non-consensual sexually explicit deepfakes spread online, from the Institute for Strategic Dialogue, shows X and search engines surface these sites easily.

Aside from the infrastructure issue the researchers were studying, they found that 312 of the 400 sites they initially identified were unrelated to deepfakes, like gambling or random travel or cooking SEO-slop sites, but were using non-consensual imagery keywords as a way to rank higher in search results. This shows how incredibly popular the marketplace is for AI-generated abuse imagery, and how sites are able to manipulate Google search to appear higher in results if they use related terms. 

Morgan told me that while journalists can expose site administrators (like in the case of MrDeepfakes.com, whose owner was identified by a massive joint investigation by Bellingcat, the CBC and TjekDet), and legislation can act as a deterrent, the research group wanted to focus on infrastructure providers as the “distribution supply” for these sites. “Creators are going to create and people are going to demand. We can’t stop that. But we can call for providers to cut the distribution supply and stop enabling these sites. This content needs preventing from being shared in the first place. All parts of the ecosystem have to work together to play a part,” she said.

The researchers recommend in their paper that these providers stop supplying services to sites hosting non-consensual imagery. 

“We aren’t saying that infrastructure providers are knowingly facilitating this content — or that they are aware of what’s on every site that uses their provisions — but it’s in providers’ power to vastly improve their moderation and cease services to sites as soon as they are identified as hosting this content. And to check sites that are reported to them,” Morgan said. “A gold standard response in our eyes would be a commitment from infrastructure providers to working with NGOs and governments across the globe who are searching for solutions that will lead to verifying URLs and sharing these with participating platforms so they can be blocked.”   

Scroll to Top