appliedbits
FIELD NOTES PUBLISHED
PUBLISHED 2026-10-02

Cloudflare serves most of 88 deepfake abuse sites, study finds

Journal of Online Trust and Safety  ·  Sarah Morgan, Hany Farid, Sophie J. Nightingale  ·  source ↗

Sarah Morgan, Hany Farid and Sophie Nightingale identified 88 public sites hosting AI-generated non-consensual intimate imagery over six weeks, 38 of them dedicated to it, and traced nine infrastructure services behind each. The paper is in Stanford’s Journal of Online Trust and Safety; 404 Media reported it September 30.

Cloudflare was the provider in 64 of 105 hosting identifications, 68 of 122 CDN identifications and 67 of 87 DNS identifications. Google issued 61 of 88 SSL certificates. Namecheap was the largest registrar, at 27 of 88, ahead of Danesco Names and Porkbun at seven each. 82 of the 88 sites surfaced in Google Search within the authors’ three-step protocol. Most registrants used privacy services; the authors found four owners and passed their details to authorities. Cloudflare, Proton and Namecheap did not answer 404 Media.

The authors ask infrastructure providers to permanently drop sites that exclusively host this material, payment and ad networks to cut them off, and search engines to de-index them. The registrars here are bound by the same RAA section 3.18 that just ended Trustname’s accreditation, but the 2024 amendments define DNS abuse as malware, botnets, phishing, pharming and spam used to deliver them. NCII is outside that definition. Hosting, CDN and DNS providers have no accreditation contract at all.

Tagsdeepfakesnciiinfrastructureregistrars