Cloudflare, Google and Proton supplied services used by 38 sites dedicated to sexual deepfakes made without their subjects’ consent, researchers found in a study published September 30, 2026. Site operators used web hosting, security certificates, ads and email to run the sites; the people depicted bore the harm.
Cloudflare appeared most often in the study’s hosting-provider identifications, Google in its certificate and advertising identifications, and Proton Mail in its email-provider identifications.
Sarah Morgan, project coordinator at Lancaster University; Hany Farid, a computer science professor at Dartmouth College; and Sophie Nightingale, a senior psychology lecturer at Lancaster, examined 400 candidate web addresses between February 5 and March 19, 2026. They identified 88 sites hosting AI-generated nonconsensual intimate imagery, of which 38 were dedicated to it. The other 312 addresses did not qualify; 11 redirected to sites already counted.
The team then used web-analysis tools to identify the companies behind different parts of those sites. Among the 38 dedicated sites, Cloudflare accounted for 33 of 43 hosting-provider identifications, 34 of 54 content-delivery identifications and 34 of 39 domain-name-system identifications. Content-delivery networks help serve pages to visitors; the domain-name system directs a typed web address to a site. Cloudflare also appeared in 27 of 68 analytics identifications.
Google supplied security certificates for 31 of the 38 dedicated sites and appeared in 20 of 40 advertising-service identifications. Those certificates enable the encrypted connection a visitor sees in a browser. Proton Mail appeared in six of 19 email-provider identifications. The denominators differ because the researchers counted service identifications, not one provider per site.

The pattern extended beyond the dedicated sites. Across all 88 sites, the researchers recorded Cloudflare in 64 of 105 hosting-provider identifications and Google in 40 of 92 advertising identifications. Namecheap registered 27 of the 88 domains, including 13 of the dedicated sites.
Finding the sites required little digging. The researchers located 34 of the 38 dedicated sites, about 89%, calculated from the study’s counts, within the first two pages of Google results. Twenty appeared on page one. Searches ranged from words in a site’s name to its full address, so those results do not measure what someone searching for a victim would see.
The sample focused on recognizable celebrities so the researchers could assess whether images were fabricated. Subjects were predominantly women, including performers and K-pop idols. The researchers estimated that most dedicated sites held thousands of abusive files; more than a quarter held tens of thousands. The same ability to fabricate a recognizable person’s likeness has also surfaced in deepfakes targeting people in election campaigns.

What the providers said, and what their rules permit
Google’s publisher policies prohibit sexually explicit content and promotion of generated sexual imagery. In response to the study, Google told 404 Media that it blocks ads or suspends accounts for violations, but said it needed the domains to investigate these findings:
“Without the specific domains from the report, we can’t investigate these claims.”, Google spokesperson, speaking to 404 Media
Proton’s terms prohibit illegal uses and allow account restrictions. Cloudflare and Proton did not answer 404 Media’s requests for comment. Cloudflare’s January-June 2025 transparency report lists zero voluntary domain terminations and, in a separate category, 1,475 terminations involving child sexual abuse material.
One provider identification needs particular care. Researchers found WordPress software in 24 of 27 content-management identifications among dedicated sites. WordPress.org told 404 Media that anyone can install its open-source software on an independently hosted site; that does not give WordPress.org control of the site or its content. Farid pointed separately to hosting and other services supplied by WordPress.com and Automattic.
Morgan described the researchers’ focus as cutting off distribution rather than trying to identify every creator:
“But we can call for providers to cut the distribution supply and stop enabling these sites.”, Sarah Morgan, speaking to 404 Media
There is precedent for acting at a service boundary. In 2024, WIRED found Google sign-in available on 16 different nudify sites; after its inquiries, Discord and Apple terminated developer accounts connected to sites it examined. Sign-in is a different service from hosting or advertising, but the distinction is the point: each provider has its own relationship with a site and its own decision to make.
For the 38 sites mapped here, the study shows which services were present. It does not show that Google blocked their ads, Proton restricted their accounts or Cloudflare cut them off. The subjects remain on the sites while those decisions sit with the providers.
Further Reading
- The Backbone of Abuse, Peer-reviewed study of the sites, their discoverability and their service providers.
- Internet Infrastructure Services Empower Deepfake Abuse, New Study Finds, Reporting on provider responses and the dispute over WordPress.
- Google Publisher Policies, Google’s rules for content carried by its advertising products.
- Terms of Service, Proton’s rules on illegal use and account restrictions.
- Cloudflare | Transparency Report | H1 2025, Cloudflare’s published domain-termination figures.
- Harmful ‘Nudify’ Websites Used Google, Apple, and Discord Sign-On Systems, WIRED’s test of sign-in services on a different set of sites.
