Research / July 2026 / Investigation

5 of 5

of Google’s top results for a porn search are planted spam. Four of them run on hijacked university pages.

All Five of Google’s Top Results for “Best AI Porn Apps” Are Spam. Four Run on University Pages.

Type four words into Google. “Best AI porn apps.” Then look at what comes back.

The number one result is Roosevelt University. Number two is Eastern University. Number three is Benchling, a biotech software company. Number four is Cornell Law School. Number five is George Mason. Not one genuine review among them. Adult spam, planted on the web pages of American universities and a software platform by people they have never met, sitting at the very top of the largest search engine on earth.

We found eleven organisations caught this way in a single morning. Two weeks earlier we found nine others. Not one name repeats. This is not a glitch. It is an operation, and it is quietly taxing a market worth more than 1.6 million American searches a year.

The top of Google, taken over

One search: “best ai porn apps.” This is who actually holds the top five organic spots. Pink is a university. Violet is a software company. None of them know they are there.

best ai porn apps
1
Roosevelt Universityfundraising page
Hijacked .edu
2
Eastern Universityfundraising page
Hijacked .edu
3
Benchling (biotech software)shared-document platform
Hijacked SaaS
4
Cornell Law Schooljournal-software redirect
Hijacked .edu
5
George Mason Universityjournal-software redirect
Hijacked .edu

US organic results, measured 19 July 2026. There is no genuine result in the top five. Every position is planted content.

How a university ends up selling porn apps

None of these organisations uploaded anything. The trick is called parasite SEO, and it is parasitic in the literal sense. Attackers do not build their own trusted website. They borrow one. They find a feature on a domain Google already respects, a public fundraising page, a journal system, a form that accepts file uploads, a job board, even a bug tracker, and they use it to plant a page. Google sees a Cornell address and assumes the content is worth trusting. It ranks. The visitor gets funneled to adult affiliate offers. The institution never knows.

Across our data the hijack falls into six repeating shapes:

  • Journal-software redirects. Outdated academic publishing systems whose document viewer can be bent into a cloaked redirect. Seen on Cornell Law, George Mason, and the University of Technology Sydney.
  • Form-upload directories. Public web forms that save uploaded files where Google can crawl them. Seen on MIT, and on the state-government sites in our first report.
  • Fundraising page hijacks. “Start your own fundraiser” pages, seeded with spam. Seen on Roosevelt, Eastern, and a hospital charity.
  • Job and careers listings. Open submission of listings or applicant files. Seen on two nonprofit portals.
  • Bug-tracker attachments. File attachments served from a trusted corporate domain. Seen on Google’s own Chromium tracker.
  • Shared-document platforms. Collaborative document tools that publish user-created pages on a trusted company domain. Seen on Benchling, a biotech software platform, holding position three.

We are not publishing the exact URLs or upload methods. Every affected institution and Google received the full technical detail directly, so the pages can be removed without handing the next spammer a recipe.

The eleven, named

Every host below is a victim, not a participant. Positions are US organic, 19 July 2026.

Ten of the eleven hosts, mapped. Tap or hover a dot for the name. The eleventh is the University of Technology Sydney, Australia. Every host is also named in the table below.

InstitutionTypePeakQueryHijack vector
Roosevelt UniversityUS .edu#1best ai porn appsFundraising page hijack
Eastern UniversityUS .edu#2best ai porn appsFundraising page hijack
Benchling (biotech software)US corporate#3best ai porn appsShared-document abuse
Cornell Law SchoolUS .edu#4best ai porn appsJournal-software redirect
George Mason UniversityUS .edu#5best ai porn appsJournal-software redirect
Ochsner Health (charity)US .org#6best porn generatorFundraising page hijack
PWD (nonprofit careers)US .org#7best porn generatorCareers upload
Univ. of Technology SydneyAU .edu.au#12best porn generatorJournal-software redirect
MIT (Chemistry dept.)US .edu#12best ai porn appsForm-upload directory
PMA-DC (assoc. job board)US .org#18best ai porn generatorJob-listing spam
Google (Chromium tracker)Corp infra#2undress ai appIssue-attachment abuse

Zero of these eleven appeared in the nine hosts we documented on 12 July. Combined, that is twenty organisations in two weeks, and we were not looking hard.

The detail that should not exist

The number two result for “undress ai app,” a term 5,400 Americans search every month, is hosted on Google’s own Chromium bug tracker. Google is ranking a Google property, at number two, for a search about undressing people with AI. That single position funnels an estimated 750 people a month from Google, through Google, to spam.

The prize they are fighting for

Ten commercial terms. More than 135,000 American searches every month, over 1.6 million a year, from people ready to spend money. This is the real estate the spam network is quietly occupying.

ai porn generator
90,500
free ai porn generator
18,100
nsfw ai generator
12,100
best ai porn generator
6,600
undress ai app
5,400
best ai nude generator
1,000
best ai hentai generator
590
best ai porn apps
390
best ai sexting
390
best porn generator
90

Monthly US search volume per term. Measured by Sindexed, 19 July 2026.

What it costs, in plain numbers

Here is the honest version, floors not fantasies. On the positions we personally verified, the spam intercepts a floor of about 1,050 buying-intent clicks every month, roughly 12,600 a year, from people who wanted a real product and got a hijacked .edu instead.

1.6M

searches a year in the category the spam competes in

~12,600

buying-intent clicks a year diverted through the hosts we verified (a floor)

$9k to $38k

annual value of that diverted traffic, and it climbs with every new host

The dollar range is deliberately conservative. Google bans adult advertising, so this traffic cannot be bought on Google at any price. On the adult ad networks where it can be bought, a click like this runs anywhere from 75 cents to three dollars. Apply that to the traffic we verified and you get roughly 9,000 to 38,000 dollars a year, from four search terms, on the day we happened to look. Widen it to a realistic one to two percent capture of the whole category and the figure moves toward six figures a year. Every new host and every long-tail term pushes it up, never down.

Who pays, and who cashes in

Three groups lose. The institutions, whose good name is being used to sell adult content without their knowledge, and whose search reputation Google may punish for hosting spam. The person searching, who is quietly routed toward affiliate spam and possible malware. And every legitimate platform in the category, which does the honest work of building a product and then watches a hijacked university page take the click it earned.

One group wins. The affiliate operators who run this, and whichever platforms buy their redirected traffic. We are not naming the platforms that receive it, because doing so responsibly means following live hijack chains we have chosen not to publish. Tracing the money to its destination is the obvious next chapter, and we are working on it.

One more thing the data says

The spam is not spread evenly. It clusters on the buying words, “generator,” “porn,” “nude,” the searches with a wallet behind them, and it barely touches “girlfriend” or “chat.” These operators are not random vandals. They are following the money with a precision Google’s own spam team has not matched.

How we did this, and what we held back

On 19 July 2026 we pulled the top 20 to 25 US organic results for fourteen of the highest-demand adult-AI search terms and logged every university, charity, government or corporate host holding a first-two-pages position. Search volumes are our own measurement. Click estimates apply published organic click-through rates to each verified position, and are stated as floors. Rankings reflect the day we measured and will change as hosts clean up. Every host is a victim of a hijack. We make no claim that any institution created or approved this content.

Before publishing we notified the security teams of every named institution and Google’s security contact, with the specific URLs and methods, so the pages can be removed. We withheld those URLs and methods here on purpose, so this article documents the problem without teaching the next attacker how to repeat it.

This is a follow-up to our first investigation, The Parasite Files. All figures are free to cite with attribution to Sindexed and a link (CC BY 4.0). Reporters and affected institutions can reach us at support@sindexed.com.