Research / July 2026 / Investigation
5 of 5
of Google’s top results for a porn search are planted spam. Four of them run on hijacked university pages.
All Five of Google’s Top Results for “Best AI Porn Apps” Are Spam. Four Run on University Pages.
Type four words into Google. “Best AI porn apps.” Then look at what comes back.
The number one result is Roosevelt University. Number two is Eastern University. Number three is Benchling, a biotech software company. Number four is Cornell Law School. Number five is George Mason. Not one genuine review among them. Adult spam, planted on the web pages of American universities and a software platform by people they have never met, sitting at the very top of the largest search engine on earth.
We found eleven organisations caught this way in a single morning. Two weeks earlier we found nine others. Not one name repeats. This is not a glitch. It is an operation, and it is quietly taxing a market worth more than 1.6 million American searches a year.
The top of Google, taken over
One search: “best ai porn apps.” This is who actually holds the top five organic spots. Pink is a university. Violet is a software company. None of them know they are there.
US organic results, measured 19 July 2026. There is no genuine result in the top five. Every position is planted content.
How a university ends up selling porn apps
None of these organisations uploaded anything. The trick is called parasite SEO, and it is parasitic in the literal sense. Attackers do not build their own trusted website. They borrow one. They find a feature on a domain Google already respects, a public fundraising page, a journal system, a form that accepts file uploads, a job board, even a bug tracker, and they use it to plant a page. Google sees a Cornell address and assumes the content is worth trusting. It ranks. The visitor gets funneled to adult affiliate offers. The institution never knows.
Across our data the hijack falls into six repeating shapes:
- Journal-software redirects. Outdated academic publishing systems whose document viewer can be bent into a cloaked redirect. Seen on Cornell Law, George Mason, and the University of Technology Sydney.
- Form-upload directories. Public web forms that save uploaded files where Google can crawl them. Seen on MIT, and on the state-government sites in our first report.
- Fundraising page hijacks. “Start your own fundraiser” pages, seeded with spam. Seen on Roosevelt, Eastern, and a hospital charity.
- Job and careers listings. Open submission of listings or applicant files. Seen on two nonprofit portals.
- Bug-tracker attachments. File attachments served from a trusted corporate domain. Seen on Google’s own Chromium tracker.
- Shared-document platforms. Collaborative document tools that publish user-created pages on a trusted company domain. Seen on Benchling, a biotech software platform, holding position three.
We are not publishing the exact URLs or upload methods. Every affected institution and Google received the full technical detail directly, so the pages can be removed without handing the next spammer a recipe.
The eleven, named
Every host below is a victim, not a participant. Positions are US organic, 19 July 2026.
Ten of the eleven hosts, mapped. Tap or hover a dot for the name. The eleventh is the University of Technology Sydney, Australia. Every host is also named in the table below.
| Institution | Type | Peak | Query | Hijack vector |
|---|---|---|---|---|
| Roosevelt University | US .edu | #1 | best ai porn apps | Fundraising page hijack |
| Eastern University | US .edu | #2 | best ai porn apps | Fundraising page hijack |
| Benchling (biotech software) | US corporate | #3 | best ai porn apps | Shared-document abuse |
| Cornell Law School | US .edu | #4 | best ai porn apps | Journal-software redirect |
| George Mason University | US .edu | #5 | best ai porn apps | Journal-software redirect |
| Ochsner Health (charity) | US .org | #6 | best porn generator | Fundraising page hijack |
| PWD (nonprofit careers) | US .org | #7 | best porn generator | Careers upload |
| Univ. of Technology Sydney | AU .edu.au | #12 | best porn generator | Journal-software redirect |
| MIT (Chemistry dept.) | US .edu | #12 | best ai porn apps | Form-upload directory |
| PMA-DC (assoc. job board) | US .org | #18 | best ai porn generator | Job-listing spam |
| Google (Chromium tracker) | Corp infra | #2 | undress ai app | Issue-attachment abuse |
Zero of these eleven appeared in the nine hosts we documented on 12 July. Combined, that is twenty organisations in two weeks, and we were not looking hard.
The detail that should not exist
The number two result for “undress ai app,” a term 5,400 Americans search every month, is hosted on Google’s own Chromium bug tracker. Google is ranking a Google property, at number two, for a search about undressing people with AI. That single position funnels an estimated 750 people a month from Google, through Google, to spam.
The prize they are fighting for
Ten commercial terms. More than 135,000 American searches every month, over 1.6 million a year, from people ready to spend money. This is the real estate the spam network is quietly occupying.
Monthly US search volume per term. Measured by Sindexed, 19 July 2026.
What it costs, in plain numbers
Here is the honest version, floors not fantasies. On the positions we personally verified, the spam intercepts a floor of about 1,050 buying-intent clicks every month, roughly 12,600 a year, from people who wanted a real product and got a hijacked .edu instead.
1.6M
searches a year in the category the spam competes in
~12,600
buying-intent clicks a year diverted through the hosts we verified (a floor)
$9k to $38k
annual value of that diverted traffic, and it climbs with every new host
The dollar range is deliberately conservative. Google bans adult advertising, so this traffic cannot be bought on Google at any price. On the adult ad networks where it can be bought, a click like this runs anywhere from 75 cents to three dollars. Apply that to the traffic we verified and you get roughly 9,000 to 38,000 dollars a year, from four search terms, on the day we happened to look. Widen it to a realistic one to two percent capture of the whole category and the figure moves toward six figures a year. Every new host and every long-tail term pushes it up, never down.
Who pays, and who cashes in
Three groups lose. The institutions, whose good name is being used to sell adult content without their knowledge, and whose search reputation Google may punish for hosting spam. The person searching, who is quietly routed toward affiliate spam and possible malware. And every legitimate platform in the category, which does the honest work of building a product and then watches a hijacked university page take the click it earned.
One group wins. The affiliate operators who run this, and whichever platforms buy their redirected traffic. We are not naming the platforms that receive it, because doing so responsibly means following live hijack chains we have chosen not to publish. Tracing the money to its destination is the obvious next chapter, and we are working on it.
One more thing the data says
The spam is not spread evenly. It clusters on the buying words, “generator,” “porn,” “nude,” the searches with a wallet behind them, and it barely touches “girlfriend” or “chat.” These operators are not random vandals. They are following the money with a precision Google’s own spam team has not matched.
How we did this, and what we held back
On 19 July 2026 we pulled the top 20 to 25 US organic results for fourteen of the highest-demand adult-AI search terms and logged every university, charity, government or corporate host holding a first-two-pages position. Search volumes are our own measurement. Click estimates apply published organic click-through rates to each verified position, and are stated as floors. Rankings reflect the day we measured and will change as hosts clean up. Every host is a victim of a hijack. We make no claim that any institution created or approved this content.
Before publishing we notified the security teams of every named institution and Google’s security contact, with the specific URLs and methods, so the pages can be removed. We withheld those URLs and methods here on purpose, so this article documents the problem without teaching the next attacker how to repeat it.
This is a follow-up to our first investigation, The Parasite Files. All figures are free to cite with attribution to Sindexed and a link (CC BY 4.0). Reporters and affected institutions can reach us at support@sindexed.com.