Research / July 2026 / Investigation

5 of 5

of Google’s top results for a porn search are planted spam. Four of them run on hijacked university pages.

All Five of Google’s Top Results for “Best AI Porn Apps” Are Spam. Four Run on University Pages.

Published Data as of Updated

Type four words into Google. “Best AI porn apps.” Then look at what comes back.

The number one result is Roosevelt University. Number two is Eastern University. Number three is Benchling, a biotech software company. Number four is Cornell Law School. Number five is George Mason. Not one genuine review among them. Adult spam, planted on the web pages of American universities and a software platform by people they have never met, sitting at the very top of the largest search engine on earth.

We found eleven organisations caught this way in a single morning. Two weeks earlier we found nine others. Not one name repeats. This is not a glitch. It is an operation, and it is quietly taxing a market worth more than 1.6 million American searches a year.

The top of Google, taken over

One search: “best ai porn apps.” This is who actually holds the top five organic spots. Pink is a university. Violet is a software company. None of them know they are there.

best ai porn apps
1
Roosevelt Universityfundraising page
Hijacked .edu
2
Eastern Universityfundraising page
Hijacked .edu
3
Benchling (biotech software)shared-document platform
Hijacked SaaS
4
Cornell Law Schooljournal-software redirect
Hijacked .edu
5
George Mason Universityjournal-software redirect
Hijacked .edu

US organic results, measured 19 July 2026. There is no genuine result in the top five. Every position is planted content.

How a university ends up selling porn apps

None of these organisations uploaded anything. The trick is called parasite SEO, and it is parasitic in the literal sense. Attackers do not build their own trusted website. They borrow one. They find a feature on a domain Google already respects, a public fundraising page, a journal system, a form that accepts file uploads, a job board, even a bug tracker, and they use it to plant a page. Google sees a Cornell address and assumes the content is worth trusting. It ranks. The visitor gets funneled to adult affiliate offers. The institution never knows.

Across our data the hijack falls into six repeating shapes:

  • Journal-software redirects. Outdated academic publishing systems whose document viewer can be bent into a cloaked redirect. Seen on Cornell Law, George Mason, and the University of Technology Sydney.
  • Form-upload directories. Public web forms that save uploaded files where Google can crawl them. Seen on MIT, and on the state-government sites in our first report.
  • Fundraising page hijacks. “Start your own fundraiser” pages, seeded with spam. Seen on Roosevelt, Eastern, and a hospital charity.
  • Job and careers listings. Open submission of listings or applicant files. Seen on two nonprofit portals.
  • Bug-tracker attachments. File attachments served from a trusted corporate domain. Seen on Google’s own Chromium tracker.
  • Shared-document platforms. Collaborative document tools that publish user-created pages on a trusted company domain. Seen on Benchling, a biotech software platform, holding position three.

We are not publishing the exact URLs or upload methods. Every affected institution and Google received the full technical detail directly, so the pages can be removed without handing the next spammer a recipe.

The eleven, named

Every host below is a victim, not a participant. Positions are US organic, 19 July 2026.

Ten of the eleven hosts, mapped. Tap or hover a dot for the name. The eleventh is the University of Technology Sydney, Australia. Every host is also named in the table below.

InstitutionTypePeakQueryHijack vector
Roosevelt UniversityUS .edu#1best ai porn appsFundraising page hijack
Eastern UniversityUS .edu#2best ai porn appsFundraising page hijack
Benchling (biotech software)US corporate#3best ai porn appsShared-document abuse
Cornell Law SchoolUS .edu#4best ai porn appsJournal-software redirect
George Mason UniversityUS .edu#5best ai porn appsJournal-software redirect
Ochsner Health (charity)US .org#6best porn generatorFundraising page hijack
PWD (nonprofit careers)US .org#7best porn generatorCareers upload
Univ. of Technology SydneyAU .edu.au#12best porn generatorJournal-software redirect
MIT (Chemistry dept.)US .edu#12best ai porn appsForm-upload directory
PMA-DC (assoc. job board)US .org#18best ai porn generatorJob-listing spam
Google (Chromium tracker)Corp infra#2undress ai appIssue-attachment abuse

Zero of these eleven appeared in the nine hosts we documented on 12 July. Combined, that is twenty organisations in two weeks, and we were not looking hard.

The detail that should not exist

The number two result for “undress ai app,” a term 5,400 Americans search every month, is hosted on Google’s own Chromium bug tracker. Google is ranking a Google property, at number two, for a search about undressing people with AI. That single position funnels an estimated 750 people a month from Google, through Google, to spam.

The prize they are fighting for

Ten commercial terms. More than 135,000 American searches every month, over 1.6 million a year, from people ready to spend money. This is the real estate the spam network is quietly occupying.

ai porn generator
90,500
free ai porn generator
18,100
nsfw ai generator
12,100
best ai porn generator
6,600
undress ai app
5,400
best ai nude generator
1,000
best ai hentai generator
590
best ai porn apps
390
best ai sexting
390
best porn generator
90

Monthly US search volume per term. Measured by Sindexed, 19 July 2026.

What it costs, in plain numbers

Here is the honest version, floors not fantasies. On the positions we personally verified, the spam intercepts a floor of about 1,050 buying-intent clicks every month, roughly 12,600 a year, from people who wanted a real product and got a hijacked .edu instead.

1.6M

searches a year in the category the spam competes in

~12,600

buying-intent clicks a year diverted through the hosts we verified (a floor)

$9k to $38k

annual value of that diverted traffic, and it climbs with every new host

The dollar range is deliberately conservative. Google bans adult advertising, so this traffic cannot be bought on Google at any price. On the adult ad networks where it can be bought, a click like this runs anywhere from 75 cents to three dollars. Apply that to the traffic we verified and you get roughly 9,000 to 38,000 dollars a year, from four search terms, on the day we happened to look. Widen it to a realistic one to two percent capture of the whole category and the figure moves toward six figures a year. Every new host and every long-tail term pushes it up, never down.

Who pays, and who cashes in

Three groups lose. The institutions, whose good name is being used to sell adult content without their knowledge, and whose search reputation Google may punish for hosting spam. The person searching, who is quietly routed toward affiliate spam and possible malware. And every legitimate platform in the category, which does the honest work of building a product and then watches a hijacked university page take the click it earned.

One group wins. The affiliate operators who run this, and whichever platforms buy their redirected traffic. We are not naming the platforms that receive it, because doing so responsibly means following live hijack chains we have chosen not to publish. Tracing the money to its destination is the obvious next chapter, and we are working on it.

One more thing the data says

The spam is not spread evenly. It clusters on the buying words, “generator,” “porn,” “nude,” the searches with a wallet behind them, and it barely touches “girlfriend” or “chat.” These operators are not random vandals. They are following the money with a precision Google’s own spam team has not matched.

How we did this, and what we held back

On 19 July 2026 we pulled the top 20 to 25 US organic results for fourteen of the highest-demand adult-AI search terms and logged every university, charity, government or corporate host holding a first-two-pages position. Search volumes are our own measurement. Click estimates apply published organic click-through rates to each verified position, and are stated as floors. Rankings reflect the day we measured and will change as hosts clean up. Every host is a victim of a hijack. We make no claim that any institution created or approved this content.

Before publishing we notified the security teams of every named institution and Google’s security contact, with the specific URLs and methods, so the pages can be removed. We withheld those URLs and methods here on purpose, so this article documents the problem without teaching the next attacker how to repeat it.

Where the network stands

The tables above record the network as published, a frozen snapshot. This one tracks what has changed since.

* “Not observed” means the host did not appear in our sampled checks on the stated date; it may still rank intermittently. We do not know whether disappearances reflect enforcement action. ≈ marks approximate dates. Hollow dot = sampled observation; solid dot = directly confirmed.
HostFirst observedLast seen in our checksStatus
roosevelt.edu (fundraising page)Not observed since ≈19 Jul*
eastern.edu (fundraising page)Not observed since ≈19 Jul*
cornell.edu (pdf.js viewer)Not observed since ≈19 Jul*
gmu.edu (pdf.js viewer)Not observed since ≈19 Jul*
benchling.com (shared-document platform)Not observed since ≈19 Jul*
ochsner.org (fundraising page)Not observed since ≈19 Jul*
careers.pwd.org (careers upload)Not observed since ≈19 Jul*
epress.lib.uts.edu.au (pdf.js viewer)Not observed since ≈19 Jul*
chemistry.mit.edu (form-upload directory)Not observed since ≈19 Jul*
jobs.pma-dc.org (job-listing spam)Under review
issues.chromium.org (issue-attachment abuse)Under review
scribehow.com (planted review page)Page returns 410 (20 Jul)
scribehow.com (planted generator listicle)Still ranking
cityofpearidgear.gov (form-upload PDF)Under review
education.delaware.gov (document store)Under review
asset-sherlockbot.adobe.com (planted spam pages (corporate subdomain))Still ranking
cih.ucsd.edu (planted PDF)Still ranking
ktc.uky.edu (planted PDF)Still ranking
nationalsecurity.gmu.edu (planted PDF)Still ranking
calrecycle.ca.gov (planted PDF)Still ranking
lrapa-or.gov (planted PDF (27 Jul document stamp))Still ranking
capiaa.ca.gov (planted PDF (27 Jul document stamp))Still ranking
council.nyc.gov (planted PDF)Still ranking
foundation.charleston.edu (planted PDF)Still ranking
students.syr.edu (planted PDF)Still ranking
smc-aws-pub.stanford.edu (planted PDF (re-surfaced))Still ranking

This is a follow-up to our first investigation, The Parasite Files. All figures are free to cite with attribution to Sindexed and a link (CC BY 4.0). Reporters and affected institutions can reach us at support@sindexed.com.

* Figures reflect data as measured on the dates stated inline; where no date is stated, as of . Search results change continuously; the log below records material changes we have observed since publication.
Updates & corrections
UpdateAn index-level re-measurement on 17 August found every institutional host we had been tracking absent from the measured top ten across six covered queries: the Roosevelt and Eastern charity pages, Benchling, ResearchGate, LeetCode, the tahoe.ca.gov documents and the syr.edu page among them. The class has not receded: the same charity-fundraiser path pattern reappeared the same week on a University of Nebraska-Lincoln page (glowbigred.unl.edu), and new plantings were observed on an IEEE-operated GitLab instance and a California state .gov form-upload directory. This read comes from search-index data, not a live browser sample, and our previous checks have shown live results can remain saturated after the index clears. Browser verification is pending. The published snapshot above is unchanged.
UpdateThe network has jumped beyond institutional hosts to a Fortune-500 corporate subdomain: asset-sherlockbot.adobe.com was carrying planted adult-keyword spam pages in live results on a covered query, verified in-browser on 28 July. Ten further hosts were observed and browser-verified the same day, including two .gov documents carrying 27 July stamps, planted the day before we found them, and one university host previously logged in our checks re-surfacing. All are recorded in the status table below with observation dates. The published snapshot above is unchanged; the class is expanding, not receding.
StatusThe institutional hosts named in our headline finding are no longer observed in live Google search for those queries. Google's results pages now carry legal-request removal notices (11 and 24 results on the two queries as of 21 July). Slower third-party indexes still list some of them, and intermittent ranking remains possible. The snapshot above is unchanged, as published.
UpdateOne planted third-party page tracked in our checks now returns HTTP 410 (gone). A separate planted page on the same host is still live, so the class is receding unevenly, not resolved.
UpdateAdditional hosts observed ranking on covered queries, including three government domains not in the published corpus. Logged in our checks; see the status table for host-level detail.
UpdatePublished. All named institutions and Google's security contact were notified before publication.
Full history
CorrectionPre-publication: position 3 was initially logged as a legitimate result; re-verification showed planted content on a corporate document platform. Corrected before publishing, and disclosed to the affected host.