✓ Connection Protected ISP: Anthropic, PBC (216.73.217.135)

Hackers Hijack Government Websites to Push AI Porn Ads

Cybercriminals have compromised dozens of government websites to spread porn ads and malicious content. The attacks targeted at least 38 government sites across 18 states.

Hackers Hijack Government Websites to Push AI Porn Ads

How the Attack Works

Hackers exploited a vulnerability in public form submission features on government websites. These sites allow residents to upload documents for feedback and public comment. Bad actors used these upload forms to inject adult content onto trusted government domains.

The compromised sites include agencies in Nebraska, Indiana, Hawaii, California, Washington, and Kansas. Google indexed the malicious content, making it appear in search results when users looked for government services.

Example of Hacked Website
Example of Hacked Website (Image Source: KWCH 12 News)

What Content Appeared

The hijacked pages displayed various types of questionable material:

  • AI-generated pornography creation tools
  • Adult chatbot advertisements
  • Online sex toy store promotions
  • Malware downloads disguised as legitimate files

Security researcher Dominic Alvieri discovered the widespread campaign while investigating cyberattacks. He found that hackers didn’t actually breach the websites themselves. Instead, they simply uploaded files through public forms meant for resident feedback.

Social Post from Dominic Alvieri
Social Post from Dominic Alvieri

Affected Agencies

Major government organizations impacted include:

  • California Secretary of State
  • Hawaii State Government
  • Indiana State Department of Health
  • Nevada Department of Transportation
  • Washington State Department of Veterans Affairs
  • US General Services Administration

Nebraska appeared to have the highest number of poisoned PDFs appearing in Google search results.

Example of Infected Google Search Results
Example of Infected Google Search Results

Government Response

Denver-based software company Granicus hosts approximately 5,500 government sites. The company confirmed that outside actors exploited public form submissions to upload inappropriate content. Granicus stated they detected no breach of their systems or data.

 
Your Connection is Exposed

Hide Your Digital Fingerprint

IP Address 216.73.217.135
Location Columbus, Ohio
ISP Anthropic, PBC
Secure My Connection Now
Limited Time: 85% Off + 3 Months FREE
 

“Those attachments were then indexed by Google, causing them to appear in search results,” Granicus explained in an official statement.

The company identified 10 IP addresses used to upload the malicious content. Those addresses are now blocked. Granicus also implemented security measures to prevent uploaded documents from becoming publicly accessible through search engines.

Final Thoughts

This attack shows how hackers can abuse trusted government domains without actually breaking into the sites. Users searching for official government information could accidentally click on pornographic ads or download malware.

The incident highlights the need for better security controls on public form submissions. Government agencies must verify and scan all uploaded content before it becomes publicly accessible through search engines.

For more details on this story, refer to the report from KWCH 12 News and the posts from security researcher Dominic Alvieri.

We want to know your thoughts. What do you think about this story? Let us know in the comment section below!

Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.

This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.

SURFSHARK VPN
ONLY $.07/DAY!

X
TROYPOINT Last Chance for VPN