⌁AI·CYBER·BRIEF▌
AI Threats6 min read

167 lookalike "Jev AI" domains in 13 days — and some of them relay your prompts

UpGuard counted 167 Jev lookalike domains in the 13 days after TypeSafe's launch, at roughly twice the rate seen for ChatGPT or Claude. A few sit between users and the real product.

TypeSafe announced its Jev model on September 15, 2026. Within 13 days, 167 lookalike domains built around the name had been registered, according to research UpGuard published on October 5. A handful of the resulting sites do something worse than squat on a name: they pass user traffic through to the real product while logging what goes by.

What happened, in plain English

When a product becomes popular very quickly, people register domain names that look like the official one. Some hope to resell them, some want the search traffic, and some want to be mistaken for the real thing.

UpGuard, a security firm that tracks newly registered domains, looked at what happened around Jev's launch and found 167 names containing "jev" registered in the 13 days that followed — about 12.8 per day. For comparison, over the same monitoring window (August 14 to September 28, 2026) the firm saw roughly 6.7 new Claude lookalikes and 5.4 ChatGPT lookalikes per day. A new product with no established defenses drew lookalikes at about twice the rate of the incumbents.

The interesting part is what a few of these sites actually do. UpGuard describes pages advertising "Jev AI" that work as a wrapper: you type a prompt, the site forwards it to the real service, and the answer comes back. Nothing looks broken, because nothing is broken — but the prompt, any file you attached, and any API key you pasted have passed through someone else's server on the way. UpGuard calls one of them a "data-mining wrapper for the real Jev."

Think of it as a shop front that takes your order, walks next door to buy the item, and hands it to you with a markup you never see — except what it keeps is your data, not your money.

A second group of these domains is set up for email. UpGuard found 24 domains across the "jev", "jevai" and "typesafe" keyword sets with deliberately configured mail servers, which means they can send messages that appear to come from the vendor — a password reset, an invoice, a "your API quota has been upgraded" notice — or receive mail intended for the real company.

Are you affected? What to do now

If nobody in your organization uses Jev, there is nothing to do today beyond the general point at the end of this section. If people do use it — and TypeSafe says the model is in use at 25% of the Fortune 500, a claim the company has not supported with a customer list — work through this:

  • Know the canonical domain. TypeSafe's official site is typesafe.ai, with documentation at docs.typesafe.ai and the account console at console.typesafe.ai. Everything else is not TypeSafe, however plausible the name. Confirm against your contract or invoices rather than a search result or an ad; paid search placements are one of the ways lookalike sites get traffic.
  • Search your own logs for the rest. Query DNS resolver logs, web proxy logs and firewall logs for hostnames containing jev or typesafe, and treat every hit outside typesafe.ai as worth a look.
  • Ask whether an API key ever left the official domain. Any key pasted into a third-party "Jev" page should be treated as disclosed: rotate it in console.typesafe.ai, then review the account's usage logs for calls you cannot account for.
  • Check what was typed into those pages. If staff used a wrapper site, the exposure is whatever they submitted — source code, customer records, internal documents. That determines whether this is a cleanup or a reportable incident.
  • Allowlist rather than blocklist. Allowing typesafe.ai and its subdomains is more durable than trying to block lookalikes as they appear; UpGuard's figures show new ones arriving faster than any blocklist is updated.
  • Warn users about the email angle. Messages about billing, quota or account changes for a newly adopted AI tool are a natural fit for invoice fraud, because few people yet know what legitimate mail from that vendor looks like.
  • If you own the brand: UpGuard's own recommendation is to have domain monitoring and defensive registrations in place before a launch, "because by the time it is obviously needed, most of the namespace is already gone."

Examples named in the report give a sense of the pattern: jev-ai.com (listed for resale at $9,800), thejevai.com, jev-ai-typesafe.com and typesafe-jev.com. Hyphens and a leading "the" are doing a lot of work here, as is the spread across newer top-level domains like .cloud, .support and .software.

The expert view

Nothing in this research is technically novel, and that is the point worth making to a security team.

The proxy pattern is a plain man-in-the-middle, except no interception is needed — the victim is sent to the attacker voluntarily, and the attacker provides real value by relaying to the genuine API. There is no certificate warning to notice and no broken page to report, because the TLS connection to the lookalike site is perfectly valid; it just terminates in the wrong place. The only signals available to a defender are the hostname itself and the absence of the request from the real vendor's audit logs. That makes DNS and proxy telemetry the detection surface here, not endpoint tooling.

What is different about the AI case is the value density of the intercepted traffic. A squatted banking domain yields credentials, which are revocable and usually protected by a second factor. A squatted AI domain yields whatever employees paste into a chat box, which in practice is unreleased code, customer data, contracts and incident notes — along with API keys that often carry broad scopes and no second factor. The same interception produces a much richer haul.

The launch-window effect is also structural rather than incidental. The report's comparison of registration rates — 12.8 per day for Jev against 6.7 and 5.4 for Claude and ChatGPT — should be read with the caveat that it compares a 13-day burst against a 46-day baseline, so the multiple would likely shrink over a longer window. But the direction holds: attention arrives before brand protection does, and the first days after an announcement are when defensive registrations are both cheapest and least likely to exist. It is the same asymmetry as unpatched software at release, applied to a namespace.

Two things this research does not show, and should not be read as showing. It names no victims and confirms no data theft — the finding is an exposure pattern and the capability to abuse it, not an incident. And it does not establish how much traffic these sites receive; a lookalike domain registered for resale and one actively proxying prompts look similar in registration data but differ enormously in impact. Anyone quoting the 167 figure as a count of active attacks is overstating it.

Official sources

Coverage: none at the time of writing — this brief is based on the research report itself, which was brought to our attention by UpGuard's press team.

Get the daily brief

AI + security signal by email: headlines, a two-line summary, a link. No noise, no spam.

How often