[Breaches](/breaches)

Have You Heard of Jev? They Have.

[Blog](/blog)[Breaches](/breaches)[Resources](/resources)[News](/news)

# Have You Heard of Jev? They Have.

##### [Greg Pollock](/team/greg-pollock)

Published Oct 05, 2026

##### Join 27,000+ cybersecurity newsletter subscribers

On September 15th 2026, San Francisco-based company [TypeSafe](https://typesafe.ai/) released an AI model named “[Jev](https://en.wikipedia.org/wiki/Jev_\(AI_model\))” into limited early access. Jev is unusual in that it does not “talk.” Where a large language model generates text, Jev answers a fixed set of question types (pick one of these options, score this against these levels, answer yes or no, etc.) and returns a typed value with a confidence estimate. By September 18th, just three days later, [Vercel clocked Jev](https://vercel.com/blog/ai-gateway-jev-model-launch) as the fastest-adopted model in the history of its AI gateway. TypeSafe removed its initial waitlist on September 20th, but within just two days, the company [had to pause new signups](https://aifront-page.com/typesafe-ai-pauses-jev-ai-model-signups-demand-surge/) because it couldn’t keep up with demand. In the space of about a week, a name almost nobody had typed into a browser became one of the most searched terms in the industry.

A brand that becomes valuable overnight becomes a target overnight. One of the cheapest ways to take a piece of it is to register a domain that looks like it belongs to that brand. Some will park the domain and wait to resell it at a markup. Some run advertising on it and monetize the mistyped traffic. Some build a convincing copy of the real site to harvest credentials or API keys. Some configure mail on it and send invoices, support requests or recruitment offers that appear to come from the company. For 46 days, from August 14th to September 28th, we monitored the feed of all newly registered domain names and found those resembling Jev and fifteen other AI products and companies. Jev’s first lookalike domain, jev.quest, was registered on September 16th, the day after the model was announced. By September 28th there were 167 of them.

## What Is Jev, And Why Domain Spoofing? 

### About Jev

Typesafe positions Jev as a “[System One](https://docs.typesafe.ai/concepts/system-one)” model, more generically called a "decision model" or classifer. This means it is not a replacement for an LLM, but a fast, cheap layer for routine decision making inside software workflows. The [company claims](https://typesafe.ai/blog/introducing-system-one-models-and-jev) response times of 70 to 500 milliseconds and costs 40 to 400 times lower than a frontier model on comparable classification work. Because the answers are constrained to a schema defined in advance, [TypeSafe argues](https://typesafe.ai/blog/introducing-system-one-models-and-jev) the model cannot “hallucinate” or return something the calling code was not expecting. TypeSafe’s founders include [Diogo Almeida](https://typesafe.ai/team), who spent about four years at OpenAI working on reinforcement learning.

### Domain Spoofing

The techniques of [domain spoofing](https://en.wikipedia.org/wiki/Domain_name#Domain_name_spoofing) are well worn. The simplest is to take the exact name and buy it on every extension the owner does not already hold, for example: jev.app, jev.cloud, jev.support. A second is the one-character typo, exploiting the fact that a meaningful fraction of people will mistype a name they have only just learned. A third substitutes lookalike characters, so that a zero stands in for an O or “rn” for an M. The fourth, and in practice the most dangerous, wraps the brand inside a longer, more plausible sounding name: jev-support.com, jevai-login.net, secure-jev.io. 

When a user accidentally ends up at one of these sites, the consequences can range from giving clicks to ads set up on the dummy site to full exposure of PII, credentials and other sensitive information when entered into a fraudulent form or login window.

## Data Analysis

For each keyword, we scanned every domain registered between August 14th and September 28th. We flagged each of the four specific kinds of resemblance types mentioned above. Every match was then resolved in DNS, recording whether the domain points at a server and whether it is configured to receive mail. We found that lookalike domains playing on the Typesafe and Jev brand names appeared immediately and grew rapidly in the weeks after launch.

| Date      | What happened to Jev                                        | New Lookalike Domains |
| --------- | ----------------------------------------------------------- | --------------------- |
| 15 Sep    | Early access; $40M seed announced; launch video goes viral. | 0                     |
| 16 Sep    |                                                             | 1                     |
| 17 Sep    |                                                             | 17                    |
| 18 Sep    | Vercel: fastest-adopted model in AI Gateway history         | 11                    |
| 19 Sep    |                                                             | 75                    |
| 20 Sep    | Waitlist removed, general availability                      | 12                    |
| 21 Sep    |                                                             | 15                    |
| 22 Sep    | New signups paused due to demand                            | 15                    |
| 23–28 Sep | Bloomberg coverage (25 Sep)                                 | 21                    |

### “jev”

166 domains are the exact name jev on different TLDs. Those 166 domains sit on 166 distinct extensions, with no extension used twice. This is the signature of an automated run down a list of available top-level domains, buying the name on each one. The extensions cover nearly the whole generic namespace in what appear to be alphabetical batches: .accountants, .art, .asia and onwards. Alongside credible targets like .cloud, .software, .systems and .support, the sweep also took .wtf, .mom, and .dog,  extensions no serious impersonation campaign would choose. This all gives a strong indication that the jev name was being bought in bulk, likely with the intent to resell some of them back to TypeSafe.

### “jevai”

jevai returned 93 distinct domains. 40 domains are the exact name on another extension and 53 are typographic variants. One of those, jevaisecurity.com, is a direct impersonation of a Jev-related security product.

The names that really matter are hyphenated. Between the 17th and 26th of September, 22 domains of the form jev-ai.\<extension> were registered, for example: .com, .space, .pro, .org, etc. Most sit behind Cloudflare, and seven even have Cloudflare Email Routing configured. These are fronted by a CDN and set up to receive mail, which is a materially different level of effort from buying a name and pointing it at an ad page. Hyphenation is also the highest-yield pattern for a short brand, because jev-ai.com reads as legitimate in a way that jevv.com does not.

### “typesafe”

typesafe returned 35 domains and was first seen on September 17th. The interesting domains pair the company with the product, such as jev-typesafe.com, jev-typesafe.org, jev-typesafe.pro, typesafe-jev.com, and jev-ai-typesafe.com. This last domain is configured for inbound mail through Amazon SES. Two more, typesafe-ai-avis.fr and avis-typesafe-ai.fr, use the French word for “review” and follow the standard pattern for affiliate and review-bait pages that rank for a brand’s name before the brand itself does.

Across all three keywords, 24 domains have working mail on infrastructure someone configured deliberatel&#x79;**.** Only two of those 24 are in the jev scan. The volume is under jev, but the intent is under jevai and typesafe.

## Jev Compared With Other AI Keywords

While it was in the news, Jev attracted lookalike registrations at roughly twice the rate of Claude, the most-targeted established AI brand in the set, and about two and a half times the rate of ChatGPT. Jev saw 13 new domains a day against Claude’s 6.7 and ChatGPT’s 5.4.

| Keyword    | Domains | Per Million | Per Day | Window  | Real Mail |
| ---------- | ------- | ----------- | ------- | ------- | --------- |
| jev        | 167     | 30.0        | 12.8    | 13 days | 1%        |
| claude     | 306     | 15.6        | 6.7     | 46 days | 30%       |
| copilot    | 265     | 13.5        | 5.8     | 46 days | 20%       |
| chatgpt    | 250     | 12.7        | 5.4     | 46 days | 23%       |
| gemini     | 234     | 11.9        | 5.1     | 46 days | 21%       |
| deepseek   | 213     | 10.8        | 4.6     | 46 days | 3%        |
| typesafe   | 35      | 7.4         | 3.2     | 11 days | 14%       |
| grok       | 140     | 7.1         | 3.0     | 46 days | 11%       |
| jevai      | 93      | 5.2         | 2.2     | 42 days | 19%       |
| llama      | 98      | 5.0         | 2.1     | 46 days | 15%       |
| openai     | 88      | 4.8         | 2.0     | 43 days | 20%       |
| anthropic  | 49      | 2.7         | 1.1     | 43 days | 12%       |
| perplexity | 47      | 2.5         | 1.1     | 44 days | 51%       |
| qwen       | 37      | 1.9         | 0.8     | 45 days | 8%        |
| deepmind   | 20      | 1.1         | 0.5     | 41 days | 5%        |
| midjourney | 13      | 0.9         | 0.4     | 35 days | 0%        |

Product names attract far more impersonation than company names: claude drew 306 domains against anthropic’s 49, chatgpt 250 against openai’s 88, gemini 234 against deepmind’s 20. Squatters chase the word users type. On that basis, jev will keep carrying more risk than typesafe.

Perplexity drew only 47 domains, but 51% of them have real mail configured, 17 on Google Workspace. Although the volume is relatively small, the intent behind the lookalikes seems more focused.

## Why It Matters

### Timing Is Everything

Jev’s launch produced one of the fastest lookalike-domain responses we’ve measured so far: 167 domains in 13 days. That’s roughly twice the rate that the most-targeted established AI brands sustain.

A lookalike domain is worth what its traffic is worth, and traffic follows whatever people are currently searching. The registration curve in this data tracks the news cycle quite closely. The peak came when Jev was [most talked about](https://www.theinformation.com/newsletters/dealmaker/jev-fervor-leads-talk-big-valuation-boost). A domain costs a few dollars and takes minutes to register. Nobody needs to know anything about the product, or even whether it will still exist in six months. Buy the name on fifty extensions, park them and wait. Some fraction will draw mistyped traffic, some fraction can be resold to the brand later. The 75 domain run on September 19th for Jev is that calculation executed at scale. 

Any brand protection process that begins at launch is already a week behind. Jev’s first lookalike appeared the day after [announcement](https://typesafe.ai/blog/introducing-system-one-models-and-jev), and 116 arrived in the first full week. Meanwhile, TypeSafe now has to decide which, if any, of the 166 extensions are worth buying back and at what price.

### AI Fraud

New AI brands appear constantly and unpredictably. Users have no accumulated instinct for which domain is real. Someone who has used a bank for ten years knows what its address looks like. Someone who heard about Jev on Tuesday does not, and jev-ai.com and other variations are entirely plausible. 

Signing up for an AI service typically means creating an account, entering payment details, and generating an API key. This API key is a credential that is long-lived, frequently pasted into code and directly convertible into compute an attacker does not have to pay for. A convincing fake signup page for an AI product is straightforwardly profitable in a way that a fake page for most other consumer software is not.

Secondly, while a parked domain waits for people to arrive, a mail-capable domain can go out to them. All the phishing and fraud vectors have more success when the sending domain closely resembles or contains the real one. Invoices from a vendor’s lookalike address, support replies to users who posted a problem publicly, recruitment approaches to engineers, “your API key is expiring” notices: the possibilities are wide-ranging. That’s why 24 Jev lookalike domains with deliberately configured mail actually presents a higher risk than the total 167 registrations.

Finally, when an AI model is accessed by hostname through an API, a lookalike domain can act as a man-in-the-middle proxy that relays traffic to the real service while logging every prompt, response and key that passes through. The user sees correct answers. The integration keeps working. Detection depends entirely on someone noticing that the hostname is wrong.

## Conclusion

The window in which a brand becomes worth impersonating opens before the brand is ready to defend it, and attempts at impersonation flourish during times of massive public attention. Domain brand protection should be in place for a company as early as possible. By the time it is obviously needed, most of the namespace is already gone.

## Protect your organization

Get in touch or book a free demo.

[Contact sales](/demo)

[Free demo](/demo)

## Related breaches

Learn more about the latest issues in cybersecurity.

[](/breaches/cyber-risks-of-the-2026-world-cup)

#### [Own Goal: Inside the Cyber Risks of the 2026 World Cup](/breaches/cyber-risks-of-the-2026-world-cup)

Free World Cup streams and black-market betting sites are leaking fan data. UpGuard research reveals the hidden cyber risks of the 2026 tournament.

[](/team/greg-pollock)

[Greg Pollock](/team/greg-pollock)

June 30, 2026

[](/breaches/social-insecurity-billions-of-social-security-number-and-passwords)

#### [Social Insecurity: Billions of Social Security Number and Passwords](/breaches/social-insecurity-billions-of-social-security-number-and-passwords)

UpGuard research found a trove of sensitive information in an exposed Elastic database. Getting to the bottom of what it meant led us down an interesting path.

[](/team/greg-pollock)

[Greg Pollock](/team/greg-pollock)

February 18, 2026

[](/breaches/angelsense-data-leak)

#### [Sixth Sense: GPS and AI Data Exposed for Assistive Devices](/breaches/angelsense-data-leak)

UpGuard can now report that it has secured an Elasticsearch database for AngelSense, a GPS tracker for children and adults with special needs.

[](/team/upguard)

[UpGuard Team](/team/upguard)

January 30, 2025

[](/breaches/pta-database)

#### [Stolen Data: National PTA Database Available on Dark Web](/breaches/pta-database)

On May 13th, UpGuard discovered a new set of data recently posted on a prominent dark web forum, this time allegedly belonging to the National Parent Teacher Association.

[](/team/upguard)

[UpGuard Team](/team/upguard)

May 14, 2024

[](/breaches/smarterselect)

#### [Student Applications: How an Education Software Company Exposed Millions of Files](/breaches/smarterselect)

UpGuard can now report that a public Google Cloud Storage bucket containing approximately 1.5 terabytes of data used to administer funding programs for college students has been secured. The bucket belonged to SmarterSelect, a company that provides software for managing the application process for scholarships, grants, and awards. The more than 2.8 million files included documents like transcripts, resumes, personal essays, tax returns, and invoices for approximately 1.2 million applications to funding programs.

[](/team/upguard)

[UpGuard Team](/team/upguard)

November 22, 2021

[](/breaches/power-apps)

#### [By Design: How Default Permissions on Microsoft Power Apps Exposed Millions](/breaches/power-apps)

38 million records were exposed in multiple data leaks resulting from misconfigured Microsoft Power Apps portals. Data included sensitive information such as COVID-19 contact tracing data, COVID-19 vaccination appointments, social security numbers for job applicants, employee IDs, and millions of names and email addresses.

[](/team/upguard)

[UpGuard Team](/team/upguard)

August 23, 2021

[View all breaches](/breaches)

### Sign up for our newsletter

UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.

##### Free instant security score

## How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.

* Instant insights you can act on immediately
* Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities

[Free score](/instant-security-score)
