Security Review

Is cutout.pro legit or a scam?

Our verdict:Suspicious· 55/100

A functional AI editing platform with a history of massive data breaches and poor security transparency.

cutout.proScanned 4h ago
0
Trust score
SUSPICIOUS
Heuristics 100·MT 45
Category tags
ai toolsphoto editing#data harvester90% MT confidence
Warning signals (1)

These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.

View density

Analysis Summary

Threat Intelligence
0/92
All engines report clean
Domain Age
6 years old
Registered Aug 23, 2020
MT Intelligence
Suspicious
Moderate likelihood · 90% confidence
SUSPICIOUS

Warning signs detected

A functional AI editing platform with a history of massive data breaches and poor security transparency. Several risk indicators suggest caution. This site might be legitimate — but treat it as unverified until you can independently confirm.

Website Preview

Screenshot of cutout.pro
LIVE RENDER
cutout.pro

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.

MT Intelligence

Advanced threat intelligence
MT Security Analyst
Moderate scam likelihoodengineMT · Guardiantrust45/100
MT AgentLive web researchVisual inspection
0%
Confidence
The platform is a long-standing business with high traffic and functional AI tools, but it carries a high risk due to its security history. In February 2024, a verified breach exposed over 20 million user records, including names and hashed passwords. Our research shows the company reportedly denied these findings despite independent verification by security researchers. Additionally, a 2023 server misconfiguration leaked millions of user images and logs. While the site is not a 'scam' in the sense of a fake shop, the repeated failure to protect user data makes it a high-risk environment for personal information.
Full dossier
Analysis complete

Page Content

The site offers a comprehensive suite of AI-powered tools including background removal, image restoration, and video enhancement. It features a professional layout with clear pricing, API documentation, and links to mobile apps and Shopify plugins.

Infrastructure

The domain is hosted on a reputable infrastructure with a valid SSL certificate issued by Amazon. It maintains a high global traffic rank, indicating a large and active user base.

Domain History

Registered over five years ago, the domain history aligns with the established business operations of LibAI Lab in Hong Kong. There is no evidence of brand impersonation or cloning.

Web Reputation

The site's reputation is polarized. While professional review sites give it high marks for utility, consumer forums and security databases are filled with reports of data leaks and subsequent spam. The lack of transparency regarding the 2024 breach is a major red flag for security-conscious users.
Risk Factors
5
  • Verified data breach in February 2024 exposing 20 million user records.
  • Company reportedly denied a confirmed security incident, showing poor transparency.
  • Previous 2023 server misconfiguration leaked user images and internal logs.
  • Multiple user reports on an independent review aggregator and Reddit linking the site to increased spam and 'dark web' alerts.
  • No phone number listed for direct customer support.
Positive Signals
4
  • Domain has been active for over 5 years.
  • Clean results from 92 antivirus engines in our network.
  • High global traffic ranking suggests a functional and popular service.
  • Positive professional reviews on platforms like G2 for tool performance.
AI Recommendation
If you must use this service, do not use your primary email address or a password you use elsewhere. Monitor your accounts for unauthorized access and consider using a disposable email service.
Next-gen fraud intelligence
Evidence-backedCross-checked

Web Research Findings

Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for cutout.pro, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.

Domain age
5.8 yrs
Registered Aug 2020
Business registration
Active · Hong Kong
Site traces back to an actively registered business.
Clone check
Not a clone
No well-known site's layout or branding detected here.
Typosquat check
No look-alike match
The domain doesn't resemble any well-known brand's spelling.
Web mentions
3 scam reports · 3 positive
Key findings
7 headline facts from open-web research
  • Domain registered approximately 2129 days ago (~2019-2020), matching the company's stated founding in 2018 by LibAI Lab in Hong Kong.
  • Major data breach in February 2024 exposed ~20 million user records including emails, names, IP addresses, and salted MD5 password hashes; data was leaked on BreachForums and verified by Troy Hunt/HIBP and BleepingComputer.
  • Company reportedly denied the breach, calling claims a 'clear scam' or fraudulent, despite independent verification of leaked emails triggering password resets.
  • Prior 2023 server misconfiguration also leaked user images, usernames, and ~22 million log entries according to Cybernews.
  • Scamadviser concludes it is "legit and safe for consumers to access" with valid SSL and safe DNS labels, but notes negative reviews detected.
  • Trustpilot has ~36 reviews with mixed feedback; some users link the breach to ongoing spam, hacking, and dark web exposure of their emails.
  • Actively used AI photo/video editing tool with positive mentions for background removal and e-commerce workflows; offers apps, pricing plans (credit-based and subscriptions), and claims 25K+ business users.
Scam reports (3)
Direct quotes from public scam databases, forums, and news.
  • Trustpilotopen

    ""Don't use this app - data leak" "As everybody else here is saying, this site is a scam, i also got hacked and i finally found out it was by this shit scam site thanks to MalwareBytes. I'm still getting spam mails""

  • Redditopen

    "my email entered the dark web because cutout.pro"

  • MobileAppDailyopen

    "Cutout Pro suffered a verified data breach in February 2024 that exposed over 41 million user records, and the company denied the incident despite independent verification by Have I Been Pwned."

Positive reviews (3)
Quotes indicating the site is legitimate.
  • Cutout.pro siteopen

    "We are an e-commerce company. Before using cutout.pro, we had to remove background from pictures all night through. Now that I have this software, everything is as easy as finger snapping."

  • "Cutout.pro has been rated 4.4 stars by 13 verified reviews on G2."

  • VanceAI reviewopen

    "Is Cutout.Pro safe to use? Absolutely. It deletes images after a certain period of time"

Business registration
Status: active · Hong Kong

Operated by LibAI Lab (previously picup.ai), founded 2018/2019 in Hong Kong by Yong T / Jeff Tang. Address listed as 6/F Manulife Place, 348 Kwun Tong Road, Kowloon, HK. Unfunded private company.

Research summary
Narrative write-up from our AI analyst, grounded on the facts above
Our research confirmed a major data breach in early 2024 that exposed millions of user records, including emails and salted MD5 password hashes. Security researchers and news outlets like BleepingComputer verified the leak, though the company reportedly dismissed the claims. Users on Reddit and an independent review aggregator have reported their data appearing on the dark web shortly after using the service. Conversely, professional users on G2 praise the platform's AI capabilities for e-commerce workflows.

Antivirus Engines

Clean pass · verified
Clean across 92 engines

We cross-check every URL against our antivirus network of 92 malware and blacklist engines. None of them flagged this URL in the last scan.

0Malicious0Suspicious61Harmless92Engines
Clean
Kaspersky
Clean
Bitdefender
Clean
Microsoft
Not in pass
ESET-NOD32
Not in pass
Avira
Not in pass
Sophos
Clean
Fortinet
Clean
Google Safebrowsing
Clean
Emsisoft
Clean

No engine detections. The URL passed every antivirus and blacklist engine we queried in this scan. Stay vigilant — AV coverage is only one signal among many.

Security Scans

Blacklist Check
Not flagged on major threat lists

Checked against the major public blocklists used by browsers and security tools — no hits.

Contact Verification

We fetched the page and looked for real-world contact details. Legitimate businesses almost always publish an email on their own domain, a phone number, and a postal address. Scam shops usually don't.

What We Found
Has a contact email on its own domain
Emails on site's domaintech@cutout.pro
Phone numbersNone
Postal addressPresent
Linked social profiles5
Signal Summary
Contact details look reasonable
  • No phone number listed on the page.
  • Contact email on the site's own domain (tech@cutout.pro).
  • Postal address visible on the page.
  • Links to 10 social profiles.

Domain & Encryption

Domain History
Age6 years old
RegistrarAmazon Registrar, Inc.
RegisteredAug 23, 2020
ExpiresAug 23, 2027
Owner privacyVisible
Encryption Certificate
StatusValid
ProtocolTLSv1.2
IssuerAmazon · Amazon RSA 2048 M04
ExpiresDec 22, 2026 (182d)
Self-signedNo
Hosting & Technology
HostingAmazon Technologies Inc.
Server locationUS
Web servernginx
Platform / CMSWordPress
PopularityTop 100k worldwide

Redirect Chain

Hops
2
Cross-domain
Yes
Lookalike
No
Punycode
No
  • 1301http://cutout.pro/
  • 2301https://cutout.pro/
  • 3200https://www.cutout.pro/cross-domain

Server Reputation

Abuse Intelligence
Confidence score0%
Reports on file0
ISPAmazon Technologies Inc.
Usage typeContent Delivery Network

Proceed with caution

Our automated review flagged enough risk that you should treat this site as unverified.

  • Treat cutout.pro as unverified

    Do not enter credentials or send money until you have independently verified the business.

  • Verify the business through independent channels

    Check the company's social profiles, registry records, and search for recent news or reviews that are not hosted on the site itself.

  • Never use irreversible payment methods

    Crypto, gift cards, wire transfers, and cash apps offer zero buyer protection. Use a credit card or PayPal if you must pay.

  • Share your experience

    If you have additional context, drop a comment below or post on the MalwareTips forum.

    Open

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
Not listedCheck ↗
VirusTotal
Not listedCheck ↗
AbuseIPDB
Not listedCheck ↗

Referenced Domains

Outbound domains this page links to or loads resources from. Each links to its own security scan.

Safety FAQ

Common questions about this site, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.

  • Our automated security review marked cutout.pro as suspicious. Several warning signs were detected; it may still turn out legitimate, but you should verify it through independent channels before trusting it with money or credentials.
  • cutout.pro currently scores 55/100 on our trust scale. We found enough warning signals to recommend caution. Verify the site through independent channels before entering credentials or money.
  • Yes. cutout.pro presents a valid TLSv1.2 certificate issued by Amazon · Amazon RSA 2048 M04, expiring in 182 days. Note that SSL only encrypts the connection — it does not guarantee that the site itself is trustworthy.
  • cutout.pro is 5.8 years old, registered on 8/23/2020 through Amazon Registrar, Inc.. Scam domains are often freshly registered — a site under 6 months old warrants extra caution.
  • No. All 92 antivirus engines in our malware network report cutout.pro as clean.
  • No. cutout.pro is not currently listed on the major browser blocklist feeds that modern browsers use.
  • cutout.pro resolves to an IP operated by Amazon Technologies Inc. in US (usage type: Content Delivery Network). Hosting location alone doesn't make a site good or bad, but unusual geography for a brand's claimed country is one of many signals we weigh.
  • Yes. cutout.pro sits in the global top-100k on Cloudflare Radar, which means it has substantial real-world traffic. That does not automatically make it safe, but established brands almost always rank here and throwaway scam domains almost never do.

Final Verdict

0
Trust / 100
Final Verdict·cutout.pro
SUSPICIOUS

Cutout.pro is a legitimate AI photo editing platform that has been severely compromised by major data breaches. While the tools function as advertised, the company's handling of user data and its denial of verified security incidents pose a significant risk to your personal information. Use with extreme caution and avoid using primary email addresses or passwords.

If you must use this service, do not use your primary email address or a password you use elsewhere. Monitor your accounts for unauthorized access and consider using a disposable email service.

AV engines
92
MT passes
2
Net signals
0
Scan another URL
Security review completemalwaretips.com/url-scan
Recently scanned

Other Suspicious reports

Browse all reports
Community review

User reviews & comments(0)

Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.

Loading…
Loading comments…
This report is generated automatically by combining threat intelligence, domain signals, and an AI security analyst. It is informational, not legal advice. Always use your own judgement before sharing personal information or money online.