Back to Blog
Domain Strategy

The Brand Attack That Started With a Domain You Don't Own

ยท

Every year, Interisle Consulting Group publishes a study on the cybercrime supply chain - the infrastructure criminals use to conduct phishing, malware, and spam attacks at scale. The 2025 edition is not comfortable reading.

19.5 million unique domains were used in cyberattacks between September 2024 and August 2025. That is a 126% increase year-over-year. Criminals registered more than 7.3 million of those domains in bulk - up 177%. And brand names appearing in those registered domains increased 97%.

These are not abstract statistics. They describe a growing, industrialised attack economy that specifically targets the gap between a brand's name and the namespace it controls.

How Your Name Becomes a Weapon

The report identifies four distinct ways criminals exploit branded domains.

The first is brand-plus: a criminal registers brand-uk.com, brand-support.net, or brand-payments.shop. The brand name anchors trust. The modifier - a geography, a service, a product line - looks like something the company might legitimately operate. Most customers have no way of knowing which regional or service domains a brand actually owns, so if it looks right, they trust it.

The second is look-alikes: subtle substitutions in spelling, characters, or phonetics. "rn" for "m". "0" for "o". Cyrillic characters visually indistinguishable from Latin ones. Unlike traditional typosquatting, look-alikes are designed to be clicked, not mistyped. They look right on a quick glance, which is all that is needed on a small screen.

The third is exact-match sprawl: the real brand name, spelled correctly, in a different extension. Brand.shop. Brand.uk. Brand.online. This works because around 75% of domains matching Global 2000 brand names are not owned by the brand itself. In alternative extensions the availability is even greater - and criminals know it.

The fourth is domain swarms: AI-generated, bulk-registered domain sets that rotate when one is suspended. The 2025 report found 7.3 million bulk-registered cybercrime domains, up 177%. Criminals took advantage of discount pricing and minimal registration friction to register thousands of domains in hours, many containing exact brand matches.

These methods compound and layer. A brand-plus domain hosts a look-alike interface. A swarm of exact-match sprawl domains keeps the operation running when individual ones are suspended. The attack surface is not a single domain - it is the entire gap between what a brand name signals and what namespace the brand actually controls.

The Extension Problem

One of the most significant findings for any founder deciding between .com and an alternative extension is how cybercrime distributes across the domain name space.

New generic TLDs hold 12% of the global domain market. They account for 47% of cybercrime domains. That is nearly four times their market share.

By contrast, .com - the largest TLD, open to anyone with no restrictions - showed a 9% decrease year-over-year in its share of cybercrime domains. At 3% of .com's domains involved in cybercrime against a rate of over 10% for seven of the top ten TLDs, the difference in criminal density is material.

This is not a coincidence. The report is explicit: "TLDs with no registration restrictions had the highest composite cybercrime domain score." But pricing and enforcement also matter. The extensions with the lowest cybercrime rates were those with identity verification requirements or nexus obligations. The extensions with the highest rates were the cheapest, easiest to register in bulk, and least policed.

What this means practically: a company operating on .co, .io, .ai, or any alternative extension is operating in a namespace where criminal density is proportionally higher - and where exact-match sprawl in that same extension is more likely to be in criminal hands.

The .co TLD had 251,933 cybercrime domains in the study period, 95% used for spam. For a founder who chose .co because .com was unavailable or too expensive, this is the hidden cost that never appears in a registrar invoice.

Brand Impersonation Is Not a Large-Company Problem

For a long time, the economics of domain-based brand attacks pointed in one direction: target the companies with the most customers, where impersonation yields the highest return. The study's most impersonated brands - the US Postal Service with 85,843 exact domain matches, Coinbase, Amazon, Apple, Facebook - reflect this logic.

But the 2025 report marks a shift. AI has made attack kits cheap to customise and deploy. Domain registration is frictionless and often promotional. The report documents a 59% rise in standalone website infringements from 2022 to 2023, and one major travel platform reported AI-fuelled phishing scams growing 500% to 900% over approximately 18 months.

When attacks cost almost nothing to launch, the selection criteria change. Criminals no longer need to focus exclusively on high-volume brands. A growing e-commerce company, a B2B SaaS product with a loyal customer base, a professional services firm building a reputation in a niche - each carries enough brand trust to make impersonation worthwhile.

The report is direct about the implication: "by the time most SMBs find out they've been targeted, the damage is done."

What Criminals Are Reading From Your Namespace

The 2025 report describes a systematic attack against namespace gaps. Criminals register the .com variant of a .io company. They register the brand-support and brand-login domains that the real company does not own. They register exact matches of brand names across dozens of extensions and configure MX records - the 2025 data found that 42% of branded domains owned by third parties already had MX records set up, meaning they were ready to send email impersonating the brand almost as soon as they were registered.

Every gap in a company's namespace is legible to automated systems scanning for attack surface. A brand that operates on getbrand.io with brand.io and brand.com unregistered is advertising the attack vector. A brand that operates on brand.com with brand.io, brand.co, and brand-support.com registered and redirected is structurally harder to impersonate.

This is not a recommendation to register every possible domain. It is a description of how the attack economy reads namespace. The criminals who registered 7.3 million bulk domains in the last year were not choosing targets randomly. They were scanning for gaps.

The Governance Connection

The technical argument leads directly to the governance one. Domain names are attacked because they are the layer everything else depends on - email, authentication, brand trust, customer access. But in most companies, that layer is the least explicitly owned.

The registrar account often belongs to whoever set it up at launch. The billing email may be a personal address. Multi-factor authentication may be inconsistent. Nobody audits defensive registrations or stress-tests what happens if the domain expires.

CSC's 2024 Domain Security Report found that 72% of Forbes Global 2000 companies have less than half of basic domain security measures in place. The Interisle data shows what criminals do with the other half.

The attack surface is not primarily technical. It is a governance gap dressed as a technical problem. A domain with no explicit owner, no renewal policy, and no defensive registrations in place is not a neutral asset. It is an invitation.

Three Checks Worth Running Now

The Interisle data describes the attack. Three tools address the defence.

Domain Strategy Quiz - a two-minute assessment that scores current domain strategy across credibility, governance, and growth readiness. Most companies find at least one gap they were not aware of.

Domain Governance Generator - generates a board-ready domain governance policy tailored to the organisation, covering ownership, access controls, renewal procedures, and escalation paths.

Domain Technical Health Dashboard - a single-view check covering SSL status, DNSSEC, domain expiry, DNS resolution, email authentication, and payment method validity across all domains.