Typosquatting goes by many names: URL hijacking, domain mimicry and domain typo-squatting, to name a few. However, they all mean the same thing: malicious attackers register domain names similar to popular websites but with common typos and variations.
Typosquatting aims to trick users who mistype the legitimate URL into visiting and using the fraudulent site. It is a widespread practice. In fact, one report found more than 500 squatted domains related to candidates during the 2020 presidential election year. Likewise, there have been more than 150,000 pandemic-themed domain names since December 2019.
Typosquatting leaves individuals vulnerable to identity theft, malware and virus attacks, inappropriate content and more. It also hurts businesses, who miss out on revenue when customers shop typosquatting sites and suffer reputational damage when users have a negative experience.
Organizations must watch out for fraudulent websites and take action when needed. Here is what you need to know about typosquatting and how to protect your business against it.
Visitors typically end up visiting a fraudulent website in two ways:
The websites may try to create the same look and feel as the web pages they’re mimicking to bait users into disclosing personal information, such as login info or credit card details. Bad actors can then use this information, especially if users have the same usernames and passwords on multiple sites so that even unrelated accounts are at risk.
Typosquatting relies on human errors, such as:
Many typosquatting incidents go unnoticed, but there have been some famous cases that gained attention:
Even the largest and most secure corporations must be diligent against typosquatting to ensure it doesn’t compromise customer data or hurt their reputation.
There are many different reasons that hackers use typosquatted domains. Just a few uses include:
The biggest reason hackers use fraudulent websites is to host malicious content or encourage users to download infected files. One study found that over 18% of registered squatting domains were malicious and used to distribute malware or conduct a phishing attack.
By resembling legitimate websites, hackers trick users into providing sensitive information for identity theft, fraudulent transactions and other cybercrimes.
(Avoid phishing attacks, including the more precise spear phishing.)
Some fraudulent websites display ads or use click fraud schemes to generate revenue from unsuspecting visitors. These ads may…
Bad actors siphon web traffic from legitimate websites by registering domain names similar to their competitors. It can be a form of corporate sabotage or a way to get an unfair advantage.
Some typosquatted websites sell counterfeit and knockoff products. These products can harm the reputation of the legitimate brand and trick consumers into buying low-quality items they cannot return.
Some of these domains are used to send spam or phishing emails that appear to come from legitimate sources. By using a domain that closely resembles the real one, attackers can increase the chances that recipients will open and interact with the malicious emails.
Typosquatting can hurt company sales and brand reputations, so organizations must diligently fend off attempts. While any business can be a potential target for typosquatting, certain companies and industries are more vulnerable:
There are multiple steps you should take to protect your business from typosquatting:
Register common misspellings and variations. The first step is stopping bad actors from acquiring the domains in the first place. Proactively register domain names that are common misspellings, variations, or phonetic approximations of your primary domain.
Acquire alternative TLDs. Register your domain name with various TLDs, like .net, .org, and .co, to reduce the likelihood of typosquatters exploiting these alternatives.
Monitor domain registrations. ICANN (Internet Corporation for Assigned Names and Numbers) has a Trademark Clearing House that allows website owners to monitor how their names are used with different domains. Regularly check in to see how names similar to your brand or domain are used.
Implement domain name system security extensions (DNSSEC). DNSSEC will protect your domain from multiple cyber threats, including typosquatting.
Report fraudulent domains. Report typosquatted domains to relevant authorities like ICANN or the domain registrar. They may be able to suspend or remove the fraudulent site.
Pursue legal action. If you discover a typosquatted domain that infringes on your copyright or trademarks, legal action may be necessary to control the domain and prevent further harm. If relevant authorities cannot remove the site, consider getting a lawyer to help.
Educate customers and employees. Raise awareness among your customers and employees about potential typosquatting. Let them know the risks and encourage them to double-check URLs and use a search engine to find your website.
While stopping all typosquatting may be impossible, you can mitigate some risks and better protect your brand, reputation and customers.
Typosquatting is a common malicious practice used for various nefarious purposes, such as phishing, malware distribution, traffic diversion, and more. They pose significant risks to both visitors and businesses.
To protect your business from typosquatting by proactively registering misspellings and variations on your domain name and monitoring registrations. Be prepared to take legal action when necessary and report any suspicious registrations immediately. These strategies can help you better safeguard your reputation, brand, and customers from the various threats posed by typosquatted websites.
See an error or have a suggestion? Please let us know by emailing ssg-blogs@splunk.com.
This posting does not necessarily represent Splunk's position, strategies or opinion.
The Splunk platform removes the barriers between data and action, empowering observability, IT and security teams to ensure their organizations are secure, resilient and innovative.
Founded in 2003, Splunk is a global company — with over 7,500 employees, Splunkers have received over 1,020 patents to date and availability in 21 regions around the world — and offers an open, extensible data platform that supports shared data across any environment so that all teams in an organization can get end-to-end visibility, with context, for every interaction and business process. Build a strong data foundation with Splunk.