Tony Kirsch is the commercial director and cofounder of the Brand Safety Alliance (a GoDaddy Registry Initiative).gettyIn 2025, nearly 20 million unique domains were used in more than 26 million malware, phishing and spam attacks. Pause and think about that for just a moment: that’s nearly 20 million domains implicated in cybercrime around the world—more than 54,000 domains every day.So, is this normal? And more importantly, why is this happening? In short: AI and other developments have made domain-based attacks so quick and easy to launch that bad actors can attack at an unbelievable scale and pace.Some attacks work using low-cost, random-character, nonsense domains. However, many leverage the trust inherent in household brand names to fool customers, steal money, hack digital systems and damage brand reputations. As I shared previously for the Forbes Technology Council, this isn’t restricted to multinationals. SMBs are increasingly becoming the target. How Attackers Use Domains To Hijack A Brand Bad actors have developed four distinct methods for exploiting branded domains. Understanding them is the first step to recognizing when they’re being used against you. 1. Brand-Plus These domains typically include a brand name followed by an additional term or modifier, such as a geographic region, service or product/sub-brand—for example, brand-uk.com, brandmexico.shop or brand-support.site.They work because they look like they could be legitimate. The brand name creates an anchor of trust and distracts users from the other parts of the domain. Customers have no way of knowing which regional sites or service portals a brand actually operates, so if it looks right, they trust it. That's what the attackers are counting on. 2. Look-alikes Look-alike domains use subtle tricks of spelling, characters and phonetics to impersonate a brand: doubled letters, swapped vowels, visually confusable characters or non-Latin characters, such as using “rn” for “m,” “1” for “I,” “0” for “o,” or Cyrillic “а” in place of the Latin “a.”Where traditional typosquatting relies on users mistyping the domain themselves, look-alikes are designed to be clicked. They look right on quick glance, so users believe they’re in the right place—perfect for small devices and that SMS scam that duped your grandmother.3. Exact-Match Sprawl Exact-match sprawl uses a brand’s real name, spelled correctly, but registered in a different domain extension—for example, brand.shop, brand.uk or brand.online. This relies on the fact most brands don’t own their trademark in every domain extension. In fact, around 75% of domains matching Global 2000 brands (six characters or longer) are not owned by the brand. 4. Domain Swarms This strategy uses volume to escape detection and maximize impact. Using AI and script-based tools, attackers generate and register domains in bulk, often using templated structures that include numbers or special characters. This could look like brand123.com, brand345.tech or brand-secure-01.top.With hundreds of interchangeable domains, attackers can rotate as needed. If one is suspended, they move on to the next. Domain swarms often take advantage of discount promotions to get lots of domains as cheaply as possible. They do use brands to increase recognition, but it's often less necessary because of the nature of the scams they’re used for.Particularly with the proliferation of AI, this technique is becoming more common. Bulk criminal registrations of domains grew 177% between 2024 and 2025. How Fraudulent Domains Become Cyber Crime What makes this landscape genuinely dangerous is that attackers don’t follow a single playbook. They combine these methods, layer them and adapt in real time. This creates complex and multi-vectored scams that build on the foundation of brand trust. Email Attacks Business email compromise and email abuse are the most common direct attack vectors using branded domains. Business email compromise is a source of major losses to business—approximately $2.77 billion in the U.S. in 2024. Brand-plus and exact-match sprawl often do the heavy lifting here. A domain that looks legitimate on a casual glance is enough to convince employees, customers and suppliers to trust an email and act on it. Domain swarms keep the operation running when one domain is suspended, rotating in a replacement before the next phishing email is even sent.The scale of readiness is alarming. CSC found that 42% of branded domains owned by a third party already have MX records configured of the large volume of branded domains owned by third parties, meaning they’re already set up for email use almost as soon as they’re registered. Fraudulent Pages And Forms Using look-alikes to deliver traffic from misreads and mistypes, exact-match sprawl then ensures there are legitimate-looking domains to use for hosting. Then fraudulent forms and sites capture purchase details, personal data and other information for malicious use. Generative AI has cut the cost of building these attacks. Standalone website infringements rose 59% from 2022 to 2023, and Booking.com reported AI-fuelled travel scams grew 500% to 900% over approximately 18 months. The barrier to entry for attackers has effectively disappeared, while the consequences remain as serious as ever. Enterprise Isn’t The Only Target For a long time, the economics of domain abuse pointed in one direction: target the biggest brands, where the returns justify the effort. Now, the landscape has changed. With attacks cheaper to launch and easier to scale, targets don’t have to be selected so carefully. Bad actors can cast a wide net and hit hundreds of brands simultaneously, and SMBs are increasingly among them. A growing e-commerce brand, business with a loyal local following or company building a recognizable name in its niche all carry the kind of customer trust that makes impersonation worthwhile. Combined with the relative lack of infrastructure to detect or respond to an attack quickly, by the time most SMBs find out they’ve been targeted, the damage is done. Knowing what these attacks look like is the first step. What you do next determines how much damage they cause. In my next article, I’ll explore what SMB leaders can do to defend their brand, and what to do in the critical hours after discovering you’ve been targeted.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
The 4 Key Types Of Fraudulent Domains Used To Attack Brands
AI and other developments have made domain-based attacks so quick and easy to launch that bad actors can attack at an unbelievable scale and pace.







