Truviss

705 Domains: Anatomy of a Brand Impersonation Attack

Home/Blog/705 Domains: Anatomy of a Brand Impersonation Attack
Domain & Phishing

705 Domains: Anatomy of a Brand Impersonation Attack

Catch the pattern before the damage window stays open for months

Truviss’s Domain Scanner watches new registrations against your brand’s name, correlating patterns across domains, not just checking one at a time.

Book a demo
Phishing domain attack case study cover
TL;DR
  • 705 fraudulent domains targeting L’Oréal were registered in under three weeks, all combining the brand name with job-related terms, and were already being used in employment scams.
  • The attack was identifiable as one coordinated case, not 705 unrelated nuisances, once the registrar, timing and contact-detail pattern across all of them was correlated.
  • A second real case, Microsoft’s RaccoonO365 operation, shows a more visually convincing variant: homoglyph domains like “rn” standing in for “m”, which defeated a quick glance and helped steal 5,000+ credentials across 94 countries.
  • UDRP secured a complete legal outcome for L’Oréal, but only after a real damage window, the faster route for active harm is a direct hosting-provider abuse report.

Seven hundred and five. That’s how many fraudulent domain names were registered targeting L’Oréal between 23 December 2025 and 15 January 2026, a span of roughly three weeks. Every one of them combined the L’Oréal name with job-related terms, applicationloreal.com, careerexperiencehubloreal.online, lorealhiringnetwork.com among the examples on record, and the domains were already being used in connection with employment-related scams by the time the case reached resolution. Fifty-two different names were listed as the registrants. L’Oréal’s own representatives argued in the filing that the real number of people behind it was likely one or two.

The pattern that gave it away

Individually, any one of these 705 domains might have looked like a one-off scam, easy to miss among the routine noise of brand-adjacent junk domains that get registered every day. What made this identifiable as a single coordinated attack rather than 705 unrelated nuisances was the pattern underneath the registrant names: all of them went through only two domain registrars, many shared the same email address, and all were registered within the same tight three-week window. Fifty-two names on paper, but one registration fingerprint underneath all of them.

L’Oréal pursued this through the Uniform Domain-Name Dispute-Resolution Policy, UDRP, filed with WIPO. The panel ordered all 705 domains cancelled. That’s a real, complete resolution, but it’s worth being honest about the timeline: UDRP cases typically run around two months from filing to decision, which means the practical damage window, domains actively impersonating an HR department, chasing job applicants for personal data or attempting to redirect supplier payments, was open well before any of the 705 domains were ordered offline.

A second mechanism: the homoglyph attack

Not every lookalike domain relies on an obvious misspelling. Microsoft has been tracking an operation known as RaccoonO365 since at least July 2024, a phishing kit built specifically to steal Microsoft 365 credentials, that has taken at least 5,000 logins from victims across 94 countries. Working with Cloudflare and under a court order from the Southern District of New York, Microsoft seized 338 websites tied to the operation to disrupt its infrastructure. Reporting on the operation has described its use of homoglyph-style domains, near-identical character substitutions such as “rn” standing in for “m”, built to survive a quick visual glance that would catch a cruder misspelling instantly.

This is the same underlying threat as L’Oréal’s case, a domain built to be mistaken for a real brand’s, executed with a more visually convincing technique than an obvious typo. Both fall under the same category of typosquatting and phishing domain abuse, but the homoglyph variant specifically defeats the “does this look roughly right” check most people rely on without thinking about it.

See how Truviss correlates domain registrations against your brand’s name, catching the pattern, not just one domain at a time.

Explore Domain Scanner

Why the registration pattern matters more than any single domain

The lesson from L’Oréal’s case isn’t that one domain slipped through, it’s that 705 individually plausible-looking domains only became visible as one attack once someone connected the registrar, timing and contact-detail pattern across all of them. A brand watching for isolated typosquats one at a time would catch some of these eventually, through user reports or chance discovery, but the coordinated wave itself, the thing that made this newsworthy and legally actionable as a single case, only shows up when registrations are correlated against each other, not evaluated individually.

Two response routes, and when each applies

Once a suspicious registration pattern is confirmed, there are two genuinely different paths, and picking the wrong one costs time that matters. UDRP is the thorough, comparatively affordable route for a confirmed bad-faith registration, roughly two months to resolution, filing fees starting in the low thousands, built around a three-part test of confusing similarity, no legitimate interest, and bad-faith registration or use. It’s the right tool for securing a complete, permanent outcome like L’Oréal’s mass cancellation.

When a domain is actively phishing right now, credentials or personal data being harvested in real time, two months is far too slow to stop ongoing harm. A direct abuse report to the domain’s hosting provider can pull an actively malicious site offline in hours rather than weeks, trading a slower, more complete legal remedy for immediate harm reduction. The right call depends on how urgent the active harm is, not on which route looks more thorough on paper, and the two aren’t mutually exclusive: a fast abuse report to stop the bleeding, followed by a UDRP filing to secure the domains permanently, is a reasonable sequence rather than a choice between the two.

What this means for a brand’s own monitoring

It’s tempting to read the L’Oréal case as proof that only very large, high-profile brands get targeted at this scale. The more accurate reading is that a company with L’Oréal’s resources still needed to catch a 705-domain wave by recognising a registration pattern across weeks, and still had a real damage window before the UDRP process concluded. A smaller brand with fewer resources to notice that pattern manually has even less margin. The attacker’s cost to register a lookalike domain barely changes whether the target is a global conglomerate or a mid-sized regional brand. What changes is whether anyone is watching new registrations closely enough, and correlating them against each other, to catch the pattern before the damage window stays open for months.