Truviss

Tag: Domain Monitoring

  • 705 Domains: Anatomy of a Brand Impersonation Attack

    705 Domains: Anatomy of a Brand Impersonation Attack

    Home/Blog/705 Domains: Anatomy of a Brand Impersonation Attack
    Domain & Phishing

    705 Domains: Anatomy of a Brand Impersonation Attack

    Catch the pattern before the damage window stays open for months

    Truviss’s Domain Scanner watches new registrations against your brand’s name, correlating patterns across domains, not just checking one at a time.

    Book a demo
    Phishing domain attack case study cover
    TL;DR
    • 705 fraudulent domains targeting L’Oréal were registered in under three weeks, all combining the brand name with job-related terms, and were already being used in employment scams.
    • The attack was identifiable as one coordinated case, not 705 unrelated nuisances, once the registrar, timing and contact-detail pattern across all of them was correlated.
    • A second real case, Microsoft’s RaccoonO365 operation, shows a more visually convincing variant: homoglyph domains like “rn” standing in for “m”, which defeated a quick glance and helped steal 5,000+ credentials across 94 countries.
    • UDRP secured a complete legal outcome for L’Oréal, but only after a real damage window, the faster route for active harm is a direct hosting-provider abuse report.

    Seven hundred and five. That’s how many fraudulent domain names were registered targeting L’Oréal between 23 December 2025 and 15 January 2026, a span of roughly three weeks. Every one of them combined the L’Oréal name with job-related terms, applicationloreal.com, careerexperiencehubloreal.online, lorealhiringnetwork.com among the examples on record, and the domains were already being used in connection with employment-related scams by the time the case reached resolution. Fifty-two different names were listed as the registrants. L’Oréal’s own representatives argued in the filing that the real number of people behind it was likely one or two.

    The pattern that gave it away

    Individually, any one of these 705 domains might have looked like a one-off scam, easy to miss among the routine noise of brand-adjacent junk domains that get registered every day. What made this identifiable as a single coordinated attack rather than 705 unrelated nuisances was the pattern underneath the registrant names: all of them went through only two domain registrars, many shared the same email address, and all were registered within the same tight three-week window. Fifty-two names on paper, but one registration fingerprint underneath all of them.

    L’Oréal pursued this through the Uniform Domain-Name Dispute-Resolution Policy, UDRP, filed with WIPO. The panel ordered all 705 domains cancelled. That’s a real, complete resolution, but it’s worth being honest about the timeline: UDRP cases typically run around two months from filing to decision, which means the practical damage window, domains actively impersonating an HR department, chasing job applicants for personal data or attempting to redirect supplier payments, was open well before any of the 705 domains were ordered offline.

    A second mechanism: the homoglyph attack

    Not every lookalike domain relies on an obvious misspelling. Microsoft has been tracking an operation known as RaccoonO365 since at least July 2024, a phishing kit built specifically to steal Microsoft 365 credentials, that has taken at least 5,000 logins from victims across 94 countries. Working with Cloudflare and under a court order from the Southern District of New York, Microsoft seized 338 websites tied to the operation to disrupt its infrastructure. Reporting on the operation has described its use of homoglyph-style domains, near-identical character substitutions such as “rn” standing in for “m”, built to survive a quick visual glance that would catch a cruder misspelling instantly.

    This is the same underlying threat as L’Oréal’s case, a domain built to be mistaken for a real brand’s, executed with a more visually convincing technique than an obvious typo. Both fall under the same category of typosquatting and phishing domain abuse, but the homoglyph variant specifically defeats the “does this look roughly right” check most people rely on without thinking about it.

    See how Truviss correlates domain registrations against your brand’s name, catching the pattern, not just one domain at a time.

    Explore Domain Scanner

    Why the registration pattern matters more than any single domain

    The lesson from L’Oréal’s case isn’t that one domain slipped through, it’s that 705 individually plausible-looking domains only became visible as one attack once someone connected the registrar, timing and contact-detail pattern across all of them. A brand watching for isolated typosquats one at a time would catch some of these eventually, through user reports or chance discovery, but the coordinated wave itself, the thing that made this newsworthy and legally actionable as a single case, only shows up when registrations are correlated against each other, not evaluated individually.

    Two response routes, and when each applies

    Once a suspicious registration pattern is confirmed, there are two genuinely different paths, and picking the wrong one costs time that matters. UDRP is the thorough, comparatively affordable route for a confirmed bad-faith registration, roughly two months to resolution, filing fees starting in the low thousands, built around a three-part test of confusing similarity, no legitimate interest, and bad-faith registration or use. It’s the right tool for securing a complete, permanent outcome like L’Oréal’s mass cancellation.

    When a domain is actively phishing right now, credentials or personal data being harvested in real time, two months is far too slow to stop ongoing harm. A direct abuse report to the domain’s hosting provider can pull an actively malicious site offline in hours rather than weeks, trading a slower, more complete legal remedy for immediate harm reduction. The right call depends on how urgent the active harm is, not on which route looks more thorough on paper, and the two aren’t mutually exclusive: a fast abuse report to stop the bleeding, followed by a UDRP filing to secure the domains permanently, is a reasonable sequence rather than a choice between the two.

    What this means for a brand’s own monitoring

    It’s tempting to read the L’Oréal case as proof that only very large, high-profile brands get targeted at this scale. The more accurate reading is that a company with L’Oréal’s resources still needed to catch a 705-domain wave by recognising a registration pattern across weeks, and still had a real damage window before the UDRP process concluded. A smaller brand with fewer resources to notice that pattern manually has even less margin. The attacker’s cost to register a lookalike domain barely changes whether the target is a global conglomerate or a mid-sized regional brand. What changes is whether anyone is watching new registrations closely enough, and correlating them against each other, to catch the pattern before the damage window stays open for months.

  • GLP-1 Brand Impersonation: The AI Ad Scam Network

    GLP-1 Brand Impersonation: The AI Ad Scam Network

    Home/Blog/GLP-1 Brand Impersonation: The AI Ad Scam Network
    Ad Misuse

    GLP-1 Brand Impersonation: The AI Ad Scam Network

    See every fake ad, storefront and listing wearing your brand’s name

    Book a demo to see how Truviss detects brand impersonation across ads, domains and marketplace listings in one dashboard.

    Book a demo
    GLP-1 Brand Impersonation: The AI Ad Scam Network cover
    TL;DR
    • 2026’s wave of fake GLP-1 ads isn’t just a consumer-fraud story: every fake ad, storefront and listing runs under a real healthcare brand’s name without permission.
    • The scam network spans three surfaces that reinforce each other: AI-generated deepfake ads, lookalike storefront domains, and counterfeit marketplace listings.
    • Manual review can’t keep pace once AI-generated ad variants scale, and regulators are increasingly treating this as a counterfeit supply-chain issue, not just a consumer-warning one.
    • Catching the full pattern needs detection across all three surfaces at once: the ad, the domain and the listing, not just one of them.

    Weight-loss drug scams made headlines across 2026 for the money and health harm they caused: fake AI-generated ads, fake online pharmacies, and counterfeit pens sold under real brand names. The Better Business Bureau logged more than 170 complaints tied to a single AI-generated video, one purporting to show Oprah Winfrey endorsing a “pink salt” weight-loss drink, with victims reporting losses of $300 and more. Every one of those stories gets told as a consumer-fraud warning: watch the red flags, verify the seller, don’t pay with crypto or gift cards.

    What gets missed in that framing is what’s actually happening to the brand whose name got used. A fake ad, a fake storefront and a counterfeit listing selling under a real pharma or healthcare brand’s name isn’t just a scam that happened to a patient. It’s a brand impersonation and counterfeit distribution problem, running at a scale that manual monitoring was never built to catch.

    How the network actually works

    This isn’t one bad actor running one scam. It’s three surfaces working together, each one making the next look more legitimate.

    It typically starts with an ad. The Better Business Bureau and Today.com have both documented a rise in AI-generated ads using deepfake video and images of celebrities, doctors and other trusted figures to promote GLP-1-type products. These ads run on the same platforms as any legitimate paid campaign: Google Search, Facebook, Instagram.

    Click through, and the ad usually lands on a storefront designed to look like a real pharmacy or the brand’s own site. This is the domain-level layer: a lookalike or phishing-style URL, built to survive a quick glance.

    From there, the actual product gets sold, either through that storefront directly or through a marketplace listing or a social media seller messaging buyers privately. These listings frequently use stolen product photography and fabricated testimonials, and the products themselves range from real drugs sold through unauthorised channels to “research chemical” peptides with no verified content at all.

    Each layer reinforces the one before it. The ad looks credible because it links to a storefront that looks real. The storefront looks real because it shows product photos that look identical to the genuine article. By the time a buyer is entering payment details, they’ve been walked through three separate, coordinated impersonations of a brand that had no part in any of it.

    Why this is the brand’s problem, not just the patient’s

    The financial and health harm in these stories falls on the person who got scammed. One case reported to the Better Business Bureau involved a consumer who paid a $32 “membership fee,” then faced repeated $670 charge attempts even after trying to cancel. Regulators have also flagged the physical risk: California Attorney General Rob Bonta, as part of a 38-state coalition letter to the FDA in February 2025, urged faster action against manufacturers of counterfeit weight-loss drugs, citing documented health harm from unverified products.

    But the reputational and legal exposure lands somewhere else entirely: on the brand whose name was on the ad, the storefront, or the packaging. A search for that brand name now surfaces scam warnings, complaint threads and news coverage the brand had no hand in creating. Regulatory attention is increasingly framing this as a counterfeit supply-chain enforcement issue, not purely a consumer-education one, which means the brand’s exposure isn’t just reputational anymore.

    Manual review can’t keep pace with this. A team checking flagged ads one at a time is already behind the moment a scam network starts generating AI variants of the same ad at scale, each one slightly different, each one needing its own review.

    What detection actually needs to catch

    Because the scam network spans three surfaces, a brand only ever sees part of the picture if its monitoring only covers one of them.

    Catching the ad itself. Fake or brand-misuse ads need to be flagged on the platforms where they actually run, Google, Facebook and Instagram, before they drive more traffic toward a fake storefront. Truviss’s Ads Scanner checks ad copy, creative and destination pages for brand-term and trademark misuse across these three channels, routing verified fake ads into a case management dashboard for the brand’s team to act on.

    See how Truviss’s Ads Scanner detects brand-misuse ads on Google, Facebook and Instagram.

    Explore Ads Scanner

    Catching the storefront. The lookalike or phishing-style domain impersonating the brand or an authorised pharmacy is the layer that makes the ad look credible in the first place. Truviss’s Domain Scanner continuously monitors for these lookalike and phishing domains, so a fake storefront gets flagged before it has time to build up the reviews and traffic that make it look legitimate.

    Catching the listing. A marketplace listing selling a counterfeit product under the brand’s name needs to be checked against the brand’s actual catalogue, not just against patterns learned from other fake listings; a generated variant can dodge a pattern built from other fakes, but it can’t fabricate a real product that matches the brand’s genuine SKU data. That’s what SKU-level matching is for, and it’s the core of how Truviss’s Marketplace Scanner verifies suspected counterfeit listings.

    The pattern repeats beyond GLP-1

    This specific version of the scam, AI-generated ads feeding fake storefronts feeding counterfeit listings, isn’t unique to weight-loss drugs. It’s a template that shows up anywhere a high-demand, high-price product creates enough incentive for brand impersonation to pay off. Treating an incident like this as three separate problems, an ad issue here, a domain issue there, a listing issue somewhere else, means missing how each one is built to reinforce the others. A counterfeit listing rarely shows up alone; it usually has an ad and a storefront working alongside it, wearing the same brand’s name.

  • Domain Phishing: The Complete Guide (2026)

    Domain Phishing: The Complete Guide (2026)

    Home/Blog/Domain Phishing: The Complete Guide (2026)
    Domain & Phishing

    Domain Phishing: The Complete Guide (2026)

    Domain Phishing: The Complete Guide cover
    TL;DR
    • APWG recorded 3.8 million unique phishing attacks in 2025, up from 3.76 million in 2024, and most of these rely on a lookalike domain to appear legitimate.
    • The average phishing site stays live for only around 12 hours before takedown (BlackBerry, 2025), which is why continuous monitoring beats periodic manual checks.
    • FBI IC3 recorded $215.8 million in direct phishing losses in 2025, up sharply from $70 million the year before.
    • A documented detect, verify, enforce process against your own domain and brand assets closes phishing domains faster and gives you an evidence trail if a case escalates.

    What domain phishing and typosquatting actually look like

    Domain phishing almost always starts with typosquatting, a domain registered on a common misspelling or visual variant of a real brand’s web address. A swapped letter, a doubled character, a numeral standing in for a similar-looking letter. The domain is then built to mirror the real site closely enough to pass a quick glance, most often cloning a login or checkout page to harvest credentials or payment details under the brand’s name.

    APWG recorded 3.8 million unique phishing attacks across 2025, up from 3.76 million in 2024 (APWG, Phishing Activity Trends Report, Q4 2025). A large share of these depend on exactly this pattern: a domain close enough to a trusted brand’s real address that a customer doesn’t look twice before entering sensitive information.

    Why lookalike domains are so effective

    A lookalike domain doesn’t need to fool a security team, it only needs to fool a customer moving quickly, usually someone who clicked a link in an email or a text message and is already expecting to land on the brand’s real site. Pairing the domain with a valid SSL certificate removes the one browser warning most people would actually notice, so the page looks legitimate at a glance even to someone paying reasonable attention.

    Phishing sites also don’t stay up for long. The average phishing site is live for only around 12 hours before it’s taken down (BlackBerry, 2025), which sounds reassuring until you consider how much damage a convincing fake can do to the right audience in that window, and how quickly a new one can go up to replace it.

    The real cost of a phishing domain using your brand

    The most direct cost lands on customers, not the brand: stolen credentials, stolen payment details, and in many cases money sent to an account that was never the brand’s own. But the brand absorbs the fallout regardless. Customers who realise they’ve been phished under a brand’s name associate the experience with that brand, not with the criminal who registered the domain, and support teams end up fielding complaints about a page the brand never built.

    Phishing losses reported to the FBI’s Internet Crime Complaint Center reached $215.8 million in 2025, up from $70 million the year before (FBI IC3, 2025 Internet Crime Report), and that figure only captures reported financial losses, not the harder-to-measure cost of customer trust.

    Manual domain watching versus continuous monitoring

    Most brands start out checking for lookalike domains the way they check for most things online: occasionally, and manually, usually after a customer reports a suspicious email or a phishing page turns up in a search. This catches the domains that are already active and already causing complaints.

    What it misses is the domain that’s registered today and weaponised next week. New domains can be registered, built out to mimic a real site, and pushed into a phishing campaign within days, well inside the gap between manual checks. Continuous monitoring closes that gap by watching new domain registrations and DNS activity for patterns that match a brand’s name, rather than waiting for a phishing page to surface on its own.

    Building a domain takedown process that holds up

    A workable process against domain phishing generally follows the same three stages as any other brand protection channel:

    Detect continuously. Monitor new domain registrations and lookalike variants of your own domain and brand name, not just an occasional manual search.

    Verify against your real domain portfolio and known partners, so a legitimate regional site or an approved reseller’s domain isn’t mistaken for an infringement.

    Enforce with a documented trail, filed with the registrar or host, logged with enough detail (when it was found, what made it identifiable as a phishing clone) to support further action if the case escalates.

    See how Truviss’s Domain Scanner catches lookalike and typosquatted domains the moment they’re registered.

    Explore Domain Scanner

    Common mistakes brands make

    The most common mistake is only reacting once a phishing domain is already active and customers are already complaining, rather than watching for the registration itself. By the time a phishing page is live and indexed, some damage is usually already done.

    A second is assuming a domain has to be an exact match to be a threat. Attackers deliberately use near-misses, a swapped character, an added hyphen, a different top-level domain, specifically so the domain doesn’t show up in a simple exact-match search.

    A third is treating a single takedown as the end of the problem. A determined phishing operation will often re-register a near-identical domain shortly after the first one is taken down, which is why ongoing monitoring matters more than any single enforcement action.

    Getting started

    Start by mapping the domain variations most likely to be used against your brand, common misspellings, added or swapped characters, alternate top-level domains, then put continuous monitoring in place against that list rather than relying on customers or search results to surface the next one. Once detection is running, pair it with the same evidence-backed takedown process used for online brand protection more broadly, so enforcement is consistent regardless of which channel a threat shows up on first.

    Frequently asked questions

    How can I tell if someone has registered a phishing domain using my brand?

    Manually searching common misspellings of your domain will catch some cases, but continuous monitoring of new domain registrations against your brand name is what catches a domain before it’s actively being used in a campaign.

    Is registering a domain to impersonate another brand illegal?

    Registering a domain specifically to impersonate a brand, particularly for phishing, generally breaches trademark law and most registrars’ acceptable use policies, which is why a documented takedown request to the registrar is usually effective.

    How fast can a phishing domain be taken down once it’s found?

    Timelines vary by registrar and host, but a documented, evidence-backed request is generally actioned faster than a vague report. Given that the average phishing site is only live for around 12 hours anyway, speed of detection often matters more than speed of takedown.

    Do phishing domains only target large, well-known brands?

    No. Any brand with an online presence and customers who might click a link can be targeted, and smaller brands often have fewer resources dedicated to watching for it, which makes automated detection more valuable relative to team size.

    What’s the difference between typosquatting and brand impersonation?

    Typosquatting is a lookalike domain, usually used for phishing. Brand impersonation is a fake social media account or page. Both fall under online brand protection but are detected and enforced through different channels.

    Can a legitimate regional site or reseller domain get mistakenly flagged?

    It shouldn’t, provided detection is verified against your real domain portfolio and known authorised partners rather than flagged on a name match alone. This is why the verify step matters as much as detection itself.