Truviss

Tag: Typosquatting

  • 705 Domains: Anatomy of a Brand Impersonation Attack

    705 Domains: Anatomy of a Brand Impersonation Attack

    Home/Blog/705 Domains: Anatomy of a Brand Impersonation Attack
    Domain & Phishing

    705 Domains: Anatomy of a Brand Impersonation Attack

    Catch the pattern before the damage window stays open for months

    Truviss’s Domain Scanner watches new registrations against your brand’s name, correlating patterns across domains, not just checking one at a time.

    Book a demo
    Phishing domain attack case study cover
    TL;DR
    • 705 fraudulent domains targeting L’Oréal were registered in under three weeks, all combining the brand name with job-related terms, and were already being used in employment scams.
    • The attack was identifiable as one coordinated case, not 705 unrelated nuisances, once the registrar, timing and contact-detail pattern across all of them was correlated.
    • A second real case, Microsoft’s RaccoonO365 operation, shows a more visually convincing variant: homoglyph domains like “rn” standing in for “m”, which defeated a quick glance and helped steal 5,000+ credentials across 94 countries.
    • UDRP secured a complete legal outcome for L’Oréal, but only after a real damage window, the faster route for active harm is a direct hosting-provider abuse report.

    Seven hundred and five. That’s how many fraudulent domain names were registered targeting L’Oréal between 23 December 2025 and 15 January 2026, a span of roughly three weeks. Every one of them combined the L’Oréal name with job-related terms, applicationloreal.com, careerexperiencehubloreal.online, lorealhiringnetwork.com among the examples on record, and the domains were already being used in connection with employment-related scams by the time the case reached resolution. Fifty-two different names were listed as the registrants. L’Oréal’s own representatives argued in the filing that the real number of people behind it was likely one or two.

    The pattern that gave it away

    Individually, any one of these 705 domains might have looked like a one-off scam, easy to miss among the routine noise of brand-adjacent junk domains that get registered every day. What made this identifiable as a single coordinated attack rather than 705 unrelated nuisances was the pattern underneath the registrant names: all of them went through only two domain registrars, many shared the same email address, and all were registered within the same tight three-week window. Fifty-two names on paper, but one registration fingerprint underneath all of them.

    L’Oréal pursued this through the Uniform Domain-Name Dispute-Resolution Policy, UDRP, filed with WIPO. The panel ordered all 705 domains cancelled. That’s a real, complete resolution, but it’s worth being honest about the timeline: UDRP cases typically run around two months from filing to decision, which means the practical damage window, domains actively impersonating an HR department, chasing job applicants for personal data or attempting to redirect supplier payments, was open well before any of the 705 domains were ordered offline.

    A second mechanism: the homoglyph attack

    Not every lookalike domain relies on an obvious misspelling. Microsoft has been tracking an operation known as RaccoonO365 since at least July 2024, a phishing kit built specifically to steal Microsoft 365 credentials, that has taken at least 5,000 logins from victims across 94 countries. Working with Cloudflare and under a court order from the Southern District of New York, Microsoft seized 338 websites tied to the operation to disrupt its infrastructure. Reporting on the operation has described its use of homoglyph-style domains, near-identical character substitutions such as “rn” standing in for “m”, built to survive a quick visual glance that would catch a cruder misspelling instantly.

    This is the same underlying threat as L’Oréal’s case, a domain built to be mistaken for a real brand’s, executed with a more visually convincing technique than an obvious typo. Both fall under the same category of typosquatting and phishing domain abuse, but the homoglyph variant specifically defeats the “does this look roughly right” check most people rely on without thinking about it.

    See how Truviss correlates domain registrations against your brand’s name, catching the pattern, not just one domain at a time.

    Explore Domain Scanner

    Why the registration pattern matters more than any single domain

    The lesson from L’Oréal’s case isn’t that one domain slipped through, it’s that 705 individually plausible-looking domains only became visible as one attack once someone connected the registrar, timing and contact-detail pattern across all of them. A brand watching for isolated typosquats one at a time would catch some of these eventually, through user reports or chance discovery, but the coordinated wave itself, the thing that made this newsworthy and legally actionable as a single case, only shows up when registrations are correlated against each other, not evaluated individually.

    Two response routes, and when each applies

    Once a suspicious registration pattern is confirmed, there are two genuinely different paths, and picking the wrong one costs time that matters. UDRP is the thorough, comparatively affordable route for a confirmed bad-faith registration, roughly two months to resolution, filing fees starting in the low thousands, built around a three-part test of confusing similarity, no legitimate interest, and bad-faith registration or use. It’s the right tool for securing a complete, permanent outcome like L’Oréal’s mass cancellation.

    When a domain is actively phishing right now, credentials or personal data being harvested in real time, two months is far too slow to stop ongoing harm. A direct abuse report to the domain’s hosting provider can pull an actively malicious site offline in hours rather than weeks, trading a slower, more complete legal remedy for immediate harm reduction. The right call depends on how urgent the active harm is, not on which route looks more thorough on paper, and the two aren’t mutually exclusive: a fast abuse report to stop the bleeding, followed by a UDRP filing to secure the domains permanently, is a reasonable sequence rather than a choice between the two.

    What this means for a brand’s own monitoring

    It’s tempting to read the L’Oréal case as proof that only very large, high-profile brands get targeted at this scale. The more accurate reading is that a company with L’Oréal’s resources still needed to catch a 705-domain wave by recognising a registration pattern across weeks, and still had a real damage window before the UDRP process concluded. A smaller brand with fewer resources to notice that pattern manually has even less margin. The attacker’s cost to register a lookalike domain barely changes whether the target is a global conglomerate or a mid-sized regional brand. What changes is whether anyone is watching new registrations closely enough, and correlating them against each other, to catch the pattern before the damage window stays open for months.

  • Domain Phishing: The Complete Guide (2026)

    Domain Phishing: The Complete Guide (2026)

    Home/Blog/Domain Phishing: The Complete Guide (2026)
    Domain & Phishing

    Domain Phishing: The Complete Guide (2026)

    Domain Phishing: The Complete Guide cover
    TL;DR
    • APWG recorded 3.8 million unique phishing attacks in 2025, up from 3.76 million in 2024, and most of these rely on a lookalike domain to appear legitimate.
    • The average phishing site stays live for only around 12 hours before takedown (BlackBerry, 2025), which is why continuous monitoring beats periodic manual checks.
    • FBI IC3 recorded $215.8 million in direct phishing losses in 2025, up sharply from $70 million the year before.
    • A documented detect, verify, enforce process against your own domain and brand assets closes phishing domains faster and gives you an evidence trail if a case escalates.

    What domain phishing and typosquatting actually look like

    Domain phishing almost always starts with typosquatting, a domain registered on a common misspelling or visual variant of a real brand’s web address. A swapped letter, a doubled character, a numeral standing in for a similar-looking letter. The domain is then built to mirror the real site closely enough to pass a quick glance, most often cloning a login or checkout page to harvest credentials or payment details under the brand’s name.

    APWG recorded 3.8 million unique phishing attacks across 2025, up from 3.76 million in 2024 (APWG, Phishing Activity Trends Report, Q4 2025). A large share of these depend on exactly this pattern: a domain close enough to a trusted brand’s real address that a customer doesn’t look twice before entering sensitive information.

    Why lookalike domains are so effective

    A lookalike domain doesn’t need to fool a security team, it only needs to fool a customer moving quickly, usually someone who clicked a link in an email or a text message and is already expecting to land on the brand’s real site. Pairing the domain with a valid SSL certificate removes the one browser warning most people would actually notice, so the page looks legitimate at a glance even to someone paying reasonable attention.

    Phishing sites also don’t stay up for long. The average phishing site is live for only around 12 hours before it’s taken down (BlackBerry, 2025), which sounds reassuring until you consider how much damage a convincing fake can do to the right audience in that window, and how quickly a new one can go up to replace it.

    The real cost of a phishing domain using your brand

    The most direct cost lands on customers, not the brand: stolen credentials, stolen payment details, and in many cases money sent to an account that was never the brand’s own. But the brand absorbs the fallout regardless. Customers who realise they’ve been phished under a brand’s name associate the experience with that brand, not with the criminal who registered the domain, and support teams end up fielding complaints about a page the brand never built.

    Phishing losses reported to the FBI’s Internet Crime Complaint Center reached $215.8 million in 2025, up from $70 million the year before (FBI IC3, 2025 Internet Crime Report), and that figure only captures reported financial losses, not the harder-to-measure cost of customer trust.

    Manual domain watching versus continuous monitoring

    Most brands start out checking for lookalike domains the way they check for most things online: occasionally, and manually, usually after a customer reports a suspicious email or a phishing page turns up in a search. This catches the domains that are already active and already causing complaints.

    What it misses is the domain that’s registered today and weaponised next week. New domains can be registered, built out to mimic a real site, and pushed into a phishing campaign within days, well inside the gap between manual checks. Continuous monitoring closes that gap by watching new domain registrations and DNS activity for patterns that match a brand’s name, rather than waiting for a phishing page to surface on its own.

    Building a domain takedown process that holds up

    A workable process against domain phishing generally follows the same three stages as any other brand protection channel:

    Detect continuously. Monitor new domain registrations and lookalike variants of your own domain and brand name, not just an occasional manual search.

    Verify against your real domain portfolio and known partners, so a legitimate regional site or an approved reseller’s domain isn’t mistaken for an infringement.

    Enforce with a documented trail, filed with the registrar or host, logged with enough detail (when it was found, what made it identifiable as a phishing clone) to support further action if the case escalates.

    See how Truviss’s Domain Scanner catches lookalike and typosquatted domains the moment they’re registered.

    Explore Domain Scanner

    Common mistakes brands make

    The most common mistake is only reacting once a phishing domain is already active and customers are already complaining, rather than watching for the registration itself. By the time a phishing page is live and indexed, some damage is usually already done.

    A second is assuming a domain has to be an exact match to be a threat. Attackers deliberately use near-misses, a swapped character, an added hyphen, a different top-level domain, specifically so the domain doesn’t show up in a simple exact-match search.

    A third is treating a single takedown as the end of the problem. A determined phishing operation will often re-register a near-identical domain shortly after the first one is taken down, which is why ongoing monitoring matters more than any single enforcement action.

    Getting started

    Start by mapping the domain variations most likely to be used against your brand, common misspellings, added or swapped characters, alternate top-level domains, then put continuous monitoring in place against that list rather than relying on customers or search results to surface the next one. Once detection is running, pair it with the same evidence-backed takedown process used for online brand protection more broadly, so enforcement is consistent regardless of which channel a threat shows up on first.

    Frequently asked questions

    How can I tell if someone has registered a phishing domain using my brand?

    Manually searching common misspellings of your domain will catch some cases, but continuous monitoring of new domain registrations against your brand name is what catches a domain before it’s actively being used in a campaign.

    Is registering a domain to impersonate another brand illegal?

    Registering a domain specifically to impersonate a brand, particularly for phishing, generally breaches trademark law and most registrars’ acceptable use policies, which is why a documented takedown request to the registrar is usually effective.

    How fast can a phishing domain be taken down once it’s found?

    Timelines vary by registrar and host, but a documented, evidence-backed request is generally actioned faster than a vague report. Given that the average phishing site is only live for around 12 hours anyway, speed of detection often matters more than speed of takedown.

    Do phishing domains only target large, well-known brands?

    No. Any brand with an online presence and customers who might click a link can be targeted, and smaller brands often have fewer resources dedicated to watching for it, which makes automated detection more valuable relative to team size.

    What’s the difference between typosquatting and brand impersonation?

    Typosquatting is a lookalike domain, usually used for phishing. Brand impersonation is a fake social media account or page. Both fall under online brand protection but are detected and enforced through different channels.

    Can a legitimate regional site or reseller domain get mistakenly flagged?

    It shouldn’t, provided detection is verified against your real domain portfolio and known authorised partners rather than flagged on a name match alone. This is why the verify step matters as much as detection itself.