Digital squatting is a growing cybercrime infrastructure problem in which criminals register domains that mimic legitimate businesses to steal credentials, divert traffic, and funnel customers toward fraudulent services. The threat has exploded as domain registration costs have dropped and new top-level domains (TLDs) have proliferated, giving attackers cheap and easy ways to impersonate established brands.
Key Takeaways
- 94% of organisations have encountered at least one fraudulent domain impersonating their brand
- Digital squatting enables credential theft, which attackers then use for credential stuffing across other platforms
- The Methbot scheme spoofed 6,000 U.S. domains and allegedly stole $5 million daily in fraudulent ad revenue
- Buying protective domains with misspellings and alternative TLDs is a core defensive tactic
- Continuous monitoring of new domain registrations is essential to catch threats early
According to TechRadar, 94% of organisations saw at least one fraudulent domain posing as their brand and emailing customers. The scale of the problem is staggering. The Methbot operation alone spoofed 6,000 U.S. domains and allegedly siphoned off $5 million in fraudulent revenue per day, demonstrating how profitable domain fraud has become for criminals.
Why Digital Squatting Is More Than a Branding Problem
Digital squatting is not just about stolen logos or customer confusion. Spoofed domains serve as launching pads for credential theft, counterfeit product sales, and ad revenue hijacking that directly harms both revenue and customer trust. When attackers capture customer login credentials through a fake domain, they weaponise those credentials through credential stuffing—testing the same username and password combination across other platforms to compromise accounts at banks, email providers, and social networks.
The economics are brutal. Criminals register domains cheaply, host them on compromised infrastructure, and either harvest credentials directly or inject malicious code that redirects legitimate traffic to counterfeit services. Unlike traditional brand infringement, which might cost a company reputation, digital squatting directly enables fraud and feeds organised cybercrime networks.
Five Core Defences Against Digital Squatting
Protecting your brand requires a multi-layered strategy that goes beyond defending your primary domain. TechRadar recommends businesses protect not only their legitimate domains but also similar, suspicious, or infringing domains that criminals might exploit.
The first step is reconnaissance. Scan domain registries to identify which TLDs are available with your company’s domain name and which are already registered. This reveals gaps in your digital footprint and flags which extensions attackers might target next. Many businesses focus only on .com, missing the fact that .net, .co, .io, and newer TLDs offer cheap entry points for impersonators.
Second, buy protective domains with common misspellings and alternative TLDs when feasible. If your brand is Acme Corp, register acmecorp.net, acmecorp.io, acmecorp.co, and common typos like acmecorps.com and acmecorpp.com. This removes targets from the attacker’s playbook and signals ownership across the domain ecosystem. The cost is modest compared to the damage a single credential-harvesting campaign can inflict.
Third, take action against domains that infringe your brand or create a security risk. This means monitoring registrar records, sending takedown notices, and working with domain registrars and hosting providers to shut down fraudulent sites. Speed matters—a fake domain sitting active for even a week can harvest thousands of credentials.
Fourth, implement continuous monitoring for suspicious activity such as new domain registrations around your company’s digital footprint. Use domain monitoring tools to alert you when someone registers a domain similar to yours, then investigate and respond immediately. Many registrars offer monitoring services; others integrate with threat intelligence platforms.
Fifth, educate your customers and employees about the risk. Train staff to verify domain legitimacy before clicking links in emails, and publish guidance on your official website directing customers to your canonical domain. This reduces the attack surface by making it harder for criminals to trick people into visiting fake sites.
The Cost of Inaction
Ignoring digital squatting is a business risk that compounds over time. Each unmonitored domain represents a potential vector for credential theft, which then flows into credential stuffing attacks against your customers’ personal accounts. If your brand is compromised in this way, liability questions arise: did you take reasonable steps to protect customer data? Regulators and customers expect businesses to defend their digital footprint actively.
The Methbot case shows what happens when domain fraud scales. A single operation can siphon millions daily while operating in plain sight. Your business may be next.
Is digital squatting the same as domain squatting?
Digital squatting and domain squatting are related but distinct. Domain squatting traditionally refers to registering domains for resale or extortion. Digital squatting, by contrast, actively uses fake domains to commit fraud—credential theft, malware distribution, counterfeit sales, or ad fraud. Digital squatting is more malicious and operationally active.
How often should I monitor for new fraudulent domains?
Continuous monitoring is the standard. Ideally, automated tools alert you within hours of suspicious registrations. Manual quarterly audits are insufficient—attackers move fast, and a week-old fake domain can harvest thousands of credentials. Set up real-time alerts through your registrar or a third-party monitoring service.
Can I take down a fraudulent domain myself?
You can report it to the registrar and hosting provider, but they handle takedowns. File a DMCA complaint if the site hosts your copyrighted content, or contact law enforcement if the domain facilitates fraud. Registrars are often faster than courts—a clear infringement report can result in suspension within days.
Digital squatting is a moving target, but it is not an unsolvable problem. By scanning your domain ecosystem, buying protective registrations, monitoring continuously, and acting decisively against threats, you shrink the attack surface and make your brand a harder target. The cost of defence is trivial compared to the cost of a credential-harvesting campaign that compromises your customers.
Edited by the All Things Geek team.
Source: TechRadar


