HOME

TheInfoList



OR:

Typosquatting, also called URL hijacking, a sting site, a cousin domain, or a fake URL, is a form of
cybersquatting Cybersquatting (also known as domain squatting) is the practice of registering, trafficking in, or using an Internet domain name, with a bad faith intent to profit from the goodwill of a trademark belonging to someone else. The term is derived ...
, and possibly
brandjacking Brandjacking is an activity whereby someone acquires or otherwise assumes the online identity of another entity for the purposes of acquiring that person's or business's brand equity. The term combines the notions of 'branding' and 'hijacking', and ...
which relies on mistakes such as typos made by Internet users when inputting a website address into a
web browser A web browser, often shortened to browser, is an application for accessing websites. When a user requests a web page from a particular website, the browser retrieves its files from a web server and then displays the page on the user's scr ...
. A user accidentally entering an incorrect website address may be led to any URL, including an alternative website owned by a cybersquatter. The typosquatter's
URL A uniform resource locator (URL), colloquially known as an address on the Web, is a reference to a resource that specifies its location on a computer network and a mechanism for retrieving it. A URL is a specific type of Uniform Resource Identi ...
will usually be ''similar'' to the victim's site address; the typosquatting site could be in the form of: *A misspelling, or foreign language spelling, of the intended site *A misspelling based on a typographical error *A plural of a singular domain name *A different
top-level domain A top-level domain (TLD) is one of the domain name, domains at the highest level in the hierarchical Domain Name System of the Internet after the root domain. The top-level domain names are installed in the DNS root zone, root zone of the nam ...
(e.g., .com instead of .org) *An abuse of the
Country Code Top-Level Domain A country code top-level domain (ccTLD) is an Internet top-level domain generally used or reserved for a country, sovereign state, or dependent territory identified with a country code. All ASCII ccTLD identifiers are two letters long, and all tw ...
(ccTLD) ( .cm, .co, or .om instead of .com) Similar abuses: *Combosquatting – no misspelling, but appending an arbitrary word that appears legitimate, but that anyone could register. *
Doppelganger domain A doppelganger domain is a domain that is spelled identically to a legitimate fully qualified domain name (FQDN) but missing the dot between host/subdomain and domain, to be used for malicious purposes. Typosquatting's traditional attack vector ...
– omitting a period or inserting an extra period *Appending terms such as ''sucks'' or -' to a domain name Once on the typosquatter's site, the user may also be tricked into thinking that they are actually on the real site through the use of copied or similar logos, website layouts, or content. Spam emails sometimes make use of typosquatting URLs to trick users into visiting malicious sites that look like a given bank's site, for instance.


Motivation

There are several different reasons for typosquatters buying a typo domain: *To try to sell the typo domain back to the brand owner *To monetize the domain through
advertising Advertising is the practice and techniques employed to bring attention to a Product (business), product or Service (economics), service. Advertising aims to present a product or service in terms of utility, advantages, and qualities of int ...
revenues from direct navigation misspellings of the intended domain *To redirect the typo-traffic to a competitor *To redirect the typo-traffic back to the brand itself, but through an affiliate link, thus earning commissions from the brand owner's affiliate program *As a
phishing Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticate ...
scheme to mimic the brand's site, while intercepting passwords which the visitor enters unsuspectingly *To install drive-by
malware Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
or revenue generating
adware Adware, often called advertising-supported software by its developers, is software that generates revenue by automatically displaying Online advertising, online advertisements in the user interface or on a screen presented during the installatio ...
onto the visitors' devices *To harvest misaddressed e-mail messages mistakenly sent to the typo domain *To express an opinion that is different from the intended website's opinion *By legitimate site owners, to block malevolent use of the typo domain by others *To annoy users of the intended site


Examples

Many companies, including
Verizon Verizon Communications Inc. ( ), is an American telecommunications company headquartered in New York City. It is the world's second-largest telecommunications company by revenue and its mobile network is the largest wireless carrier in the ...
,
Lufthansa Deutsche Lufthansa AG (), trading as the Lufthansa Group, is a German aviation group. Its major and founding subsidiary airline Lufthansa German Airlines, branded as Lufthansa, is the flag carrier of Germany. It ranks List of largest airlin ...
, and
Lego Lego (, ; ; stylised as LEGO) is a line of plastic construction toys manufactured by the Lego Group, a privately held company based in Billund, Denmark. Lego consists of variously coloured interlocking plastic bricks made of acrylonitri ...
, have gained reputations for aggressively chasing down typosquatted names. Lego, for example, has spent roughly on taking 309 cases through
UDRP The Uniform Domain-Name Dispute-Resolution Policy (UDRP) is a process established by the Internet Corporation for Assigned Names and Numbers (ICANN) for the resolution of disputes regarding the registration of internet domain names. The UDRP curre ...
proceedings. Celebrities have also pursued their domain names. Prominent examples include basketball player Dirk Nowitzki's UDRP of DirkSwish.com and actress Eva Longoria's UDRP of EvaLongoria.org. Goggle, a typosquatted version of
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
, was the subject of a 2006 web safety promotion by
McAfee McAfee Corp. ( ), formerly known as McAfee Associates, Inc. from 1987 to 1997 and 2004 to 2014, Network Associates Inc. from 1997 to 2004, and Intel Security Group from 2014 to 2017, is an American proprietary software company focused on online ...
, a computer security company, which depicted the significant amounts of malware installed through drive-by downloads upon accessing the site at the time. Goggle installed
SpySheriff SpySheriff (also known as BraveSentry 2.0, among other names) is malware that disguises itself as anti-spyware software. It attempts to mislead the user with false security alerts, threatening them into buying the program. Like other rogue an ...
. Later, the URL was redirected to google.com; a 2018 check revealed it to redirect users to
adware Adware, often called advertising-supported software by its developers, is software that generates revenue by automatically displaying Online advertising, online advertisements in the user interface or on a screen presented during the installatio ...
pages, and a 2020 attempt to access the site through a private
DNS The Domain Name System (DNS) is a hierarchical and distributed name service that provides a naming system for computers, services, and other resources on the Internet or other Internet Protocol (IP) networks. It associates various informatio ...
resolver hosted by
AdGuard AdGuard is an ad blocking service for Windows, Linux, MacOS, Android and iOS. AdGuard is also available as a browser extension. Features AdGuard Home AdGuard Home acts as a recursive DNS resolver, which prevents most advertisements fro ...
resulted in the page being identified as
malware Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
and blocked for the user's
security Security is protection from, or resilience against, potential harm (or other unwanted coercion). Beneficiaries (technically referents) of security may be persons and social groups, objects and institutions, ecosystems, or any other entity or ...
. By mid-2022, it had been turned into a political blog. As of April 2025, goggle.com is not operational. Another example of corporate typosquatting is yuube.com, targeting
YouTube YouTube is an American social media and online video sharing platform owned by Google. YouTube was founded on February 14, 2005, by Steve Chen, Chad Hurley, and Jawed Karim who were three former employees of PayPal. Headquartered in ...
users by programming that URL to
redirect Redirect and its variants (e.g., redirection) may refer to: Arts, entertainment, and media * Redirect (album), ''Redirect'' (album), 2012 Christian metal album and its title track by Your Memorial * Redirected (film), ''Redirected'' (film), a 20 ...
to a malicious website or page that asks users to add a malware "security check extension". Similarly, www.airfrance.com has been typosquatted by www.arifrance.com, diverting users to a website peddling discount travel (although it now redirects to a warning from
Air France Air France (; legally ''Société Air France, S.A.''), stylised as AIRFRANCE, is the flag carrier of France, and is headquartered in Tremblay-en-France. The airline is a subsidiary of the Air France-KLM Group and is one of the founding members ...
about malware). Other examples are equifacks.com (
Equifax Equifax Inc. is an American multinational consumer credit reporting agency headquartered in Atlanta, Atlanta, Georgia and is one of the three largest consumer credit reporting agency, consumer credit reporting agencies, along with Experian and T ...
.com), experianne.com (
Experian Experian plc is a multinational corporation, multinational data broker and consumer credit reporting company headquartered in Dublin, Ireland. Experian collects and aggregates information on more than 1 billion people and businesses including ...
.com), and tramsonion.com (
TransUnion TransUnion LLC is an American consumer credit reporting agency. TransUnion collects and aggregates information on over one billion individual consumers in over thirty countries including "200 million files profiling nearly every credit-active co ...
.com); these three typosquatted sites were registered by comedian
John Oliver John William Oliver (born 23 April 1977) is a British and American comedian who hosts ''Last Week Tonight with John Oliver'' on HBO. He started his career as a stand-up comedian in the United Kingdom and came to wider attention for his work ...
for his show ''
Last Week Tonight A last is a mechanical form shaped like a human foot. It is used by shoemakers and cordwainers in the manufacture and repair of shoes. Lasts come in many styles and sizes, depending on the exact job they are designed for. Common variations ...
''. Over 550 typosquats related to the 2020 U.S. presidential election were detected in 2019. The Magniber
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
is being distributed in a typosquatting method that exploits typos made when entering domains, targeting mainly Chrome and Edge users.


In United States law

In the United States, the 1999
Anticybersquatting Consumer Protection Act The Anticybersquatting Consumer Protection Act (ACPA), 15 U.S.C. § 1125(d),(passed as part of ) is a U.S. law enacted in 1999 that established a cause of action for registering, trafficking in, or using a domain name confusingly similar to, or ...
(ACPA) contains a clause (Section 3(a), amending 15 USC 1117 to include sub-section (d)(2)(B)(ii)) aimed at combatting typosquatting. On April 17, 2006, evangelist
Jerry Falwell Jerry Laymon Falwell Sr. (August 11, 1933 – May 15, 2007) was an American Baptist pastor, televangelist, and conservatism in the United States, conservative activist. He was the founding pastor of the Thomas Road Baptist Church, a megachurch ...
failed to get the U.S Supreme Court to review a decision allowing Christopher Lamparello to use www.fallwell.com. Relying on a plausible misspelling of Falwell's name, Lamparello's
gripe site A gripe site is a type of website that is dedicated to critique or complaint about a specific subject.homosexuality Homosexuality is romantic attraction, sexual attraction, or Human sexual activity, sexual behavior between people of the same sex or gender. As a sexual orientation, homosexuality is "an enduring pattern of emotional, romantic, and/or sexu ...
. In ''
Lamparello v. Falwell ''Lamparello v. Falwell'', 420 F.3d 309 (4th Cir. 2005), was a legal case heard by the United States Court of Appeals for the Fourth Circuit concerning allegations of cybersquatting and trademark infringement. The dispute centered on the righ ...
'', the high court let stand a 2005
Fourth Circuit The United States Court of Appeals for the Fourth Circuit (in case citations, 4th Cir.) is a federal court located in Richmond, Virginia, with appellate jurisdiction over the district courts in the following districts: * District of Maryland ...
opinion that "the use of a mark in a domain name for a gripe site criticizing the markholder does not constitute cybersquatting."


WIPO resolution procedure

Under the
Uniform Domain-Name Dispute-Resolution Policy The Uniform Domain-Name Dispute-Resolution Policy (UDRP) is a process established by the Internet Corporation for Assigned Names and Numbers (ICANN) for the resolution of disputes regarding the registration of internet domain names. The UDRP curre ...
(UDRP),
trademark A trademark (also written trade mark or trade-mark) is a form of intellectual property that consists of a word, phrase, symbol, design, or a combination that identifies a Good (economics and accounting), product or Service (economics), service f ...
holders can file a case at the
World Intellectual Property Organization The World Intellectual Property Organization (WIPO; (OMPI)) is one of the 15 specialized agencies of the United Nations (UN). Pursuant to the 1967 Convention Establishing the World Intellectual Property Organization, WIPO was created to pr ...
(WIPO) against typosquatters (as with cybersquatters in general). The complainant has to show that the registered domain name is identical or confusingly similar to their trademark, that the registrant has no legitimate interest in the domain name, and that the domain name is being used in
bad faith Bad faith (Latin: ''mala fides'') is a sustained form of deception which consists of entertaining or pretending to entertain one set of feelings while acting as if influenced by another."of two hearts ... a sustained form of deception which c ...
.


See also

*
Bitsquatting Bitsquatting is a form of cybersquatting which relies on bit-flip errors that occur during the process of making a DNS request. These bit-flips may occur due to factors such as faulty hardware or cosmic rays. When such an error occurs, the user r ...
* (DNS) ** Domain name spoofing – Phishing attacks that depend on falsifying or misrepresenting an internet domain name ** ** * – Similar attacks on vanity
phoneword Phonewords are mnemonic phrases represented as alphanumeric equivalents of a telephone number. In many countries, the digits on the telephone keypad also have letters assigned. By replacing the digits of a telephone number with the correspondin ...
s * * * *


References


External links

* (reporting research by Ben Edelman and Tyler Moore
Measuring Typosquatting Perpetrators and Funders
* {{Domain parking Cybercrime Network addressing Nonstandard spelling Trademark law URL