Back to News
Cybersecurity

Rising Threat: Cybercriminals Invest Heavily in Expired Domains for Scams

Cybercriminals are increasingly capitalizing on expired domains to reroute traffic to malicious sites, posing significant risks to businesses and consumers.

Recent findings from Infoblox highlight a concerning trend in cybercrime, where hackers are investing nearly $7 million in acquiring expired domains, termed 'dropcatch domains.' These domains, which have lost their original ownership and are re-registered, are used to leverage existing traffic and online credibility to redirect unsuspecting users to scams and malware. In the first half of 2026 alone, over 50,400 such domains were reported as being hijacked by threat actors, underscoring the scale of this issue.

For businesses, this trend represents a dual threat: not only do they risk losing potential customers to these deceptive sites, but they also face reputational damage if their legitimate domains are used in conjunction with these scams. Companies must enhance their domain monitoring strategies and consider implementing protective measures such as domain locking and diligent registration practices to safeguard their digital assets. This situation is a stark reminder of the evolving landscape of cybersecurity threats, where even seemingly innocuous expired domains can become tools for cybercriminals, complicating the fight against online fraud and reinforcing the need for robust cybersecurity and AI solutions to detect and mitigate these risks.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html)*