Skip to content

Frequently asked questions

What is typosquatting?

Typosquatting is a form of domain impersonation where attackers register domains that are common misspellings or typos of legitimate brand names, hoping users will accidentally visit them. Related techniques include homoglyph domains, which substitute visually identical characters for Latin letters, and combosquats, which append trust words like secure-, login-, or verify- to a real brand name.

Why does typosquatting risk differ by industry?

Because the payoff and the audience differ. A cloned fintech login converts directly into stolen credentials and money, a fake SaaS login can capture workforce credentials that unlock an entire organization, e-commerce lookalikes monetize instantly through card fraud around sales peaks, and delivery-themed lures reach a huge audience genuinely expecting a package. The faster a lookalike converts into money or valuable access, the more attacker effort a sector attracts.

Which industries are most targeted by typosquatting?

Sectors where a convincing lookalike converts quickly into credentials or money: fintech, healthcare, e-commerce, SaaS, and logistics and delivery. Fintech and SaaS are targeted for their high-value logins, e-commerce for card fraud around launches and sales events, healthcare for sensitive patient-portal data, and logistics for the sheer reach of failed-delivery and tracking lures.

What are these industry risk guides based on?

Each guide is an educational explanation of why attackers target that sector and the impersonation patterns most commonly seen there — typos, homoglyphs, combosquats, and cloned login, checkout, or tracking pages. The guides are categorical: they describe techniques and attacker incentives, not named incidents, and they do not assign numeric risk scores to companies or sectors.

What should a small business do first about typosquatting?

Start by finding out what already exists. A free brand check generates roughly 160 permutations of your domain and checks each against live DNS and domain registration data, so you see registered lookalikes before deciding anything else. Ongoing monitoring then adds real-time Certificate Transparency alerts and daily newly-registered-domain checks, which flag new lookalikes as they appear instead of on a later manual review.