What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sometimes—but “buying instead of hacking” is not a wholesale change in how phishing works. Criminals do deliberately register domains for abuse, sometimes in bulk. They also exploit compromised legitimate websites, hijacked accounts, and hosting or subdomain services. The important distinction is whether a domain was registered for malicious use or was legitimate before an attacker took it over.

What does “maliciously registered” mean?

A maliciously registered domain is one deliberately registered for abuse. That differs from a legitimate domain or website that an attacker later compromises. A phishing URL alone does not establish which happened: investigators need evidence about the domain’s history and how it was used.

In its 2024 INFERMAL study, ICANN analyzed phishing URLs collected from APWG, PhishTank, and OpenPhish between August 2023 and January 2024. Its method used registration timing and DNS-level mitigation signals to distinguish deliberate registrations from compromised domains. Specifically, it looked for registration within 90 days before blocklisting and DNS-level mitigation within a month after a report. ICANN said the method could still miss malicious registrations. Read ICANN’s methodology.

How do deliberate registrations compare with compromised sites?

Question Deliberately registered domain Compromised legitimate site
Who controls the registration? The attacker or an intermediary may control the registration account. The legitimate owner originally registered it; the attacker gains access later.
What does the domain’s history look like? It may be newly registered, although age alone does not prove intent. It may have an older, legitimate history before the abuse begins.
Where might the phishing content appear? On the domain itself, a subdomain, or a path. Often on a compromised page, path, or subdomain within the legitimate site.
Who may need to respond? A registrar or registry may be asked to suspend the domain; a hosting provider may also need to remove content. The site owner or host may need to clean up the compromise, alongside other response steps.
What does a phishing URL prove? It identifies suspicious use, but not by itself whether the domain was registered for abuse. It does not establish whether the domain or site was compromised.

The distinction matters because the response differs: suspending a newly registered domain is not the same task as cleaning malicious content out of a legitimate site. Attackers can also use hijacked accounts and legitimate hosting or subdomain services, so domain registration is only one route to phishing infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What do the available figures show?

The studies below measure different things. Their counts should not be combined into a single estimate of how many phishing domains exist: they differ in period, population, unit counted, and whether a figure is an observation or a projection.

Source and scope Finding How to interpret it
ICANN INFERMAL, 2024; phishing-domain sample collected August 2023–January 2024 ICANN classified 28,000 maliciously registered domains from its analyzed sample. This is a study result, not a worldwide total. The study began with 534,000 blocklisted URLs, extracted 108,000 registered domains, and applied its timing and DNS-level mitigation criteria. Method and results.
Interisle, 2025; cybercrime involving malware, phishing, and spam Malicious domain registrations rose 149% year over year; bulk registration for criminal purposes rose 177%. These growth figures cover broader cybercrime activity, not phishing alone. Interisle’s cybercrime supply-chain findings.
Interisle analysis of 2025 gTLD registrations, published 2026 Of nearly 85 million new gTLD domains registered in 2025, 8.5 million had been added to malicious-activity blocklists by mid-May 2026. The 8.5 million is the observed blocklist count at that date. Interisle separately projected that the eventual figure could approach 16.8 million, or 20% of the 2025 registrations; that is an estimate, not an observed count. Interisle’s analysis.
APWG Q3 2025 report; registrars shown for BEC scam domains The chart attributed 14% to NameCheap, 13% to GoDaddy, and 12% to Hostinger. This is a bounded, quarter-specific observation of registrars used to register BEC scam domains. It does not show that a registrar knowingly enabled abuse or establish a ranking for all phishing activity. APWG’s Q3 2025 report.
Fortra observation reported in APWG Q3 2025; BEC attacks 74% of BEC attacks observed in Q3 2025 used a free webmail domain. This is a share of observed BEC attacks, not of phishing domains. It illustrates that attackers also abuse free webmail accounts rather than relying only on purchased domains. APWG’s Q3 2025 report.

Taken together, the findings support a narrower conclusion than the headline claim: deliberate domain registration is a measurable and sometimes bulk-acquired resource in the cybercrime supply chain. They do not show that it has replaced compromised sites, accounts, or service-based infrastructure. ICANN’s INFERMAL project identifies registration costs, payment methods, and bulk-registration features as factors worth studying, rather than offering proof that any one factor explains the trend. About ICANN’s INFERMAL project.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What can reduce abuse?

Interisle’s recommendations address several points in the domain and hosting supply chain. They are proposed controls, not individually proven fixes that would eliminate phishing.

  • Verify bulk registrants: use digital identity verification for customers registering domains in volume.
  • Screen patterns automatically: look for suspicious registration patterns across domains and subdomains.
  • Improve hosting abuse detection: providers can proactively identify and respond to malicious content hosted on their services.
  • Make reporting and takedowns work quickly: trusted reporter programs and clear response processes can help providers assess abuse reports and act on them.

Interisle’s phishing research also says registration policies affect phishing levels in a top-level domain. That makes prevention a shared responsibility across registrars, registries, hosting providers, and reporting systems—not simply a question of whether a criminal can buy a domain. Interisle’s phishing landscape findings and recommendations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.