ER10 · August 17, 2026 · 1Cifer
Expired domains have become a goldmine for hackers: make sure you haven't abandoned yours
A Kazakhstani outlet warned about a growing class of attacks: expired domains have become a goldmine for hackers and fraudsters. The mechanics are simple: a company rebrands, closes a project or simply forgets to renew a domain — the address frees up and an attacker buys it. With the domain he gets everything tied to it: inbound mail with invoices and password resets, access to services where the domain proved ownership, and above all the trust of people who keep the address in their contacts.
Then the scenarios are a menu: mailing "updated bank details" to partners from a familiar domain, intercepting password recovery for cloud services, raising a fake copy of the old website. Formally it is all almost legal — the domain was bought on the open market; in fact it is theft of a company's identity.
The defense costs less than any incident. Run an inventory: which domains has the company ever registered — for projects, promos, old brands. Renew key addresses years ahead with auto-billing, and retire abandoned domains properly: detach mail and services in advance, warn counterparties, and keep the address in "quarantine" for another year or two. Losing a domain is a second's oversight; winning back the trust of partners who received fake invoices in your name is a years-long task.


