Skip to main content
Attacks and Threats

Typosquatting

Registering domain names that are common misspellings of popular websites to capture credentials from users who mistype URLs.

Typosquatting (also called URL hijacking) involves registering domains that are slight misspellings or variations of legitimate websites: gooogle.com, amzon.com, microsft.com. Users who mistype a URL land on the attacker’s site, which typically mimics the real site’s login page.

When victims enter their credentials on the typosquatted domain, the attacker captures them. Some typosquatted sites also distribute malware through fake software downloads.

Defenses include bookmarking important sites, using a password manager (which matches credentials to exact domains and won’t autofill on misspelled domains), implementing browser security extensions that warn about suspicious domains, and organizations proactively registering common misspellings of their own domain.

Back to the glossary

Stop sharing passwords in spreadsheets

TeamPassword stores, shares and rotates your team credentials, encrypted end to end.

Trusted by 900+ agencies and small teams worldwide