Typosquatting
Registering domain names that are common misspellings of popular websites to capture credentials from users who mistype URLs.
Typosquatting (also called URL hijacking) involves registering domains that are slight misspellings or variations of legitimate websites: gooogle.com, amzon.com, microsft.com. Users who mistype a URL land on the attacker’s site, which typically mimics the real site’s login page.
When victims enter their credentials on the typosquatted domain, the attacker captures them. Some typosquatted sites also distribute malware through fake software downloads.
Defenses include bookmarking important sites, using a password manager (which matches credentials to exact domains and won’t autofill on misspelled domains), implementing browser security extensions that warn about suspicious domains, and organizations proactively registering common misspellings of their own domain.
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide