What Is Typosquatting? How Fake Websites Steal Your Credentials
Typosquatting is registering a domain name deliberately similar to a legitimate one, often a common misspelling, so that users who mistype a web address land on a lookalike site instead, typically designed to steal login credentials or distribute malware.
If you found a lookalike domain impersonating your business and don’t know how to take it down, this walks through exactly what to do, and what’s genuinely changed recently.
What Is Typosquatting?
Typosquatting means deliberately registering a domain name close enough to a legitimate one that a user typing quickly, or simply misremembering a spelling, lands somewhere entirely different from where they intended. The lookalike domain then typically hosts a fake login page, malware, or unwanted advertising, profiting from the mistake itself.
Lookalike domains work precisely because they exploit something nobody can fully eliminate: ordinary human typing errors and imperfect memory. Even careful, security-conscious users make typos occasionally, and that occasional mistake is exactly what typosquatting is built around.
Typosquatting vs Cybersquatting — the Intent, and Why It Matters Legally
Cybersquatting is the broader category worth understanding first. It means registering a domain in bad faith specifically to profit from someone else’s trademark or brand, whether by selling the domain back at an inflated price, hosting competing content, or running a scam.
Typosquatting is one specific method of cybersquatting, exploiting typing mistakes specifically rather than, say, registering an exact trademark match outright or a domain with an added generic word.
This distinction matters legally, since intent and method both factor directly into how a domain dispute gets resolved. Proving bad faith, that a domain was registered specifically to exploit a trademark rather than for any legitimate independent purpose, sits at the center of nearly every successful dispute outcome, regardless of which specific cybersquatting method was used.
How Does a Typosquatting Attack Work?
Here’s the practical mechanics most competitor content skips, staying too abstract to actually help someone recognize a lookalike domain when they encounter one. Typosquatters exploit a handful of predictable, well-documented typing patterns.
- Character substitution: swapping a letter for one physically adjacent on a keyboard, like “arnazon.com” for “amazon.com.”
- Missing letters: dropping a single character a fast typist commonly skips, like “gogle.com” for “google.com.”
- Transposed letters: swapping the order of two adjacent letters, like “waslmart.com” for “walmart.com.”
- Added letters: inserting an extra character, often a doubled letter, like “paypall.com” for “paypal.com.”
- Wrong top-level domain: registering the correct name under a different extension entirely, like “.cm” instead of “.com,” exploiting a typo many users don’t even notice they made.
Common Typosquatting Patterns
| Pattern | Example |
| Character substitution | arnazon.com (adjacent keyboard letter) |
| Missing letter | gogle.com |
| Transposed letters | waslmart.com |
| Added letter | paypall.com |
| Wrong TLD | example.cm instead of example.com |
From a Fake Login Page to a Hijacked Domain — the Escalation Path
A typosquatted domain typically starts modestly: a credential-harvesting page built to look nearly identical to a real login screen, waiting for a mistyped visit to hand over a username and password directly.
Once those credentials are captured, the escalation path can extend further. Account takeover follows naturally if the stolen credentials work anywhere else, exploiting password reuse across services. In more severe cases, attackers use that initial foothold, stolen employee credentials, for example, to attempt genuine domain hijacking of the real, legitimate domain itself, potentially seizing control of an organization’s actual web presence rather than just impersonating it from a lookalike address.
Slopsquatting and Address Poisoning — Typosquatting’s Next Generation
Here’s genuinely current content most competitor articles haven’t caught up to yet. Slopsquatting is a distinct evolution of the same underlying technique, but it doesn’t exploit human typos at all.
Here’s how it actually works. AI coding assistants sometimes hallucinate software package names, confidently suggesting a dependency that sounds completely plausible but simply doesn’t exist. Attackers watch for these predictable hallucinations, then register malicious packages under exactly those invented names on public repositories like npm or PyPI. A developer who trusts the AI’s suggestion without verifying it installs the attacker’s malicious package directly, no typo required at any point in the chain, since the AI made the mistake, not the human.
This matters genuinely, not as a theoretical future risk. Researchers have documented real hallucinated package names getting installed thousands of times after attackers pre-registered them, sometimes even finding their way into public documentation belonging to legitimate technology companies. This is precisely why traditional typosquatting defenses miss it entirely: there’s no misspelling to detect, since the fabricated name itself is exactly what the AI generated, letter for letter.
Address poisoning applies a closely related principle to cryptocurrency specifically. An attacker sends a small transaction from a wallet address deliberately similar to one a victim has genuinely used before, hoping the victim later copies the wrong, poisoned address from their own transaction history rather than typing the correct one manually. Same underlying exploitation of trust in a familiar-looking string, applied to blockchain transactions rather than a web address.
How Do You Take Down a Typosquatted Domain?
For most global domains, filing a UDRP complaint, the Uniform Domain Name Dispute Resolution Policy, through an ICANN-approved provider lets a trademark holder pursue transfer or cancellation of a domain registered and used in bad faith. This process exists specifically to avoid the cost and delay of formal litigation for a genuinely common problem.
For .uk domains specifically, Nominet’s Dispute Resolution Service handles the equivalent process, applying its own DRS Policy rather than the UDRP framework used elsewhere, though the underlying principles, proving rights in a name and demonstrating the registration is abusive, remain broadly similar.
What Changed with Nominet’s DRS in 2026?
Here’s a genuinely current, dated change worth understanding directly if you’re dealing with a .uk domain dispute right now. From July 7, 2026, administration of Nominet’s Dispute Resolution Service transferred to the World Intellectual Property Organization, WIPO, an established global provider of domain dispute resolution services working across more than 85 country-code domains.
Here’s what actually changed, and what didn’t. The underlying DRS Policy itself remains unchanged. Nominet’s own Independent Panel of Experts continues making the actual binding decisions. The mediation stage, the burden of proof required, and how precedent from past cases gets applied all remain exactly as before. What changed is purely administrative: new complaints filed from July 7, 2026 onward get submitted through WIPO’s own website rather than Nominet’s, and case management now runs through WIPO directly. Any case filed before that date stays with Nominet through to completion. If you’re preparing a fresh .uk domain dispute today, you’re filing through WIPO, not Nominet directly, even though Nominet’s policy still governs the outcome.
Practical Brand Protection for SMBs with a Limited Budget
Here’s honest, practical guidance for a business that can’t afford comprehensive, proactive domain registration across every possible variation. Prioritize registering your exact domain across the handful of most commonly mistyped variations and the top-level domains most relevant to your actual market, rather than attempting exhaustive coverage across every possible combination and extension.
Monitor for new, suspicious lookalike registrations rather than paying for broad, expensive proactive registration programs covering hundreds of variations preemptively. Most small businesses genuinely don’t need to own every conceivable typo of their own name; they need to notice quickly when someone else registers one and act on it, through a UDRP or DRS complaint, before real damage accumulates. Cyber Security Solutions Ltd routinely helps SMBs make exactly this call, since not every lookalike domain that surfaces genuinely warrants the cost and effort of a formal dispute filing, and knowing which ones do saves real, limited budget for the cases that actually matter.
Conclusion
Typosquatting hasn’t gone away, it’s just picked up new targets, from AI coding assistants to crypto wallets, alongside the same old mistyped web addresses. Know the common patterns, register your most obvious variations, and act quickly through UDRP or Nominet’s DRS when a genuine lookalike surfaces. If you want help deciding whether a lookalike domain targeting your business is worth a formal takedown, Cyber Security Solutions Ltd can walk through it with you.
FAQs
Typosquatting is registering a domain name deliberately similar to a legitimate one, often a common misspelling, so users who mistype a web address land on a lookalike site instead, typically designed to steal credentials or distribute malware.
Cybersquatting is the broader category, registering a domain in bad faith to profit from someone else’s trademark. Typosquatting is one specific method of cybersquatting, exploiting typing mistakes specifically rather than other bad-faith registration tactics.
Typosquatters exploit predictable typing patterns: character substitution, missing letters, transposed letters, added letters, and wrong top-level domains, each targeting a specific, common way real users mistype a familiar web address.
For most global domains, file a UDRP complaint through an ICANN-approved provider. For .uk domains, use Nominet’s Dispute Resolution Service, now administered through WIPO as of July 2026, though the underlying policy remains Nominet’s own.
Slopsquatting registers malicious software packages under names AI coding assistants predictably hallucinate, exploiting developer trust in AI-generated suggestions rather than human typos, meaning traditional typosquatting defenses don’t catch it.
From July 7, 2026, administration of Nominet’s DRS transferred to WIPO. The underlying DRS Policy, expert panel, and mediation process remain unchanged; only where new complaints get submitted and processed has changed.
