SecBriefs
← All briefs

Criminals are buying old web addresses—and the trust that comes with them

Nearly $7M was spent on expired domains that still attract visitors, links and credibility.

Hand-drawn SecBriefs editorial illustration: Criminals are buying old web addresses—and the trust that comes with themSOURCE · The Hacker News
© 2026 SecBriefs · Original illustration
SECBRIEFS ASSESSMENT

When a website disappears, its domain name can eventually be registered by someone else. Criminal groups are buying expired addresses at scale because the old domain may still appear in bookmarks, search results, emails, documents and links from reputable websites. The new owner inherits some of that history and familiarity, even though the organization behind the address has completely changed. This can make a phishing page, fake login or malware download look more credible than one hosted on a newly created domain. For everyday users, an address that looks familiar or has existed for years is not automatically safe. Navigate through the organization’s current official website before entering credentials or payment details. For businesses, retiring a website should include an exit plan: inventory old campaign, product and supplier domains, renew the important ones and monitor those that must be released. Pay particular attention to forgotten subdomains and links embedded in archived documents. Digital trust can outlive the asset that originally earned it.

Read original at The Hacker News

SecBriefs adds context and practical guidance. Reporting remains credited and linked to the original publisher.