DE-CSC
CSC , a world leader in business, legal, tax, and domain security, today released new research from their Digital Brand Services (DBS) division warning consumers that simple URL typos could lead to significant online fraud, counterfeit goods, and cyber crime during the holiday shopping season. The company identified and analyzed registered domain typos (misspellings) associated with the 10 largest online shopping brands in the world and found that over 70% of the 1,553 registered domain typos appear to be owned by third parties.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20201117005233/en/
According to CSC’s new research , these third-party owned domains receive over five million visitors annually. In addition, 40% of these domains are using domain privacy services to mask or hide their ownership and identity, and close to 48% are configured with MX (mail) records that can be used for phishing and to intercept email. In its blog, CSC offers tips to both brand owners and consumers to protect themselves against fraudulent web properties and content.
A deep dive of the top 100 most visited typo domains shows they are being used in this manner:
- 38% are pointing to advertising-related and pay-per-click web content, which can be used to spread malware via domain parking services
- 27% had no live web content, yet 37% were configured to send and receive email with MX records
- 15% were engaged in affiliate referrals, which means the brand owner could be targeted for unauthorized affiliate activity resulting in loss of revenue
- 12% were pointing at shopping-related web content, which indicates that consumers could engage with nefarious retailers selling counterfeit goods while brand owners lose revenue
- 8% were pointing toward malicious web content e.g., malware
During the holiday shopping season, just one hour of downtime can cost a business over $500,000 in lost revenue*. Despite this, many global eCommerce and shopping companies are still lacking basic domain security measures that could prevent this from happening. For instance, only 16% of the top 500 global eCommerce and shopping domains leverage domain name system (DNS) hosting redundancy, which could secure their online presence from a distributed denial of service (DDoS) attacks. In addition, only 18% use registry locks that prevent DNS hijacking attacks that could redirect consumers to alternate websites. Lastly, 40% of retailers do not use enterprise-class domain registrars. This is partially explained by the fact that 40% of the observed domains still rely on retail registrars that typically don’t provide advanced domain security features.
“ In light of the global pandemic, both consumers and leading brands have embraced online shopping as we head into the 2020 holiday season. As such, we wanted to call attention to how brands and consumers are at increased risk for a multitude of threat vectors associated with online fraud, counterfeits, revenue leakage and many other cyber criminal activities this year,” says Ihab Shraim, chief technology officer for CSC. “As evidenced by the sheer number of mail-in votes in the U.S. election, consumers are looking for safe alternatives to in-person interactions, and it’s important for brands to not only provide those digital channels, but also ensure they are secure from online threat vectors.”
“We’re delighted that companies like CSC are advocating for companies and online brands to put the necessary security protocols in place to protect not only their brand reputation, but their consumers, from online fraud and cyber crime,” says Daniel Eliot, director of Education and Strategic Initiatives at the National Cyber Security Alliance (NCSA). “The NCSA's mission is to educate consumers and businesses about these credible risks, and the importance of using recommended cyber security best practices. CSC’s research is also an important part of advocating for consumers, and showing the pervasive risk of these cyber attacks and fraudulent domains.”
Additional resources:
- Blog post
- Consumer tips infographic
*gremlin.com/ecommerce-cost-of-downtime/
About CSC
CSC is the trusted provider of choice for the Forbes Global 2000 and the 100 Best Global Brands® in enterprise domain names, domain name system, digital certificate management, as well as digital brand and fraud protection. As global companies make significant investments in their security posture, CSC can help them understand known security blind spots that exist and help them secure their digital assets. By leveraging CSC’s proprietary solutions, companies can get secure to protect against cyber threats to their online assets, helping them avoid devastating revenue loss, brand reputation damage, or significant financial penalties because of policies like the General Data Protection Regulation (GDPR). CSC also provides online brand protection—the combination of online brand monitoring and enforcement activities—taking a holistic approach to digital asset protection, along with fraud protection services to combat phishing. Headquartered in Wilmington, Delaware, USA, since 1899, CSC has offices throughout the United States, Canada, Europe, and the Asia-Pacific region. CSC is a global company capable of doing business wherever our clients are—and we accomplish that by employing experts in every business we serve. Visit cscdbs.com .
View source version on businesswire.com: https://www.businesswire.com/news/home/20201117005233/en/
Link:
Social Media:
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Libraesva and Cyber Guru Announce Strategic Combination to Create a Leading European Human-Centric Cybersecurity Provider27.1.2026 11:00:00 CET | Press release
The combination of two Italian cybersecurity leaders with strong international footprints creates a unique European player delivering an integrated portfolio of Email Security and Security Awareness Training to reduce human cyber risk end-to-end. Cyber Guru and Libraesva today announced a strategic combination that brings together two highly complementary Italian cybersecurity companies to form a new European leader in human-centric cyber protection. The combined group will offer organisations an integrated approach to defending against email-based threats, social engineering, and human-targeted attacks, integrating advanced technology with behavioural resilience. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260127531600/en/ Cyber threats are evolving rapidly, with attackers focusing less on infrastructure and more on the weak link in security – human behaviour. Phishing, business email compromise, smishing, QR-code attack
Europe’s First Meteorological Infrared Sounder Reveals the Atmosphere in 3D27.1.2026 10:30:00 CET | Press release
The first images from Europe’s pioneering meteorological infrared sounder were unveiled today at the EU Space Conference in Brussels, marking a major advance in the ability to monitor how the atmosphere evolves before and during severe weather. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260127490399/en/ Full Earth disc image from the MTG-S Infrared Sounder showing a surface-temperature-sensitive channel, captured between 12:45 and 15:30 UTC on 15 November 2025. The image distinguishes land and sea surface temperatures as well as cloud-top temperatures, highlighting cloud structures and weather systems. Hot desert regions appear in red, while cold cloud tops are shown in blue. © Image: Data acquired on 15 November 2025 and processed by industrial partners Thales and OHB under the supervision of EUMETSAT and ESA. Visual produced by EUMETSAT. The images were captured by the Infrared Sounder (IRS) flying aboard Meteosat Thir
Clearwater Analytics Embeds AI into Beacon Risk Platform to Accelerate Model Validation and Exposure Analysis27.1.2026 10:00:00 CET | Press release
Production-grade AI transforms quantitative workflows—from scenario analysis to tail risk modeling—inside investment risk operations engine Clearwater Analytics(NYSE: CWAN), the most comprehensive technology platform for investment management, today announced breakthrough embedded agentic AI capabilities within Beacon by CWAN, its enterprise risk and quantitative analytics platform, enabling risk teams to accelerate model validation, exposure analysis, and decision-making. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260126906084/en/ As regulatory scrutiny intensifies and portfolio complexity reaches unprecedented levels, traditional risk platforms are failing institutional investors when they need answers most. Built specifically for quantitative developers and risk professionals managing complex institutional portfolios, CWAN’s embedded AI operates within Beacon’s calculation engine itself, training the agents our client
Seasoned European Software Executive David Coste to Join Battery Ventures27.1.2026 09:00:00 CET | Press release
Coste, a longtime leader at pan-European ERP provider Forterro, will be a Battery executive-in-residence Battery Ventures, the global, technology-focused investment firm, announced it has hired former Forterro executive David Coste as an executive-in-residence based in its London office, effective next month. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260127122321/en/ David Coste, a former Forterro executive who begins a new executive-in-residence role with global investment firm Battery Ventures in London in February. At Battery, Coste will work closely with Battery Partner Zak Ewen and General Partner Morad Elhafed, among others, to help source and evaluate business-technology investments throughout Europe. Battery first opened its London office in 2016 and, since 2005, has completed more than 150 transactions across 13 countries including the U.K., Germany, France, the Netherlands, Belgium, Switzerland, Sweden and Nor
Castles Technology Partners With Loomis Pay to Power European Expansion With Next-Generation Android Devices27.1.2026 08:00:00 CET | Press release
Cutting-edge Android payment and Point-of-Sales (POS) technology set to transform the European payments and POS landscape Castles Technology, a global leader in Android payment acceptance devices, has been selected by Loomis Pay, the POS and digital payment division of Loomis, to support its European expansion. Through this collaboration, Loomis Pay will strengthen its capacity to deliver flexible and secure POS and payment solutions tailored to merchant preferences. As well as empowering merchants and their customers to transact the way they prefer, cash, card and digital. Following an extensive market review, Loomis Pay chose Castles Technology for its leadership in Android-based payment solutions, recognized for versatility, reliability, and innovation across its latest Android devices. Loomis Pay will deploy their POS and payment services on the portable S1F4 Pro, the PINPAD S1P2 and the unattended S1U2M4, as well its CasHUB TMS and Marketplace. Castles Technology and Loomis Pay ha
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
