Cybercrime

Cybercrime / Featured Blogs

Two Years After His Arrest, Pavel Durov Wants to Run His Own Registry

Telegram says it has applied for .gram, potentially giving a billion users DNS addresses while putting its governance, abuse controls, legal exposure and infrastructure under scrutiny as ICANN prepares to reveal applications.

How Domain Abuse, Social Media, and AI Fuel Brand Attacks

CISOs expect social media impersonation to become their leading cybersecurity threat as attackers increasingly combine AI-enabled deception, executive impersonation, and domain abuse across multiple channels to conduct fraud and steal sensitive information.

The Reporting Gap: What Happens Between a DNS Abuse Complaint and a Takedown

DNS abuse enforcement can stop abusive domains and drive systemic registrar reforms, but reporting barriers, inconsistent response times, and poorly documented complaints leave many phishing sites active before actionable cases ever reach enforcement.

Thirty-Five Years Later, Moscow Comes Looking for the Soviet Union’s Domain

Russia is imposing state identity verification on .su, the Soviet Union's surviving domain, as researchers uncover criminal infrastructure across the namespace and ICANN pursues a retirement process that could eventually remove it from the global root.

DNS Abuse and Criminal Infrastructure: Beyond Definitions and Blocklists

Research suggests criminals may control a striking share of newly registered gTLD domains, raising questions about whether ICANN's definitions, contractual safeguards and enforcement mechanisms are keeping pace with the industrial scale of technology-facilitated harm.

What Reagan-Era Cyber Strategists Can Teach America Today

Reagan-era cyber strategists anticipated today's transnational threats, proposing international treaties, public-private cooperation and infrastructure protections. As America again considers aggressive action against cybercriminals, their largely forgotten blueprint offers both lessons and warnings.

The Phishing That Hasn’t Happened Yet: MX Records as Bad-Faith Evidence in UDRP Proceedings

Inactive cybersquatted domains may conceal active email infrastructure. MX records can corroborate bad faith in UDRP disputes when weighed with other evidence, helping panels address fraud risks before harm occurs without conflating capability with misconduct.

Who Registers the Domain That Steals Your Data? The Registrar Accountability Gap in India’s DNS Abuse Crisis

India's DNS abuse crisis exposes a registrar accountability gap: malicious domains remain online while vulnerable users bear the cost. Concentrated abuse patterns suggest stronger oversight and faster mitigation could significantly reduce predictable harms nationwide today.

The Question Isn’t Whether the Harm Is Real - It’s Who Should Act

Measuring online abuse can reveal its scale, but not who should intervene. Effective policy must distinguish harm from contractual responsibility, identify the actors best placed to act, and target remedies where they can work effectively.

What the i2Coalition Article Misses About DNS Abuse

Authors defend research showing malicious domain registrations occur at industrial scale, arguing that blocklist data is reliable and that policymakers must prioritize prevention alongside mitigation to curb cybercriminal exploitation of the domain name market globally.