MONDAY, AUGUST 31, 2026|No. 13379
Technology · Cybersecurity

Concerns Raised Over Criminal Control of New Domain Registrations

New research indicates a significant portion of newly registered generic top-level domains may be controlled by cybercriminals, sparking debate over current DNS abuse measures.

A digital network graphic representing domain name system connections.
A digital network graphic representing domain name system connections. · Photo by Conny Schneider on Unsplash
4 sources
Pipeline ingest
3 reads
Positive / Neutral / Negative
0 countries
Related coverage

Evidence suggests that criminals may control a substantial share of new gTLD registrations. Although the precise scale remains contested, the article asks whether current DNS Abuse measures adequately address wider misuse of domain names.

The scale of malicious registrations

According to research published by Interisle Consulting Group, cybercriminals registered a significant share of new domain names in 2025, representing a substantial portion of the generic top-level domain (gTLD) market.

The study found that at least 10% of all new gTLD domain names registered during the year had subsequently appeared on security blocklists by the time of analysis. It estimated that, taking account of subsequent blocklisting and associated domains not themselves blocklisted, the share of names registered by malicious actors may be closer to 20%.

In a follow-up presentation at the ICANN 86 Policy Forum, Greg Aaron and Karen Rose of Interisle stated that malicious actors may have registered approximately 20% of gTLD names created in 2025. They further reported that 10% of domains registered during 2025 had already appeared on blocklists and estimated that later blocklisting could raise the directly observed proportion to around 12%. In support of that projection, they cited ICANN research indicating that, for every three domains appearing on blocklists, two additional associated domains may remain unlisted.

Any industry confronted with evidence that a material share of its output may be controlled by bad actors should be seriously concerned. It should examine whether its commercial incentives, operational practices, and contractual arrangements inadvertently enable criminals to acquire, use and profit from its products or services at scale.

Definitions and methodologies

ICANN org has since published a blog post by members of its Office of the CTO (OCTO). The post argues, reasonably, that estimates of malicious registrations depend on the definition of "abuse", the standard of evidence applied, and the analytical method used. In particular, it cautions against treating every reported or blocklisted domain as automatically constituting confirmed DNS Abuse.

The post also emphasises that ICANN's contractual definition of DNS Abuse is deliberately limited to botnets, malware, pharming, phishing, and spam when spam serves as a delivery mechanism for one of the preceding harms. It argues that broader categories (including fraud, scams, and spam that does not facilitate these enumerated harms) should be identified separately in analysis. The authors further criticise the Interisle report for referring to methods associated with ICANN and COMAR without sufficiently explaining departures from those methods. They also point to ongoing policy development work concerning associated domain checks and safeguards for high-volume registrations.

Those methodological and definitional questions are important. They affect what can properly be claimed about the scale of confirmed DNS Abuse and the comparability of different studies. However, they do not by themselves resolve the broader concern raised by the Interisle findings: that a substantial proportion of newly registered gTLD names may be under the control of actors engaged in, or supporting, malicious activity.

The scale of technology-facilitated harm

A domain need not yet appear on a blocklist or satisfy ICANN's narrow contractual definition of DNS Abuse to present a meaningful risk. Domains controlled by criminal actors may be retained for later deployment, used in campaigns not yet detected by reporting systems, or used in technology-facilitated harms falling outside ICANN’s current contractual definition, including fraud, scams, sextortion, and other forms of online deception.

The wider scale of technology-facilitated harm should inform the urgency of this discussion, while not being confused with a claim that every such harm is DNS-enabled. The Global Anti-Scam Alliance estimates that scams caused US$442 billion in global losses during 2025, and reports that the "likelihood of financial loss is notably higher in developing countries".

Childlight's Into the Light index also illustrates the scale of online child sexual abuse and exploitation. Its 2026 update reports that approximately one in four children experience online sexual solicitation (including 6.7% during 2025 alone) and that 9% experience online sexual extortion before the age of 18 (2.5% during 2025).

The above figures from the Global Anti-Scam Alliance and Childlight do not measure the role of domain names in each incident, but they do demonstrate why all relevant parts of the Internet ecosystem should consider whether their systems are being used to enable, sustain, or scale serious harm.

Is this in-hand?

The existence of legitimate methodological debate must not become a reason for institutional complacency or inaction. Even if the precise proportion of malicious registrations remains uncertain, evidence that criminal actors may control a substantial share of new gTLD registrations warrants a commensurate response.

The ICANN community should therefore examine whether current contractual definitions, preventive obligations, data-sharing arrangements, and enforcement mechanisms can reduce this risk at the necessary scale and speed. That assessment should include the effectiveness of measures before registration, at the point of registration, and after credible evidence of harmful use emerges. It should also consider whether high-volume and otherwise anomalous registration patterns receive appropriate scrutiny, consistent with due process, proportionality, and the legitimate needs of registrants.

Depending on jurisdictional requirements, ccTLD operators may have a clearer mandate and more direct legal basis to act against wider categories of illegal or harmful conduct. If approaches to technology-facilitated harm materially diverge, the community should consider the potential consequences for trust in the gTLD market. For example, this may lead some stakeholders, including governments, registrants and users, to perceive that parts of the DNS ecosystem are offering weaker safeguards against criminal misuse.

A call to action

I encourage all parts of the ICANN community to consider whether current contractual obligations, operational measures, and policy proposals are adequate in both scope and pace to address DNS Abuse, and to identify additional actions where necessary. The community should also consider whether the current definition of DNS Abuse is sufficiently broad to support effective action against domain names used to facilitate serious technology-facilitated harms, including fraud, scams, ransomware, and child sexual abuse and exploitation.

Any additional measures should not require ICANN to assume the role of a global content regulator or criminal-law authority. The broader challenge is to respond meaningfully to serious harms without unnecessarily sacrificing openness, privacy, security, interoperability, or user agency. As Heather Flanagan observed in reflecting on IETF 126, technical communities cannot disregard policy concerns, but nor should they incorporate every political demand into technical architecture without considering the consequences.

The community should instead consider whether contractual and operational arrangements adequately enable registries and registrars to prevent and mitigate misuse of domain-name infrastructure, and to cooperate, where appropriate, lawfully, transparently, and proportionately with competent national authorities addressing wider domain-name-related harms.

Effective, proportionate know-your-customer processes, going beyond superficial telephone-number or email-address validation, are likely to be part of the solution to reducing criminal misuse of domain names. Risk-based KYC checks by registrars could help identify suspicious customers and registration patterns, particularly where accounts register names at high volume or display other indicators of misuse. These measures should protect legitimate registrants while helping registrars prevent repeat abuse and, where justified by credible evidence, act earlier against criminal activity.

Any reform should preserve the distinction between ICANN’s global technical-coordination role and the primary responsibility of national legal and regulatory systems to define and enforce wider categories of illegality. However, that distinction should not prevent the ICANN community from addressing clear evidence that criminals can acquire and deploy domain-name infrastructure at industrial scale.

Finally, the community should state clearly which technology-facilitated harms it considers outside ICANN’s remit, and why. This clarity would support timely coordination between ICANN, governments, regulators, law-enforcement bodies, and other competent authorities, enabling complementary action across the wider Internet ecosystem while respecting each actor’s independent powers, responsibilities, and legal mandates.


References

This article was originally published over on CircleID.


Comments 1

Guest • 31 Aug 2026

Already have a RIPE NCC Access account? Log in.

Antonio Prado • 27 Aug 2026 15:09

Andrew, thank you for a piece that resists both temptations, alarmism and definitional complacency. One methodological note that I think strengthens your argument: the 20% figure is an upper-bound construction, since the three-to-two ratio comes from ICANN's February 2026 batch-detection work and is measured on batches already identified as malicious; generalising it to the whole registration population assumes those batches are representative. But the directly observed 10% is already enough to justify everything you call for, and anchoring the policy discussion to the robust lower bound removes the methodological debate as an excuse for inaction.

From a European operator's perspective, the risk-based KYC you propose is no longer hypothetical: Article 28 of NIS2 already obliges TLD registries and entities providing registration services to collect, verify and maintain accurate registration data, with lawful access requests answered within 72 hours under Article 28(5). The real question for the ICANN community is whether contractual policy converges with that regime or whether we get gTLD/ccTLD fragmentation, precisely the trust divergence you describe.

Finally, a parallel from routing security: we spent years debating what counts as a hijack until verifiable, automatable artefacts (ROAs, ROV, MANRS auditability) shifted the ecosystem without a central regulator. The registration market lacks the equivalent positive signal of registrant accountability, I guess. Risk-based friction, velocity limits, deferred activation for high-volume batches, pricing structures, is more automatable and more proportionate than generalised documentary KYC, whose costs would fall asymmetrically on small registrars and resellers, consolidating the market while abuse migrates to lax jurisdictions.

Reply

PAN's pipeline reviewed approximately 4 open sources for this article. No human editor reviewed this article before publication.

Related Reads

Show on timeline →