WEBINVEST.IT

Cybercriminals and gTLD domains: Interisle estimates 16.8 million malicious registrations in 2025

26 June 2026
Cybercriminals and gTLD domains: Interisle estimates 16.8 million malicious registrations in 2025

The domain market is not expanding only because of companies, creators, investors and legitimate digital projects. A meaningful share of demand also comes from actors buying cheap names as disposable infrastructure for phishing, malware, spam and online fraud. A new Interisle Consulting Group study, discussed by Karen Rose on CircleID, puts a clear figure on the issue: in 2025 cybercriminals may have purchased around 16.8 million gTLD domains, or roughly one fifth of all new generic domain registrations during the year.

For registrars, registries and domain investors, this is more than a cybersecurity statistic. It points to a structural market tension: when low pricing, automation and volume discounts make it easy to register thousands of names, part of that growth can turn into reputational and operational cost for the wider ecosystem.

Read also: ICANN measures two years of DNS Abuse enforcement: what changes for registrars and registries

The market weight of criminal demand

Interisle says nearly 85 million new gTLD domains were registered in 2025. By mid-May 2026, 8.5 million of those names had already appeared on blocklists for malicious activity, representing 10% of the total. The study treats that number as a floor, because many abusive registrations are detected later or never appear immediately in reputation feeds. Using conservative projections for future blocklisting and related domains controlled by the same actors, Interisle estimates that bad actors may have acquired 16.8 million domains.

The most relevant point for the domain industry is concentration. Abuse is not evenly spread across all operators. Interisle reports that five registrars accounted for 50% of all gTLD domains created in 2025 and later blocklisted. In some cases, individual registrars or registries saw more than half of their new registrations end up blocklisted. That does not automatically imply intent, but it does show that commercial practices, onboarding checks and post-registration enforcement materially affect outcomes.

Cheap domains, APIs and high-volume campaigns

The operational logic is simple: a domain is cheap, can be registered in seconds and can be discarded once it becomes unusable. For criminal campaigns, domain names are an ideal raw material. Interisle highlights cases where malicious groups bought hundreds of thousands of names in specific extensions, using batch registrations, promotional pricing or automated channels. For legitimate companies, APIs and volume discounts are useful portfolio tools; for attackers, the same mechanisms can become a production line.

This also matters to domain investors. A namespace perceived as a comfortable home for phishing or malware becomes less attractive to end users, advertisers, security providers and payment platforms. Low prices can generate short-term volume, but if registration quality deteriorates, the entire extension can suffer a reputational discount.

Read also: DNIB Q1 2026: global domains rise to 392.5 million, with strong new gTLD growth

Why this matters for the next gTLD round

The report lands as ICANN prepares for new open gTLDs from 2027 onward. More supply means more competition, more pricing pressure and a greater need to differentiate extensions through operational quality, not just marketing. If new operators enter the market with a volume-first strategy and weak abuse controls, the problem could grow.

Interisle also makes an important point: this level of abuse is not inevitable. Some registrars and registries expanded while keeping malicious registrations relatively low. That suggests preventive checks, registration-pattern analysis, limits on suspicious campaigns and faster intervention can reduce abuse without blocking legitimate customers or investors.

The Webinvest view

The practical takeaway is that a domain's value is not defined only by the string, the extension or the purchase price. It is also shaped by the reputation of the namespace around it. If a TLD becomes associated with disposable registrations, mass abuse and low-quality activity, the secondary market feels the impact even when individual names are clean.

For registrars, the challenge is balancing conversion and control. For registries, healthy growth will matter more than raw volume. For investors, the data is a reminder to look beyond fashionable metrics: before accumulating names in heavily discounted extensions, it is worth assessing abuse signals, operator quality and how the TLD is perceived by companies and security providers.

Source: Interisle Consulting Group and coverage on CircleID.

← All news