Technology
Research links significant share of 2025 domain registrations to malicious activity
A study by Interisle Consulting Group sparked debate over whether current ICANN policies and domain-name safeguards are sufficient to curb cybercrime.
The short version
- New research estimates that between 10% and 20% of generic top-level domains registered in 2025 were controlled by cybercriminals or appeared on blocklists.
- ICANN's Office of the CTO contested the methodology, pointing out that broad definitions of abuse do not align with ICANN's narrower contractual definitions.
- The debate centers on whether ICANN and domain registrars should adopt more stringent preventive measures, such as enhanced "know-your-customer" checks, to prevent bad actors from registering domains at scale.
Key facts
- Interisle Consulting Group published a study showing that at least 10% of new generic top-level domains (gTLDs) registered in 2025 subsequently appeared on security blocklists.[Hacker News]
- Interisle researchers Greg Aaron and Karen Rose estimated at the ICANN 86 Policy Forum that malicious actors may have ultimately registered about 20% of new 2025 gTLDs when factoring in associated, unlisted domains.[Hacker News]
- ICANN's Office of the CTO responded that estimates are highly dependent on the definition of "abuse" and analytical methods, stressing that ICANN's contractual definition of DNS abuse is limited to botnets, malware, pharming, phishing, and spam facilitating these threats.[Hacker News]
- The Global Anti-Scam Alliance reported that online scams caused an estimated $442 billion in global financial losses during 2025.[Hacker News]
What remains uncertain
- The precise proportion of newly registered domains controlled by criminals remains disputed due to differing methodologies, varying evidentiary standards, and disagreements over what constitutes DNS abuse versus wider technology-facilitated harm.[Hacker News]
Sources
- DNS Abuse and Criminal InfrastructureHacker News