Avatier

Phished or stolen credentials

Typosquatting

Also called: lookalike domain

Typosquatting is registering a web domain that looks almost like a real one, through a misspelling, swapped letter, extra word or different ending, so that people mistake it for the genuine site. Attackers use these lookalike domains to host fake login pages, send convincing email and catch visitors who mistype an address.

How it works

The attacker registers a name close to a trusted brand or company, adds a valid certificate and copies the real site's look. Links to the domain go out in phishing email or ads, and because the name nearly matches, many recipients do not notice the difference before entering credentials or downloading software.

A real example

In January 2023 CISA, NSA and MS-ISAC assessed that a help desk-themed phishing campaign against federal civilian agency staff, active since at least June 2022, was related to malicious typosquatting activity reported by the security firm Silent Push.

Source: Protecting Against Malicious Use of Remote Monitoring and Management Software (AA23-025A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-01-25

The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Phishing-resistant MFA, such as passkeys, will not sign in to a lookalike domain because it is bound to the real one. Monitor new registrations that resemble your own domains.

Related terms

Sources

  1. Protecting Against Malicious Use of Remote Monitoring and Management Software (AA23-025A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-01-25

Last reviewed Oct 2, 2026