The $7 Million Expired Domain Trap That's Redirecting Users to Scams

·
Listen to this article~6 min
The $7 Million Expired Domain Trap That's Redirecting Users to Scams

Hackers spent nearly $7 million buying expired domains to inherit their trust and redirect users to scams and malware. Here's how the attack works and how to stay safe.

You've probably typed in a web address and landed on a page that felt... off. Maybe it was a news site that suddenly pushed a fake giveaway, or a forum that redirected you to a sketchy download. It's easy to assume you made a typo or clicked a bad ad. But what if the site itself had been hijacked without you ever knowing? That's exactly what's happening on a massive scale right now. Threat actors are quietly buying up expired domains—websites that once had real traffic, real visitors, and real trust—and then weaponizing that history to push scams and malware. It's a sneaky, low-cost attack that's catching a lot of people off guard. ### What Are Dropcatch Domains? Infoblox, a company that specializes in DNS threat intelligence, has a name for these recycled domains: dropcatch domains. The idea is simple. When a domain registration lapses, it goes back into the pool of available names. Anyone can snatch it up for a small fee. But here's the kicker: the domain still carries all its old reputation. Search engines remember it. Email filters trust it. And users? They see a familiar URL and assume it's safe. That's the trap. ### The Numbers Are Staggering During the first half of 2026, researchers tracked 50,400 of these dropcatch domains being used for malicious activity. That's not a rounding error. That's a coordinated, ongoing campaign. And the financial scale is just as eye-opening. Hackers have spent nearly $7 million on these expired domains, which tells you just how profitable this scheme has become. To put that in perspective, $7 million could buy a lot of brand-new domains. But the whole point here is that fresh domains don't have history. They don't have backlinks. They don't have a reputation to abuse. So the bad guys are willing to pay a premium for digital real estate that already has a good name. ### Why Expired Domains Are So Valuable to Scammers Think of an expired domain like a used car with a spotless maintenance record. The odometer might be high, but the history says it's reliable. Scammers buy that history and then put a different engine inside. Here's what makes these domains so dangerous: - **Inherited trust**: Search engines rank them higher because of old backlinks and content. - **Email credibility**: Spam filters are less likely to block messages from a domain that's been around for years. - **User familiarity**: People are more likely to click a link they recognize, even if the content underneath has completely changed. ### How the Redirects Work Once the attacker owns the domain, they can set up a redirect. You land on what looks like a legitimate site, and boom—you're whisked away to a phishing page, a fake store, or a malware download. Sometimes the redirect is instant. Other times, it's delayed by a few seconds, which makes it even harder to notice. The scary part is that these attacks don't require any technical wizardry. You don't need to hack a server or break into a database. You just need to buy a name that someone else forgot to renew. ### Who's Most at Risk? Anyone who visits an older website is at risk, but certain groups are more exposed than others. Small business owners who rely on older sites for their industry news are prime targets. So are people who follow niche forums or hobby communities that have been around for years. If a site hasn't been updated in a while, there's a decent chance its domain could expire and fall into the wrong hands. ### What You Can Do to Stay Safe You don't need to become a cybersecurity expert to protect yourself. A few simple habits go a long way: - **Check the URL carefully**: If a familiar site suddenly looks different or asks for unusual information, pause. - **Look for HTTPS**: It's not a guarantee of safety, but it's a good baseline. - **Don't download unexpected files**: If a site you trust suddenly offers a "critical update" or "free tool," be suspicious. - **Use a reliable security tool**: A good antivirus or browser extension can catch redirects before they cause damage. ### The Bottom Line This isn't some obscure threat that only affects techies. It's a real, growing problem that's costing people money and compromising their data. The $7 million investment by hackers shows they see this as a long-term strategy, not a one-off trick. So the next time you land on a page that feels slightly off, trust your gut. That little voice might just be saving you from a very expensive mistake.