deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

Interisle data suggests criminals may control a fifth of new gTLD registrations

Interisle found 10% of new 2025 gTLD registrations landed on security blocklists, with the criminal share possibly near 20%, prompting debate over ICANN's DNS abuse framework.

Interisle data suggests criminals may control a fifth of new gTLD registrations

Research by Interisle Consulting Group indicates that cybercriminals may have registered roughly a fifth of all new generic top-level domain names created in 2025, reigniting a dispute over whether current DNS abuse measures match the scale of the problem. An analysis by Andrew Campling published on RIPE Labs, which reached Hacker News' front page, argues the resulting methodological debate must not become an excuse for institutional inaction.

What the numbers show

Interisle's study found that at least 10% of new gTLD domains registered during 2025 had appeared on security blocklists by the time the analysis was carried out. In a follow-up presentation at the ICANN 86 Policy Forum, Greg Aaron and Karen Rose of Interisle put the share of names created by malicious actors at approximately 20%, projecting that later blocklisting could lift the directly observed proportion to around 12%. They supported that projection with ICANN research indicating that, for every three domains that end up on blocklists, roughly two associated domains may never be listed.

ICANN's pushback

ICANN's Office of the CTO has since published a blog post arguing that any estimate of malicious registrations depends heavily on how "abuse" is defined, what standard of evidence is applied and which analytical method is used. It cautioned against treating every blocklisted domain as automatically confirmed DNS abuse, and noted that ICANN's contractual definition is deliberately narrow, covering only botnets, malware, pharming, phishing, and spam when spam delivers one of those harms. Broader categories such as fraud and scams should, in its view, be analysed separately. The OCTO authors also criticised the Interisle report for referencing ICANN and COMAR methods without explaining where it departed from them, and pointed to ongoing policy work on associated-domain checks and safeguards for high-volume registrations.

Campling concedes these definitional and methodological questions matter for what can be claimed and how studies compare. But he argues they do not dissolve the underlying concern: a substantial share of newly registered gTLD names may sit with actors engaged in, or supporting, malicious activity. A domain need not be blocklisted or meet the contractual definition to pose a risk. It can be stockpiled for later deployment, used in campaigns reporting systems have not yet detected, or used for technology-facilitated harms outside the definition, including fraud, scams and sextortion.

The wider harm

To frame the urgency, the RIPE Labs piece cites figures that, as it acknowledges, do not isolate the role of domain names. The Global Anti-Scam Alliance estimates scams caused US$442 billion in global losses during 2025, with the likelihood of financial loss notably higher in developing countries. Childlight's Into the Light index, updated in 2026, reports that about one in four children experience online sexual solicitation and that 9% experience online sexual extortion before the age of 18.

What should change

Campling calls on the ICANN community to test whether current contractual definitions, preventive obligations, data-sharing arrangements and enforcement mechanisms can shrink this risk quickly enough, covering the period before registration, at the point of registration, and after credible evidence of harm emerges. He argues high-volume and otherwise anomalous registration patterns warrant scrutiny, balanced against due process and registrants' legitimate needs.

He also notes that ccTLD operators may, depending on their jurisdictions, have clearer mandates to act against a wider range of illegal conduct, and that diverging approaches could leave governments, registrants and users perceiving the gTLD market as offering weaker safeguards. Risk-based know-your-customer checks by registrars, going beyond superficial phone or email validation, are put forward as part of the solution. He stresses that new measures should not turn ICANN into a global content regulator, citing Heather Flanagan's observation around IETF 126 that technical communities cannot ignore policy concerns but should not embed every political demand into architecture without weighing the consequences.

Why it matters

The domain name system is upstream infrastructure for phishing, fraud, ransomware and child exploitation operations. If one in five new registrations in a major market may be criminally controlled, that is a structural security problem rather than a measurement quibble. The outcome of this definitional fight will shape whether registries and registrars face firmer obligations on screening customers, throttling suspicious bulk registrations and sharing data with authorities, and it will affect everyone downstream who relies on blocklists and registration data to keep users safe.

  • #dns
  • #icann
  • #domain-names
  • #cybersecurity
  • #internet-governance

Related posts